Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

wirus w przeglądarce otwieranie się rosyjskich stron

spike111 20 Maj 2017 09:57 1245 4
  • Pomocny post
    #2 20 Maj 2017 10:32
    Kolobos
    Spec od komputerów

    Zrob kopie zakladek z Firefox'a i Chrome, profile utworzone przez infekcje zostana usuniete. Odinstaluj Firefox oraz Chrome.

    Skroty z cyrylica w nazwie widoczne w logach usun recznie.

    Wykonaj Fixlist.txt dla FRST:
    Task: {086D6A5C-8E69-4546-9351-C1B5688A1674} - System32\Tasks\{080E87FD-0EFA-4565-8F43-19C45EFB53F9} => msiexec.exe /package "G:\GMEApplication\GMEAPPLICATION.MSI"
    Task: {1E5868CB-6E4A-4567-8C32-E42A11CC6764} - System32\Tasks\{4D58892F-928D-440D-A1A0-333FEF90A1BF} => pcalua.exe -a C:\ProgramData\036DFF3500017CB5AF7EA3594F147C45\036DFF3500017CB5AF7EA3594F147C45.exe -c -u
    Task: {1EBB8833-5767-4331-8753-277C1FFD1066} - System32\Tasks\{FD92F567-970D-4B3C-A62A-208574BDE9A0} => pcalua.exe -a "C:\Users\www\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KBGHTT5N\JavaSetup8u66[1].exe" -d C:\Users\www\Desktop
    Task: {4149F18B-F031-4A13-8738-74D5FEFBC3BD} - System32\Tasks\{6932CF6B-2162-4BAA-A062-0C613C3C511B} => G:\setup.exe
    Task: {4239B0CD-3ECE-46C9-82DA-DFF6E9BD9B63} - System32\Tasks\{2455ED2A-AD26-485C-BF43-3877AF6D1CCD} => msiexec.exe /package "G:\GMEApplication\GMEAPPLICATION.MSI"
    Task: {65B90C39-35C6-4C01-803F-DF92B0630EC5} - \ProtectedSearch\Protected Search -> Brak pliku <==== UWAGA
    Task: {6E736AA5-AF14-429A-96FF-E56E281D30FD} - System32\Tasks\{68E10531-C164-4E66-A787-3996BC3DBB14} => pcalua.exe -a "D:\Program Files\Acoustica CD Label Maker\cdlabel.exe" -c UNINSTALL
    Task: {7201DF4A-46F8-465F-97C0-951ACED31CCD} - System32\Tasks\{CED74585-5142-4B0A-B867-5516E5A43682} => pcalua.exe -a D:\smieci\Fotoboss_Designer_setup.exe -d D:\smieci
    Task: {73BB66BE-AD41-4C37-A579-3B7FD43B4FC7} - System32\Tasks\xmarin => C:\Users\www\AppData\Local\xmarin\xmarin.exe <==== UWAGA
    Task: {856CF437-1D10-446D-9533-2FB3A499A018} - System32\Tasks\{198A7163-9D3E-425F-8C93-5D0CA21F333C} => Firefox.exe hxxp://ui.skype.com/ui/0/7.17.0.106/pl/abando...?source=lightinstaller&amp;page=tsInstall
    Task: {861E4C74-B3C2-439D-8A7A-792DDF6BDDD9} - System32\Tasks\{45B79C35-7CF2-4421-A6AB-1B2E6D3BAF49} => G:\setup.exe
    Task: {8F5A5306-B466-4CAA-AD72-C66CC652E281} - System32\Tasks\{D9087D76-5A08-4631-8F99-355831FAD43D} => msiexec.exe /package "G:\GMERomDB\GMERomDB.msi"
    TTask: {952AC7E7-368D-44F7-B94F-0EF736EE6411} - System32\Tasks\{EB2394D8-E039-4E4E-9A38-51B5D811DD70} => G:\setup.exe
    Task: {95A486E3-0D82-49C0-9309-9B19A5F9C601} - System32\Tasks\{A44C71FA-9A01-4E56-B2B3-59A66CB508A7} => msiexec.exe /package "G:\GMGLocalDB\GMGLocalDB.msi"
    Task: {A0982088-0EF4-4826-BAAC-E4EACC29C1EC} - System32\Tasks\{A2212237-FDD1-47DF-9B50-AC33A939B23A} => msiexec.exe /package "G:\GMEApplication\GMEAPPLICATION.MSI"
    Task: {A0A599CC-1A19-4A27-959E-4751FDAE2F96} - System32\Tasks\{CEA311B9-B9FE-4501-BD63-253ADB81ADA8} => msiexec.exe /package "G:\GMGInfrastructure\GMGInfrastructure.msi"




