wonz
(Szymon Wiencek)
5 Czerwiec 2007 23:50
#1
siema
mam MKS 2007 i wykryl on 2 wirusy (trojan.copier i dropper.small) ale nie potrafi ich skutecznie usunac. dodatkowo mam problemy zo otwiraniem dyskow --> blac xcopy.exe . dodam takze ze hijjackthis tez jakis blad podczas skanowania wywalil na poczatku.
Logfile of HijackThis v1.99.1 Scan saved at 01:46:07, on 2007-06-06 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Program Files\mks_vir_2007\bin\MksFwall.exe C:\Program Files\mks_vir_2007\bin\MksPC.exe C:\Program Files\mks_vir_2007\bin\mksupdate.exe C:\Program Files\mks_vir_2007\bin\mksvirmonsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\RbtProt\sgsrv.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\system32\CTHELPER.EXE C:\Program Files\Razer\razerhid.exe C:\Program Files\mks_vir_2007\bin\mkstray.exe C:\Program Files\mks_vir_2007\bin\mksregmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\Razer\razertra.exe C:\Program Files\Razer\razerofa.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\SkypePM.exe G:\programy\HijJackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - Default URLSearchHook is missing F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing) O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM…\Run: [ethernet] msnger.exe O4 - HKLM…\Run: [sghRCOLB] C:\WINDOWS\hsnugqa.exe O4 - HKLM…\Run: [msxct] msxct.exe O4 - HKLM…\Run: [sgh$vůőš/‚˛‘ĆßfĎNbC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\hsnugqa.exe O4 - HKLM…\Run: [Áł# é"h’ţ9ÓśU3rŲWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\hsnugqa.exe O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [WINDVDPatch] CTHELPER.EXE O4 - HKLM…\Run: [updReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM…\Run: [Jet Detection] “C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” O4 - HKLM…\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM…\Run: [razer] C:\Program Files\Razer\razerhid.exe O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime O4 - HKLM…\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM…\Run: [Resume copy] copyfstq.exe /startup O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [nwiz] nwiz.exe /install O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM…\Run: [RavTimeXP] C:\WINDOWS\Mstray.exe O4 - HKLM…\Run: [GXHO] C:\WINDOWS\Sys\GXHO.exe O4 - HKLM…\Run: [PDF Converter Registry Controller] “C:\Program Files\ScanSoft\PDF Converter\RegistryController.exe” O4 - HKLM…\Run: [mkstray] C:\Program Files\mks_vir_2007\bin\mkstray.exe O4 - HKLM…\Run: [smartSync - ScheduleSync] C:\PROGRA~1\MOBILE~1\SMARTS~1\SCHEDU~1.EXE O4 - HKLM…\Run: [MKSRegMon] C:\Program Files\mks_vir_2007\bin\mksregmon.exe O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM…\RunServices: [ethernet] msnger.exe O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU…\Run: [NBJ] “C:\Program Files\Ahead\Nero BackItUp\NBJ.exe” O4 - HKCU…\Run: [steelSecurity] “C:\Program Files\BullGuard Ltd.\SteelSecurity\SteelSecurity.exe” O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: MagicTune3.5.lnk = ? O4 - Global Startup: RtlWake.lnk = ? O8 - Extra context menu item: &Search - http://kc.bar.need2find.com/KC/menusearch.html?p=KC O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\PDF Converter\IEShellExt.dll /100 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2007\bin\mkslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2007\bin\mkslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2007\bin\mkslsp.dll O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2007\bin\mkslsp.dll O17 - HKLM\System\CCS\Services\Tcpip…{AF7AB969-1F83-4D72-AD36-A18F62FA4A03}: NameServer = 213.199.207.2 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll O20 - Winlogon Notify: rpccd - C:\WINDOWS\system32\rpccd.dll (file missing) O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: MksFwall - MKS Sp z o.o. - C:\Program Files\mks_vir_2007\bin\MksFwall.exe O23 - Service: MksPC - Unknown owner - C:\Program Files\mks_vir_2007\bin\MksPC.exe O23 - Service: MksUpdate - MKS Sp. z o. o. - C:\Program Files\mks_vir_2007\bin\mksupdate.exe O23 - Service: mks_vir file monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\mks_vir_2007\bin\mksvirmonsvc.exe O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\mks_vir_2007\bin\mks_scan.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoftGuard Service (SG_Service) - Unknown owner - C:\Program Files\Common Files\RbtProt\sgsrv.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
z gory dzieki za pomoc
Złączono Posta : 06.06.2007 (Sro) 9:27
zaden moderator ani admin mi nie pomorze ? doda ze przy starcie systemu wyskakuje mi ze nie znaleziono svhosta help pls
Gutek
(Gutek)
6 Czerwiec 2007 12:12
#2
nikt nie siedzi 24h na dobę.
w trybie awaryjnym usuń wpisy HJT, a pliki i foldery zaznaczone an czerwono ręcznie. Przed usuwaniem użyj Windows Worms Doors Cleanera zmień znaczki z disable na enable. Po użyciu tego narzędzia wymagany jest reset sysa.
