
http://www.wklej.org/id/581927/
http://www.wklej.org/id/581929/
:OTL
PRC - [2011-08-22 15:26:10 | 000,137,728 | ---- | M] () -- D:\Windows\systemup.exe
PRC - [2011-08-22 14:41:02 | 000,634,880 | ---- | M] () -- D:\Windows\update.2\svchost.exe
PRC - [2011-08-22 14:41:02 | 000,634,880 | ---- | M] () -- D:\Windows\update.2\svchost.exe
PRC - [2011-08-22 14:41:02 | 000,634,880 | ---- | M] () -- D:\Windows\update.2\svchost.exe
PRC - [2011-08-22 14:40:16 | 000,355,840 | ---- | M] () -- D:\Windows\update.5.0\svchost.exe
PRC - [2011-08-22 14:40:16 | 000,355,840 | ---- | M] () -- D:\Windows\update.5.0\svchost.exe
PRC - [2011-08-19 13:25:46 | 000,382,464 | ---- | M] () -- D:\Windows\update.7.1\svchostdriver.exe
PRC - [2011-08-19 13:10:38 | 000,232,960 | ---- | M] () -- D:\Windows\l1rezerv.exe
PRC - [2011-08-19 12:58:51 | 000,258,048 | ---- | M] () -- D:\Windows\sysdriver32_.exe
PRC - [2011-08-19 12:45:01 | 001,215,488 | -H-- | M] () -- D:\Windows\update.tray-9-0\svchost.exe
PRC - [2011-08-19 12:45:01 | 001,215,488 | -H-- | M] () -- D:\Windows\update.tray-8-0\svchost.exe
PRC - [2011-08-19 12:45:01 | 001,215,488 | -H-- | M] () -- D:\Windows\update.1\svchost.exe
MOD - [2011-08-22 15:26:10 | 000,137,728 | ---- | M] () -- D:\Windows\systemup.exe
MOD - [2011-08-19 13:10:38 | 000,232,960 | ---- | M] () -- D:\Windows\l1rezerv.exe
MOD - [2011-08-19 12:58:51 | 000,258,048 | ---- | M] () -- D:\Windows\sysdriver32_.exe
MOD - [2011-08-19 12:45:01 | 001,215,488 | -H-- | M] () -- D:\Windows\update.tray-9-0\svchost.exe
MOD - [2011-08-19 12:45:01 | 001,215,488 | -H-- | M] () -- D:\Windows\update.tray-8-0\svchost.exe
SRV - [2011-08-19 13:25:46 | 000,382,464 | ---- | M] () [Auto | Running] -- D:\Windows\update.7.1\svchostdriver.exe -- (ddservice)
IE - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=GRxdm047YYPL&ptb=zSi1x7xJIxCWJTyCMclJ6w
IE - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - D:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=CDS&o=16205&locale=en_US&apn_uid=5C17A339-4B53-4CAE-A7E8-8DC21245E80C&apn_ptnrs=QR&apn_sauid=7B2483E0-2CFC-4AEA-A6A0-5D361DBFEBF8&apn_dtid=&q="
[2010-02-21 18:04:46 | 000,000,000 | ---D | M] (MediaBar) -- D:\Users\Knot\AppData\Roaming\mozilla\Firefox\Profiles\y5gmkdpt.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2011-07-27 17:01:58 | 000,002,385 | ---- | M] () -- D:\Users\Knot\AppData\Roaming\Mozilla\Firefox\Profiles\y5gmkdpt.default\searchplugins\askcom.xml
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [2357229.exe] D:\Users\Knot\AppData\Local\Temp\2357229.exe ()
O4 - HKLM..\Run: [31667.exe] D:\Users\Knot\AppData\Local\Temp\31667.exe ()
O4 - HKLM..\Run: [3959819.exe] D:\Users\Knot\AppData\Local\Temp\3959819.exe ()
O4 - HKLM..\Run: [3972480.exe] D:\Windows\Temp\3972480.exe ()
O4 - HKLM..\Run: [5092637.exe] D:\Users\Knot\AppData\Local\Temp\5092637.exe ()
O4 - HKLM..\Run: [54648291-loader2.exe] D:\Windows\Temp\54648291-loader2.exe ()
O4 - HKLM..\Run: [5739745.exe] D:\Users\Knot\AppData\Local\Temp\5739745.exe ()
O4 - HKLM..\Run: [8159064.exe] D:\Windows\Temp\8159064.exe ()
O4 - HKLM..\Run: [8611735.exe] D:\Users\Knot\AppData\Local\Temp\8611735.exe ()
O4 - HKLM..\Run: [ApnUpdater] D:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] File not found
O4 - HKLM..\Run: [Corel Graphics Suite 1117] File not found
O4 - HKLM..\Run: [l1rezerv.exe] D:\Windows\l1rezerv.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] D:\Windows\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] D:\Windows\sysdriver32_.exe ()
O4 - HKLM..\Run: [systemup] D:\Windows\systemup.exe ()