    Task: {B1788D0D-0C42-4A8A-B73A-62223FAA233B} - System32\Tasks\{31984A89-580D-472A-9D0E-3653C4A6F6F1} => msiexec.exe /package "G:\GMEApplication\GMEAPPLICATION.MSI"
    Task: {B76F1BD5-24C0-4E37-B1C4-144BE284701D} - System32\Tasks\{DCC7DB37-10FE-4FDE-83F4-B0377348BBE5} => pcalua.exe -a "C:\Program Files\Elex-tech\YAC\uninstall.exe"
    Task: {CFF9479B-0DBD-435C-9650-ED3E37BE622E} - System32\Tasks\{E10EA1B3-2BCE-4290-927A-18729725F969} => pcalua.exe -a "C:\Program Files\4Media\Video Cutter 2\Uninstall.exe"
    Task: {E3DC9F25-38F8-48B6-9D40-6A78274809D4} - System32\Tasks\MSI => C:\Users\www\AppData\Roaming\Microsoft\msi.exe
    Task: {F1603EFE-B666-4153-AD46-DB1B8C09BAEC} - System32\Tasks\{29B0447B-6A22-4345-AAAC-42C2BA97FCB5} => G:\setup.exe
    Shortcut: C:\Users\www\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Footjane\Application\chrome.exe (Google Inc.)
    Shortcut: C:\Users\www\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files\Footjane\Application\chrome.exe (Google Inc.)
    Shortcut: C:\Users\www\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk -> C:\Program Files\Footjane\Application\chrome.exe (Google Inc.)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Footjane\Application\chrome.exe (Google Inc.)
    ShortcutWithArgument: C:\Users\www\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> "hxxp://povyt.ru/?utm_source=startlink03&utm_content=b1bef6feef331714ff70ebf5ea62d1ed&utm_term=B6B52C1AD8226A556A3F1193545E3FC5&utm_d=20170516"
    (© 2015 Microsoft Corporation) C:\Users\www\AppData\Local\Microsoft\BingSvc\BingSvc.exe
    HKLM\...\Run: [WindowsDefender] => -
    HKU\S-1-5-21-781027784-572822677-3152414294-1000\...\Run: [BingSvc] => C:\Users\www\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2016-04-05] (© 2015 Microsoft Corporation)
    HKU\S-1-5-21-781027784-572822677-3152414294-1000\...\Run: [Windows Defender] => -
    HKU\S-1-5-21-781027784-572822677-3152414294-1000\...\MountPoints2: {122aa6d7-5f33-11e2-99bc-001a4d65286e} - E:\KODAK_Software_Downloader.exe
    HKU\S-1-5-21-781027784-572822677-3152414294-1000\...\MountPoints2: {cef89874-652d-11e5-b491-00095bedda02} - I:\LGAutoRun.exe
    HKU\S-1-5-21-781027784-572822677-3152414294-1000\...\MountPoints2: {e633a00c-afcc-11e5-aa07-00095bedda02} - I:\LGAutoRun.exe
    HKLM\...\Providers\dvijplbz: C:\Program Files\Coasugh Debuger\local32spl.dll
    IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe
    IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe
    ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    GroupPolicy: Ograniczenia ? <======= UWAGA
    GroupPolicy\User: Ograniczenia ? <======= UWAGA
    URLSearchHook: HKU\S-1-5-21-781027784-572822677-3152414294-1000 - (Brak nazwy) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - Brak pliku
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    Toolbar: HKU\S-1-5-21-781027784-572822677-3152414294-1000 -> Brak nazwy - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - Brak pliku
    FF user.js: detected! => C:\Users\www\AppData\Roaming\Mozilla\Firefox\Profiles\2rxptta7.default-1485445806702\user.js [2017-05-16]
    FF DefaultSearchEngine: Mozilla\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF SelectedSearchEngine: Mozilla\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF ProfilePath: C:\Users\www\AppData\Roaming\Firefox\Firefox\Profiles\2rxptta7.default-1485445806702 [2017-05-16]
