Elektroda.pl
Elektroda.pl
X

Search our partners

Find the latest content on electronic components. Datasheets.com
Elektroda.pl
Please add exception to AdBlock for elektroda.pl.
If you watch the ads, you support portal and users.

Malware kometastartvx64.exe (Mail.ru) - logi hijackthis do weryfikacji

01 Apr 2017 11:48 1056 8
  • Level 10  
    Pobrałem aplikację z nieznanego źródła i zainstalował mi się na dysku wirus kometastartvx64.exe znany bardziej jako Mail.ru, zmieniający windowsowy pasek start na kometa start. Dodane zostały również na pulpicie toolbary z odnośnikami do rosyjskich serwisów.

    Przeglądarki standardowo zostały zainfekowane i ustawione na rosyjskie wyszukiwarki poprzez wtyczki : Chrome, Firefox i Edge.

    Cały system przeskanowałem programami: ESET x64, Zemana Anti Malware, Malwarebytes Anti Malware, Adv cleaner, JRT, TDSSKiller, Rkill.

    Wirusa udało się skasować, pozostały jedynie denerwujące reklamy o tematyce porno.

    Log z Hijack This:

    Quote:
    Logfile of Trend Micro HijackThis v2.0.5
    Scan saved at 11:45:43, on 2017-04-01
    Platform: Unknown Windows (WinNT 6.02.1008)
    MSIE: Internet Explorer v11.0 (11.00.14393.0953)

    FIREFOX: 52.0.2 (x86 pl)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
    C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    C:\Program Files (x86)\kED\kED2.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
    C:\Program Files\Adobe\Adobe Photoshop CC 2015\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
    C:\Program Files\Adobe\Adobe Photoshop CC 2015\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
    C:\Users\Miro\Downloads\HijackThis.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
    O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
    O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
    O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
    O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
    O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
    O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKCU\..\Run: [ScreenSplitter] C:\Program Files (x86)\LG Electronics\Screen Split\bin\ScreenSplit.exe
    O4 - HKCU\..\Run: [uTorrent] "C:\Users\Miro\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
    O4 - HKCU\..\Run: [OneDrive] "C:\Users\Miro\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
    O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    O4 - HKCU\..\Run: [StartButton] C:\Users\Miro\AppData\Local\Kometa\StartButton\kometastartvx64.exe
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe -update pepperplugin
    O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
    O4 - Startup: Adobe Media Player.lnk = C:\Program Files (x86)\Adobe Media Player\Adobe Media Player.exe
    O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
    O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
    O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
    O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
    O23 - Service: Usługa Aktualizacja Dropbox (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    O23 - Service: Usługa Aktualizacja Dropbox (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
    O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Usługa Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
    O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
    O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: ZAM Controller Service (ZAMSvc) - Unknown owner - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (file missing)

    --
    End of file - 11401 bytes
  • Helpful post
    IT specialist
    Nie widzisz, ze wymagane sa logi z FRST, a nie bezuzyteczny log z hjt? Reszta tez calkowicie zbedna.
  • Helpful post
    IT specialist
    Nie uzywaj wiecej combofix, to samo dotyczy hjt i otl.

    Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
    Task: {26500BFC-3F42-4E65-A2E0-8AB3E9300BE3} - System32\Tasks\Opera scheduled Autoupdate 1447884517 => C:\Program Files (x86)\Opera\launcher.exe [2017-02-27] (Opera Software)
    Task: {78E81A9B-1B3E-40FD-82ED-007149B2F7B7} - System32\Tasks\{71B95458-0906-4BBA-B69A-16E6934718A8} => pcalua.exe -a "C:\Program Files\McAfee Security Scan\uninstall.exe"
    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    C:\Users\Miro\AppData\Roaming\Microsoft\Windows\Start Menu\Кнопка Пуск — Комета\Кнопка Пуск — Комета.lnk
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\Run: [StartButton] => C:\Users\Miro\AppData\Local\Kometa\StartButton\kometastartvx64.exe
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {1ca0fc04-a5ce-11e6-82ef-28c2dd248d18} - "J:\RunGame.exe"
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {acc0d76c-d829-11e6-8306-28c2dd248d18} - "J:\HTC_Sync_Manager_PC.exe"
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {acc0d775-d829-11e6-8306-28c2dd248d18} - "J:\HTC_Sync_Manager_PC.exe"
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {b5c9a292-99ff-11e5-8267-28c2dd248d18} - "F:\Autorun.exe"
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {b5c9aa5d-99ff-11e5-8267-28c2dd248d18} - "I:\RunGame.exe"
    HKU\S-1-5-21-909796221-923560975-3426781482-1001\...\MountPoints2: {cb812d54-f73d-11e6-830e-28c2dd248d18} - "J:\HTC_Sync_Manager_PC.exe"
    ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    GroupPolicy: Ograniczenia <======= UWAGA
    GroupPolicy\User: Ograniczenia <======= UWAGA
    SearchScopes: HKLM -> DefaultScope - brak wartości
    CHR HKU\S-1-5-21-909796221-923560975-3426781482-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
    OPR Extension: (Translate) - C:\Users\Miro\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibnombjmjocaccigcefonnipcnlaeaed [2016-04-13]
    S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
    S3 dbx; system32\DRIVERS\dbx.sys [X]
    S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
    2017-04-01 12:04 - 2017-04-01 12:04 - 00000000 ____D C:\Users\Miro\Downloads\FRST-OlderVersion
    2017-04-01 12:00 - 2017-04-01 12:00 - 00001128 _____ C:\Users\Miro\Downloads\JRT (1).txt
    2017-04-01 11:59 - 2017-04-01 11:59 - 00005564 _____ C:\Users\Miro\Downloads\Rkill (1).txt
    2017-04-01 11:48 - 2017-04-01 11:48 - 00005564 _____ C:\Users\Miro\Downloads\Rkill.txt
    2017-04-01 11:48 - 2017-04-01 11:48 - 00001128 _____ C:\Users\Miro\Downloads\JRT.txt
    2017-04-01 11:02 - 2017-04-01 11:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Miro\Downloads\HijackThis.exe
    2017-03-30 19:21 - 2017-03-30 19:22 - 00005564 _____ C:\Users\Miro\Desktop\Rkill.txt
    2017-03-30 11:35 - 2017-03-30 11:35 - 05766464 _____ (Zemana Ltd. ) C:\Users\Miro\Downloads\Zemana.AntiMalware.Setup(2).exe
    2017-03-30 11:17 - 2017-03-30 11:17 - 05766464 _____ (Zemana Ltd. ) C:\Users\Miro\Downloads\Zemana.AntiMalware.Setup(1).exe
    2017-03-30 11:16 - 2017-03-30 11:16 - 00001128 _____ C:\Users\Miro\Desktop\JRT.txt
    2017-03-29 15:22 - 2017-03-29 15:22 - 00000000 ____D C:\Users\Miro\AppData\Roaming\Microsoft\Windows\Start Menu\Кнопка Пуск — Комета
    2017-03-29 15:22 - 2017-03-29 15:22 - 00000000 ____D C:\Users\Miro\AppData\Local\NetBoxLogs
    2017-03-29 15:21 - 2017-03-29 16:21 - 00000000 ____D C:\Users\Miro\AppData\Local\wupdate
    2017-03-29 15:21 - 2017-03-29 15:21 - 00000000 ____D C:\ProgramData\Microsoft Toolkit
    2017-03-29 15:20 - 2017-03-29 15:21 - 00000000 ____D C:\Users\Miro\AppData\Local\svshost
    2017-04-01 09:32 - 2016-06-07 17:30 - 00000000 ____D C:\AdwCleaner
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST po wykonaniu.
  • Level 10  
    Zrobiłem jw. naprawianie i usunąłem katalog FRST na dysku C.

    Przeglądarka nadal przekierowuje mnie na strony reklamowe, ilekroć kliknę w jakiś link, wyskakuje nowa zakłądka z zawirusowaną stroną. Malwarebytes blokuje mi te zakładki.

    Nadal mam złośliwe odnośniki i porno reklamy. Jak się tego pozbyć ze wszystkich przeglądarek?

    Używam Firefoxa i Chrome.
  • IT specialist
    Problem wystepuje w obu przegladarkach? Czy tylko w Chrome lub FF?
  • Level 10  
    Quote:
    Problem wystepuje w obu przegladarkach? Czy tylko w Chrome lub FF?


    Tylko w Chrome występuje problem z reklamami. Firefox działa dobrze. Edge natomiast w ogóle się nie uruchamia, wcześniej działał.
  • Level 10  
    Udało się rozwiązać problem. Usunąłem jw. katalog default z Chrome. Po reinstalacji przeglądarki problem z malware już nie występuje.

    Dziękuję za pomoc Kolobos. Temat zamykam.