Daj log z Combofix
wonz
(Szymon Wiencek)
6 Czerwiec 2007 14:23
#3
sorki za niecierpliwosc ale sesja w toku i musze miec sprawny komputer a ty jakies wirusy nie usunolem wszystkich wpisow HJT gdzy zanim mi odpisales uzylem spy dostora i podejzewam ze on niektore wywalil. a MKS dalej co jakis czas wykrywa jakies wirusy plik host.exe a wir small dropper
“szymon” - 2007-06-06 16:14:00 Dodatek Service Pack 2 NTFS ComboFix 07-06-3B - Running from: “C:\Documents and Settings\szymon\Pulpit\Firefox dl” ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) c:\autorun.inf C:\WINDOWS\autorun.inf e:\autorun.inf f:\autorun.inf g:\autorun.inf ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\nm ((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-06 ))))))))))))))))))))))))))))))) 2007-06-06 15:52 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 15:52 2007-06-06 09:15 2007-06-06 09:06 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2007-06-06 09:06 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-06-06 09:06 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2007-06-06 09:06 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-06-06 09:06 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys 2007-06-06 09:06 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2007-06-06 09:06 2007-06-06 09:06 2007-05-13 22:12 2007-05-11 20:31 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2019-12-07 21:56:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2019-12-07 21:56:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2019-12-07 21:56:00 180,224 ----a-w C:\WINDOWS\system32\nvudisp.exe 2007-06-06 14:17:02 24 ----a-w C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat 2007-06-06 14:17:02 24 ----a-w C:\WINDOWS\system32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat 2007-06-06 00:00:50 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\U3 2007-06-05 23:52:56 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\Skype 2007-06-05 14:59:24 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\uTorrent 2007-06-03 22:43:27 -------- d-----w C:\Program Files\HLSW 2007-05-28 19:40:50 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\teamspeak2 2007-04-24 22:19:24 -------- d-----w C:\Program Files\K-Lite Codec Pack 2007-04-23 22:51:23 -------- d-----w C:\Program Files\LD-Anime 2007-04-21 19:23:31 88 ----a-w C:\WINDOWS\system32\buyurl0502.dat 2007-04-17 14:46:25 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-04-17 14:46:10 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\InstallShield 2007-04-11 23:28:52 -------- d-----w C:\DOCUME~1\szymon\DANEAP~1\Vso 2007-04-11 21:56:57 47,360 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys 2007-04-11 21:56:56 -------- d-----w C:\Program Files\vso 2007-04-11 12:39:53 91,136 ----a-w C:\WINDOWS\system32\drivers\susbser.sys 2007-04-11 12:39:38 -------- d-----w C:\Program Files\BenQ 2007-03-29 21:13:10 67,078 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-03-29 21:13:10 435,978 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-03-28 13:10:50 11,776 ----a-w C:\WINDOWS\system32\mksidsf.sys 2007-03-19 21:43:57 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-03-09 10:45:47 249,856 ------w C:\WINDOWS\Setup1.exe 2007-03-09 10:45:46 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE 2007-03-06 16:09:05 6,144 ----a-w C:\WINDOWS\system32\mksidsa.sys 2007-03-06 16:09:04 15,360 ----a-w C:\WINDOWS\system32\mksfwallt.sys 2007-03-06 16:09:02 13,312 ----a-w C:\WINDOWS\system32\mksfwallf.sys ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll [2003-05-15 00:47] {53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04] {AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 01:03] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “WINDVDPatch”=“CTHELPER.EXE” [2002-07-02 11:56 C:\WINDOWS\system32\CTHELPER.EXE] “CTStartup”=“C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe” [2001-12-20 02:00] “razer”=“C:\Program Files\Razer\razerhid.exe” [2005-05-17 19:21] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2005-11-23 00:44] “Easy-PrintToolBox”=“C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe” [2004-01-14 03:10] “Resume copy”=“copyfstq.exe” [2006-01-23 01:50 C:\WINDOWS\copyfstq.exe] “nwiz”=“nwiz.exe” [2006-03-17 09:31 C:\WINDOWS\system32\nwiz.exe] “PDF Converter Registry Controller”=“C:\Program Files\ScanSoft\PDF Converter\RegistryController.exe” [2003-09-09 13:25] “mkstray”=“C:\Program Files\mks_vir_2007\bin\mkstray.exe” [2007-03-20 18:35] “SmartSync - ScheduleSync”=“C:\PROGRA~1\MOBILE~1\SMARTS~1\SCHEDU~1.EXE” [2006-02-02 16:50] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “NBJ”=“C:\Program Files\Ahead\Nero BackItUp\NBJ.exe” [2004-09-07 12:55] “Steam”="" [] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\MkS_Scan] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Acrobat Assistant.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Acrobat Assistant.lnk backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^MagicTune3.5.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\MagicTune3.5.lnk backup=C:\WINDOWS\pss\MagicTune3.5.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^RtlWake.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\RtlWake.lnk backup=C:\WINDOWS\pss\RtlWake.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection] “C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SteelSecurity] “C:\Program Files\BullGuard Ltd.\SteelSecurity\SteelSecurity.exe” HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\ mountpoints2{6cc9fb46-076b-11dc-9202-00111e110317}] AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\ mountpoints2{a6f80103-9f51-11db-b37c-00111e110317}] AutoRun\command- D:\LaunchU3.exe -a ************************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-06 16:17:52 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???h???s???w? ?w???w???w4???.??w4???4???TA?s4???&7???w???w???\ ???U??w???w?????????C@?\???\??????s????\??????s\??? ?&7?A??s?&7??C@?x???
|?w???@ scanning hidden files … ************************************************************************** Completion time: 2007-06-06 16:19:12 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-06-06 16:18 — E O F —
adam9870
(adam9870)
7 Czerwiec 2007 09:03
#6
Log jest ucięty. Proszę umieścić pliki z logami w formie plików *.txt w jakimś ogólnodostępnym serwisie hostingowym bądź skorzystać z serwisów typu http://wklej.org/
wonz
(Szymon Wiencek)
7 Czerwiec 2007 13:40
#7
lol sory juz poprawiam
Złączono Posta : 07.06.2007 (Czw) 16:13
dobra juz jest oto link do loga z gmer na megaupload http://www.megaupload.com/pl/?d=YT2F3ARQ
Złączono Posta : 08.06.2007 (Pią) 15:47
Gutek zacny czlowieku pomoz