    FF user.js: detected! => C:\Users\www\AppData\Roaming\Firefox\Firefox\Profiles\2rxptta7.default-1485445806702\user.js [2017-05-16]
    FF NewTab: Firefox\Firefox\Profiles\2rxptta7.default-1485445806702 -> hxxp://www.luckysearch123.com?type=hp&ts=...;z=7bf0d99f576c7c2b2a09f5eg4z8t8zaw4g1zae0w8m
    FF DefaultSearchEngine: Firefox\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF SearchEngineOrder.1: Firefox\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF SelectedSearchEngine: Firefox\Firefox\Profiles\2rxptta7.default-1485445806702 -> luck
    FF Extension: (z) - C:\Program Files\Mozilla Firefox\extensions\{1f721560-1c87-433f-e701-b9f9d71666bf} [2016-11-18] [Brak podpisu cyfrowego]
    CHR DefaultProfile: ChromeDefaultData
    CHR HomePage: ChromeDefaultData -> hxxps://www.google.com/
    CHR NewTab: ChromeDefaultData -> Active:"chrome-extension://epgjfmblhacacphaljkdcjllkomdcjpc/visual-bookmarks.html"
    CHR DefaultSearchURL: ChromeDefaultData -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&product_id=%7B00A0ADF4-F70D-4F1B-B8F9-42E4786F7773%7D&gp=811014
    CHR DefaultSearchKeyword: ChromeDefaultData -> mail.ru
    CHR DefaultSuggestURL: ChromeDefaultData -> hxxp://suggests.go.mail.ru/ff3?q={searchTerms}
    CHR Profile: C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-05-16] <==== UWAGA
    C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData
    CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\epgjfmblhacacphaljkdcjllkomdcjpc [2017-05-16]
    CHR Extension: (Avast Online Security) - C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-23]
    CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
    CHR Extension: (Chrome Media Router) - C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-14]
    CHR HKLM\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - d:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-14]
    OPR Extension: (Fast search) - C:\Users\www\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha [2017-05-02]
    S2 CWASRE; C:\Users\www\AppData\Local\CWASRE\Snare.dll [X]
    R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; d:\Program Files\CyberLink\PowerDVD11\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-09-02] (CyberLink Corp.)
    U3 azsdxoe1; C:\Windows\system32\Drivers\azsdxoe1.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
    U3 DfSdkS; Brak ImagePath
    S3 GPU-Z; \??\C:\Users\www\AppData\Local\Temp\GPU-Z.sys [X]
    U4 VBoxAswDrv; \??\d:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
    2017-05-16 18:07 - 2017-05-16 18:07 - 00000000 _____ C:\Users\Public\Documents\report.dat
    2017-05-16 18:05 - 2017-05-16 18:05 - 00000000 ____D C:\Users\www\AppData\Local\Firefox
    2017-05-16 18:03 - 2017-05-16 18:26 - 00000000 _____ C:\Users\Public\Documents\temp.dat
    2017-05-16 18:00 - 2017-05-16 19:12 - 00000000 ____D C:\Program Files\Firefox
    2017-05-16 18:00 - 2017-05-16 18:00 - 00000000 ____D C:\Users\www\AppData\Roaming\Firefox
    2017-05-16 18:00 - 2017-05-16 18:00 - 00000000 ____D C:\Users\www\AppData\Local\Footjane
    2017-05-16 18:00 - 2017-05-16 18:00 - 00000000 ____D C:\Program Files\Footjane
    2017-05-16 17:48 - 2017-05-16 18:48 - 00000000 ____D C:\Users\www\AppData\Local\xmarin
    2017-05-16 17:48 - 2017-05-16 17:48 - 00046376 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\QIio04UrccMW.sys