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico0] D:\Windows\update.tray-8-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico1] D:\Windows\update.tray-9-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKLM..\Run: [wxpdrv] D:\Windows\services32.exe ()
661376083-2262401081-1945447135-1000..\Run: [ALLUpdate] D:\Program Files (x86)\ALLPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000..\Run: [EA Core] File not found
O4 - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000..\Run: [eMuleAutoStart] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O31 - SafeBoot: AlternateShell - services32.exe
[2011-08-19 13:25:47 | 000,000,000 | -H-D | C] -- D:\Windows\update.7.1
[2011-08-19 13:09:43 | 000,000,000 | ---D | C] -- D:\Windows\ufa
[2011-08-19 13:09:43 | 000,000,000 | ---D | C] -- D:\Windows\rpcminer
[2011-08-19 13:09:43 | 000,000,000 | ---D | C] -- D:\Windows\phoenix
[2011-08-19 13:08:07 | 000,000,000 | -H-D | C] -- D:\Windows\update.5.0
[2011-08-19 13:05:21 | 000,000,000 | -H-D | C] -- D:\Windows\update.2
[2011-08-19 12:58:42 | 000,000,000 | ---D | C] -- D:\Windows\av_ico
[2011-08-19 12:57:02 | 000,000,000 | -H-D | C] -- D:\Windows\update.1
[2011-08-19 12:56:56 | 000,000,000 | -H-D | C] -- D:\Windows\update.tray-9-0-lnk
[2011-08-19 12:56:56 | 000,000,000 | -H-D | C] -- D:\Windows\update.tray-9-0
[2011-08-19 12:56:56 | 000,000,000 | -H-D | C] -- D:\Windows\update.tray-8-0-lnk
[2011-08-19 12:56:56 | 000,000,000 | -H-D | C] -- D:\Windows\update.tray-8-0
[2011-08-22 15:26:11 | 000,000,200 | ---- | M] () -- D:\Windows\info1
[2011-08-22 15:26:10 | 000,137,728 | ---- | M] () -- D:\Windows\systemup.exe
[2011-08-22 14:55:33 | 000,001,048 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-08-22 14:41:30 | 000,000,734 | ---- | M] () -- D:\Windows\SysNative\drivers\etc\hîsts
[2011-08-20 19:18:00 | 000,000,496 | -H-- | M] () -- D:\Windows\tasks\Norton Security Scan for Knot.job
[2011-08-20 09:09:21 | 005,589,370 | ---- | M] () -- D:\Windows\phoenix.rar
[2011-08-20 09:09:21 | 001,075,284 | ---- | M] () -- D:\Windows\rpcminer.rar
[2011-08-20 09:09:21 | 000,246,272 | ---- | M] () -- D:\Windows\unrar.exe
[2011-08-20 09:09:21 | 000,182,617 | ---- | M] () -- D:\Windows\ufa.rar
[2011-08-20 09:08:07 | 000,000,000 | ---- | M] () -- D:\Windows\loader2.exe_ok
[2011-08-19 18:45:17 | 000,002,432 | ---- | M] () -- D:\Users\Knot\AppData\Local\TempbA3160.html
[2011-08-19 18:45:17 | 000,002,089 | ---- | M] () -- D:\Users\Knot\AppData\Local\Tempjl3160.html
[2011-08-19 13:10:38 | 000,232,960 | ---- | M] () -- D:\Windows\l1rezerv.exe
[2011-08-19 13:05:16 | 000,904,792 | ---- | M] () -- D:\Windows\geoiplist.rar
[2011-08-19 12:58:51 | 000,258,048 | ---- | M] () -- D:\Windows\sysdriver32_.exe
[2011-08-19 12:58:51 | 000,258,048 | ---- | M] () -- D:\Windows\sysdriver32.exe
[2011-08-19 12:55:23 | 000,002,432 | ---- | M] () -- D:\Users\Knot\AppData\Local\TempED2648.html
[2011-08-19 12:55:23 | 000,002,089 | ---- | M] () -- D:\Users\Knot\AppData\Local\Tempkw2648.html
[2011-08-19 12:45:01 | 001,215,488 | ---- | M] () -- D:\Windows\services32.exe
[2011-08-22 15:15:15 | 000,137,728 | ---- | C] () -- D:\Windows\systemup.exe
[2011-08-19 13:05:17 | 004,636,907 | ---- | C] () -- D:\Windows\geoiplist
[2011-08-19 13:05:16 | 000,904,792 | ---- | C] () -- D:\Windows\geoiplist.rar
[2011-08-19 13:05:16 | 000,246,272 | ---- | C] () -- D:\Windows\unrar.exe
[2011-08-19 13:01:59 | 000,002,432 | ---- | C] () -- D:\Users\Knot\AppData\Local\TempbA3160.html
[2011-08-19 13:01:59 | 000,002,089 | ---- | C] () -- D:\Users\Knot\AppData\Local\Tempjl3160.html
[2011-08-19 12:59:04 | 000,258,048 | ---- | C] () -- D:\Windows\sysdriver32_.exe
[2011-08-19 12:58:50 | 000,258,048 | ---- | C] () -- D:\Windows\sysdriver32.exe
