L3moN Opublikowano 15 Grudnia 2015 Zgłoś Udostępnij Opublikowano 15 Grudnia 2015 Od wczoraj zamiast google mam coś cco nazywa się yoursites123 jak to usunąć? Addition.txt FRST.txt Shortcut.txt Odnośnik do komentarza
picasso Opublikowano 16 Grudnia 2015 Zgłoś Udostępnij Opublikowano 16 Grudnia 2015 (edytowane) W systemie są także inne obiekty adware niedokładnie wcześniej wyczyszczone. I używałeś wątpliwy skaner-naciągacz SpyHunter. Działania do przeprowadzenia: 1. Klawisz z flagą Windows + X > Programy i funkcje > odinstaluj Lenovo Experience Improvement (zbędny program), Shared C Run-time for x64 (odpadek po odinstalowanym McAfee), Visual Studio 2012 x64 Redistributables, Visual Studio 2012 x86 Redistributables (odpadki po odinstalowanym AVG), WinZipper (adware). 2. Otwórz Notatnik i wklej w nim: CloseProcesses: CreateRestorePoint: S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-15] () R2 EMUpdateCerter; C:\WINDOWS\SysWOW64\acmphelper.dll [413312 2015-08-11] () R2 IhPul; C:\Users\Paweł Górniak\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\FWdMF\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [brak podpisu cyfrowego] S2 Update Mgr StrongSignal; "C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe" [X] ShortcutWithArgument: C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP ShortcutWithArgument: C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP ShortcutWithArgument: C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} HKU\S-1-5-21-720095144-239407429-1005869762-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKU\S-1-5-21-720095144-239407429-1005869762-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKU\S-1-5-21-720095144-239407429-1005869762-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} SearchScopes: HKU\S-1-5-21-720095144-239407429-1005869762-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} SearchScopes: HKU\S-1-5-21-720095144-239407429-1005869762-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP&q={searchTerms} BHO-x32: Outrageous Deal -> {4e2d2bf0-159f-4257-acf0-b1f29b376fa0} -> C:\Program Files (x86)\Outrageous Deal\Extensions\4e2d2bf0-159f-4257-acf0-b1f29b376fa0.dll => Brak pliku StartMenuInternet: IEXPLORE.EXE - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP Edge HomeButtonPage: HKU\S-1-5-21-720095144-239407429-1005869762-1001 -> hxxp://www.yoursites123.com/?type=hp&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml [2015-11-08] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yoursites123.xml [2015-12-14] CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12] CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1450098558&z=0dcc66ecc53dc5d9e42c5dfg7z4w6e8e4t4b5w1q2c&from=wpm07173&uid=ST500LT012-1DG142_S3PA77MPXXXXS3PA77MP HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey HKLM\...\Policies\Explorer\Run: [btvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku Task: {0021258B-87B2-4F60-AA08-6B40B964CC7C} - System32\Tasks\060184C3-9766-46a0-B258-F4518A0B2633 => Cscript.exe "C:\ProgramData\Baidu Security\Duplicaterecord.js" Task: {0BC296D3-82FF-45DB-8D3A-BBFD7690404D} - System32\Tasks\{34DD01EF-567E-42A1-BFCB-306A9D310B5E} => pcalua.exe -a E:\cda_menu.exe -d E:\ Task: {32CCA36A-2803-4FE0-999C-130809AA7FF1} - System32\Tasks\{42ACF313-65EB-4EF1-AA36-445592C23BA6} => pcalua.exe -a "C:\Program Files (x86)\Picexa\uninstall.exe" Task: {406853A0-5944-48C2-B288-498562E1001F} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku Task: {49DFFE06-333D-43DB-8CA9-470FAF3C3171} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku Task: {5600E372-75E4-4B05-AEDB-23419BC5EB8E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku Task: {5D3345B5-BAAE-4320-B0BE-C559B863B13F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku Task: {5FEC6432-3CFE-4328-B956-63AA674D9793} - System32\Tasks\GridinSoft Anti-Malware => C:\Program Files\GridinSoft Anti-Malware\gsam.exe Task: {6836728A-07B3-42AD-A58B-63E244555E9B} - System32\Tasks\{17621E5A-F836-408A-832B-DBE288A9BA20} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.1.0.105&LastError=404 Task: {7463128C-F39E-4110-9989-FED9BDDC526C} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku Task: {75BD2D36-66CD-4341-B908-D08894DAAE07} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku Task: {771EF641-DC2B-404A-99CC-0624ECB5113A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku Task: {A7E8226C-4FA3-46C9-8F54-7A061589846A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku Task: {AC165305-C41A-4C67-9B3A-7DF095193A74} - System32\Tasks\{EB8E6220-3EE5-4D1E-9323-A2EBF73BFE10} => pcalua.exe -a "C:\Program Files (x86)\Intel\OpenCL SDK\2.0\Uninstall\setup.exe" -c -uninstall Task: {AD03708F-9706-455C-B753-BAE3731B572D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku Task: {B75CC2E1-4FE8-46A4-B89B-9FE02B7FA729} - System32\Tasks\{AF520519-AF68-49F7-A239-84C1AC1ED8AA} => pcalua.exe -a E:\Uruchom.EXE -d E:\ Task: {C9117321-AE5B-4792-A0D9-28CB53066E75} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku Task: {DA013BC4-3717-4FE8-9977-BAAB986F2A52} - System32\Tasks\{CADBE078-04E5-4119-B7CF-8EF9194BC924} => pcalua.exe -a E:\AutoRun.exe -d E:\ Task: {E4091DD4-C60C-43FF-8A5F-320ED28DDCC5} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-11-21] (Lenovo) Task: {FB743EF0-CF80-45E1-92A1-3A7ACF20769A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedHomepages /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedSearchScopes /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\OpenSearch" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\yoursites123.com" /f DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes RemoveDirectory: C:\Program Files (x86)\AVG RemoveDirectory: C:\Program Files (x86)\FreeCodecPack RemoveDirectory: C:\Program Files (x86)\Freemake RemoveDirectory: C:\Program Files (x86)\SFK RemoveDirectory: C:\Program Files (x86)\WinZipper RemoveDirectory: C:\ProgramData\5WMiniPro5 RemoveDirectory: C:\ProgramData\AVAST Software RemoveDirectory: C:\ProgramData\Freemake RemoveDirectory: C:\ProgramData\FWdMF RemoveDirectory: C:\ProgramData\GridinSoft RemoveDirectory: C:\ProgramData\UWdMU RemoveDirectory: C:\ProgramData\Microsoft\Windows\GameExplorer\{00EBCA8F-FF3C-44B7-A40E-C23676199D2C} RemoveDirectory: C:\ProgramData\Microsoft\Windows\GameExplorer\{33AF943B-79FC-404D-85D1-77B66DAACAF9} RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper RemoveDirectory: C:\Users\Paweł Górniak\AppData\Local\4kdownload.com RemoveDirectory: C:\Users\Paweł Górniak\AppData\Local\Avg RemoveDirectory: C:\Users\Paweł Górniak\AppData\Local\AvgSetupLog RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\AVG RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\DVDVideoSoft RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\RPEng RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\TSv RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\WinZipper RemoveDirectory: C:\Users\Paweł Górniak\AppData\Roaming\YoutubeToMp3Converter C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\ProgramData\hash.dat C:\ProgramData\rxsmznjf.zcp C:\ProgramData\mntemp C:\Users\Paweł Górniak\AppData\Roaming\trace_FilterInstaller.* C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url C:\Users\Paweł Górniak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk C:\Users\Paweł Górniak\Downloads\SpyHunter-Installer (1).exe C:\Users\Paweł Górniak\Downloads\SpyHunter-Installer.exe C:\WINDOWS\System32\Drivers\EsgScanner.sys C:\WINDOWS\System32\Tasks\GridinSoft Anti-Malware C:\WINDOWS\SysWOW64\acmphelper.dll C:\WINDOWS\SysWOW64\data.bin CMD: netsh advfirewall reset EmptyTemp: Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach. Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Napraw (Fix). Czekaj cierpliwie, nie przerywaj działania. Gdy Fix ukończy pracę, system zostanie zresetowany. W tym samym katalogu skąd uruchamiano FRST powstanie plik fixlog.txt. 3. Wyczyść przeglądarki: Firefox: Odłącz synchronizację (o ile włączona): KLIK. Menu Pomoc > Informacje dla pomocy technicznej > Odśwież program Firefox. Zakładki i hasła nie zostaną naruszone. Menu Historia > Wyczyść całą historię przeglądania. Google Chrome: Zresetuj synchronizację (o ile włączona): KLIK. Ustawienia > karta Ustawienia > Osoby > usuń poprzedni nieużywany profil, o ile widać więcej niż dwie "Osoby". 4. Zrób nowy log FRST z opcji Skanuj (Scan), ponownie z Addition, ale bez Shortcut. Dołącz też plik fixlog.txt. Potwierdź, że problemu nie ma także w przeglądarce Edge. Edytowane 2 Czerwca 2016 przez picasso Temat zostaje zamknięty z powodu braku odpowiedzi. //picasso Odnośnik do komentarza
Rekomendowane odpowiedzi