    2017-05-16 17:48 - 2017-05-16 17:48 - 00000000 ____D C:\Users\www\AppData\Roaming\Subversion
    2017-05-16 17:47 - 2017-05-16 18:48 - 00000000 ____D C:\Users\www\AppData\Local\wupdate
    2017-05-16 17:46 - 2017-05-16 18:48 - 00000000 ____D C:\Users\www\AppData\Local\svshost
    2017-05-16 17:45 - 2017-05-16 17:45 - 00561919 _____ ( ) C:\Users\www\Downloads\EZ_Activator_Office_2010(1).exe
    2017-05-16 17:44 - 2017-05-16 17:44 - 00561919 _____ ( ) C:\Users\www\Downloads\EZ_Activator_Office_2010.exe
    2017-05-16 17:43 - 2017-05-16 17:43 - 01233912 _____ C:\Users\www\Downloads\office2010toolkit___.exe
    2017-05-11 16:47 - 2017-05-11 16:47 - 00000000 _____ C:\Windows\system32\3333333
    2017-05-11 16:47 - 2017-05-11 16:47 - 00000000 _____ C:\Windows\system32\1111111
    2017-05-11 16:46 - 2017-05-11 16:46 - 00000000 _____ C:\Windows\system32\22
    2017-05-11 16:46 - 2017-05-11 16:46 - 00000000 _____ C:\Windows\system32\11
    2017-05-11 16:46 - 2017-05-11 16:46 - 00000000 _____ C:\Windows\system32\00
    2017-05-10 17:08 - 2017-05-10 17:08 - 00246264 _____ (Mozilla) C:\Users\www\Downloads\Firefox Setup Stub 53.0.2(1).exe
    2017-05-09 19:14 - 2017-05-16 18:59 - 00000000 ____D C:\Users\www\AppData\Roaming\Elex-tech
    2017-05-09 19:14 - 2017-05-09 19:14 - 00000000 ____D C:\Users\Public\Documents\Google
    2017-05-09 19:14 - 2017-05-09 19:14 - 00000000 ____D C:\Program Files\Elex-tech
    2017-05-09 19:13 - 2017-05-11 16:46 - 00000000 _____ C:\Windows\system32\1111
    2017-05-08 16:43 - 2017-05-18 21:15 - 00000000 ____D C:\ProgramData\BIT
    2017-05-03 13:16 - 2017-05-03 13:16 - 00246272 _____ (Mozilla) C:\Users\www\Downloads\Firefox Setup Stub 53.0 (1).exe
    2017-05-03 13:14 - 2017-05-03 13:14 - 00246272 _____ (Mozilla) C:\Users\www\Downloads\Firefox Setup Stub 53.0.exe
    2017-05-03 13:13 - 2017-05-03 13:13 - 00246056 _____ (Mozilla) C:\Users\www\Downloads\Niepotwierdzony 184428.crdownload
    2017-05-03 10:14 - 2017-05-16 17:59 - 00000000 ____D C:\Program Files\MK
    2017-05-03 10:14 - 2017-05-03 10:14 - 00000000 ____D C:\Windows\psgo
    2017-05-03 10:13 - 2017-05-03 10:13 - 00000000 ____D C:\Insist
    2017-05-03 10:03 - 2017-05-16 19:00 - 00000000 ____D C:\Users\www\AppData\Local\background_fault
    2017-05-03 10:03 - 2017-05-15 16:09 - 00000000 ____D C:\Program Files\dvijplbz
    2017-05-02 21:17 - 2017-05-16 19:12 - 00000000 ____D C:\Users\www\AppData\Roaming\Moqerpherpaly
    2017-05-02 21:17 - 2017-05-16 18:59 - 00000000 ____D C:\Program Files\Gucuent
    2017-05-02 21:17 - 2017-05-02 21:17 - 00000000 ____D C:\Users\www\AppData\Local\Duleried
    2017-04-23 13:39 - 2017-04-23 13:39 - 01201768 _____ (Adobe Systems Incorporated) C:\Users\www\Downloads\flashplayer25pp_xa_install.exe
    2017-04-22 20:28 - 2017-04-22 20:28 - 01201768 _____ (Adobe Systems Incorporated) C:\Users\www\Downloads\flashplayer25_xa_install(1).exe
    2017-05-16 20:41 - 2017-03-12 14:47 - 00000000 ____D C:\AdwCleaner
    2013-12-25 22:34 - 2013-12-25 22:34 - 0000000 _____ () C:\ProgramData\InkjetPrinter
    2013-12-25 22:34 - 2013-12-25 22:34 - 0000268 ___RH () C:\ProgramData\Internet Services
    2013-12-25 22:35 - 2013-12-25 22:35 - 0000268 ___RH () C:\ProgramData\Iterate Items
    2013-12-25 22:34 - 2013-12-25 22:34 - 0000268 ___RH () C:\ProgramData\Jazz
    2013-12-25 22:33 - 2013-12-25 22:33 - 0000268 ___RH () C:\ProgramData\Light Machine
    EmptyTemp:


    Po wykonaniu zamiesc nowe logi z FRST, ze skanowania.

    0
  • #3 21 Maj 2017 09:51
    spike111
    Poziom 7  

    zrobiłem tak jak kazałeś, nie znalazłem tylko tego do usunięcia C:\Users\www\AppData\Local\Google\Chrome\User Data\ChromeDefaultData
    CHR Extension: (Визуальные Закладки Mail.Ru) - ale przeglądarki działają teraz dobrze
    W załączeniu przesyłam pliki.

    0
  • Pomocny post
    #4 21 Maj 2017 10:15
    Kolobos
    Spec od komputerów

    Nowy Fixlist.txt dla FRST:
    CloseProcesses:
    AlternateDataStreams: C:\Windows:AstInfo [0]
    ShellIconOverlayIdentifiers: [TortoiseOverlay] -> {CBF88FC2-F150-4F29-BC80-CE30EFD1B62C} => C:\Users\www\AppData\Roaming\Subversion\TortoiseSVN.dll -> Brak pliku
    CHR HKLM\...\Chrome\Extension: [epgjfmblhacacphaljkdcjllkomdcjpc] - hxxps://clients2.google.com/service/update2/crx
    U3 adr741hb; C:\Windows\system32\Drivers\adr741hb.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
    2017-05-16 18:46 - 2017-05-16 18:46 - 63035592 _____ (Malwarebytes ) C:\Users\www\Downloads\Malwarebytes Free 3.1.2.1733 [1].exe
    2017-05-16 18:35 - 2017-05-16 18:35 - 04102600 _____ C:\Users\www\Downloads\adwcleaner_6.046(3).exe
    2017-05-16 18:10 - 2017-05-16 18:10 - 04102600 _____ C:\Users\www\Downloads\adwcleaner_6.046(2).exe
    2017-05-16 17:52 - 2017-05-16 17:52 - 04102600 _____ C:\Users\www\Downloads\adwcleaner_6.046(1).exe
    2017-05-13 09:11 - 2017-05-13 09:11 - 04102600 _____ C:\Users\www\Downloads\adwcleaner_6.046_www.INSTALKI.pl.exe
    2013-07-13 20:28 - 2013-12-25 22:34 - 0000268 ___RH () C:\Users\www\AppData\Roaming\InkjetPrinter
    2013-07-13 20:28 - 2013-12-25 22:35 - 0000268 ___RH () C:\Users\www\AppData\Roaming\Installer Plugin
    2013-07-13 20:28 - 2013-12-25 22:34 - 0000268 ___RH () C:\Users\www\AppData\Roaming\Instrument Library
    2013-12-25 22:33 - 2013-12-25 22:33 - 0000268 ___RH () C:\Users\www\AppData\Roaming\LaunchAgents
    2014-07-15 19:25 - 2014-10-14 19:32 - 0000000 _____ () C:\Users\www\AppData\Roaming\Receipts


    Po wykonaniu usun katalog C:\FRST.

    Zrob pelny skan przy pomocy Mbam i usun to co wykryje:
    http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
    oraz http://ftp.drweb.com/pub/drweb/cureit/launch.exe

    To wszystko.

    0
  • #5 22 Maj 2017 23:16
    spike111
    Poziom 7  

    Dziękuję wszystko działa jak należy:)

    0