[2011-08-19 12:45:14 | 001,215,488 | ---- | C] () -- D:\Windows\services32.exe
:Files
D:\Users\Knot\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit"=-
"Userinit"="C:\WINDOWS\system32\userinit.exe,"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"
:Commands
[resethosts]
[emptytemp]
[emptyflash]
:OTL
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O2 - BHO: (CrowdStar Gamebar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O3 - HKLM\..\Toolbar: (CrowdStar Gamebar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O3 - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000\..\Toolbar\WebBrowser: (CrowdStar Gamebar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O4 - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000..\Run: [Remote Control Editor] File not found
[2011-08-23 12:13:46 | 000,001,044 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
:Files
D:\Users\Knot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWRISOVM.EXE"=-
"StartCCC"=-
"TkBellExe"=-
"WinampAgent"=-
[HKEY_USERS\S-1-5-21-3661376083-2262401081-1945447135-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
"IPLA!"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Wersja bazy: 7557
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
2011-08-24 23:10:34
mbam-log-2011-08-24 (23-10-34).txt
Typ skanowania: Szybkie skanowanie
Przeskanowano obiektów: 172861
Upłynęło: 3 minut(y), 3 sekund(y)
Zainfekowanych procesów w pamięci: 0
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 23
Zainfekowanych wartości rejestru: 2
Zainfekowane informacje rejestru systemowego: 3
Zainfekowanych folderów: 11
Zainfekowanych plików: 5
Zainfekowanych procesów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych kluczy rejestru:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvbtcclient (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WXPDRIVERS (Trojan.Agent) -> Quarantined and deleted successfully.
Zainfekowanych wartości rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpDrivers\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
Zainfekowane informacje rejestru systemowego:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Zainfekowanych folderów:
d:\program files (x86)\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\3.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\setups (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Zainfekowanych plików:
d:\Users\Knot\downloads\flash-player.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\2.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\2.bin\F3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\funwebproducts\Installr\2.bin\NPFUNWEB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files (x86)\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
:OTL
IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - D:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3661376083-2262401081-1945447135-1000\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - D:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "MyStart Search"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredimail.com/mb68?u=92259915667804339"
FF - prefs.js..keyword.URL: "http://mystart.incredimail.com/mb68/?loc=ff_address_bar&u=92259915667804339&search="
[2011-08-24 23:23:30 | 000,000,000 | ---D | M] (IncrediMail MediaBar 2 Toolbar) -- D:\Users\Knot\AppData\Roaming\mozilla\Firefox\Profiles\y5gmkdpt.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
:Files
D:\Users\Knot\AppData\Local\Temp*.html
:Commands
[clearallrestorepoints]
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 14 gości