Pomoc-trojanci

2

Pomoc-trojanci

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

ComboFix 09-02-26.02 - bojana 2009-02-28 15:42:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.256.66 [GMT 1:00]
Running from: c:\documents and settings\bojana\Desktop\ComboFix.exe
AV: Eset NOD32 antivirus system 2.51 *On-access scanning disabled* (Updated)
AV: F-Secure Anti-Virus Client Security 5.55 *On-access scanning enabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams.
ADS - explorer.exe: deleted 100 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 15:12 . 2009-02-28 15:12 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\bojana\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-28 14:19 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 14:17 . 2009-02-28 14:17 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-27 19:08 . 2009-02-28 15:08 <DIR> d-------- C:\USBNoRisk
2009-02-27 10:24 . 2009-02-27 10:24 537,088 -r-hs---- c:\windows\system\wmibus.exe
2009-02-27 10:23 . 2009-02-27 10:24 537,088 --a------ c:\windows\system32\fr.exe
2009-02-27 09:58 . 2009-02-27 19:06 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-27 09:58 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-27 09:58 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-27 09:58 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-27 09:58 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-02-27 09:58 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-27 09:57 . 2009-02-27 10:11 <DIR> d-------- c:\program files\Trojan Remover
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\bojana\Application Data\Simply Super Software
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a--c--- c:\windows\system32\dllcache\fetnd5.sys
2009-02-27 06:56 . 2009-02-27 06:55 537,088 --a------ c:\windows\system\wmibus.exe.vir
2009-02-27 06:55 . 2009-02-27 06:55 537,088 --a------ c:\windows\system32\hn.exe
2009-02-26 12:23 . 2009-02-26 12:23 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-26 11:53 . 2009-02-26 11:53 530,944 --a------ c:\windows\system32\ml.exe
2009-02-26 08:26 . 2009-02-26 08:26 530,944 --a------ c:\windows\system32\yj.exe
2009-02-26 08:25 . 2009-02-26 08:25 530,944 --a------ c:\windows\system32\hz.exe
2009-02-26 08:25 . 2009-02-26 08:25 530,944 --a------ c:\windows\system\wmisys.exe.vir

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 05:09 --------- d-----w c:\program files\ESET
2006-10-11 08:04 61,036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2006-09-02 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GW Port Controller"="c:\progra~1\samsung\smarthru\PORTCTRL.EXE" [2004-02-09 163840]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-05-31 921600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-02-15 1214856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 10:18 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\hz.exe"=
"c:\\WINDOWS\\System32\\yj.exe"=
"c:\\WINDOWS\\System32\\ml.exe"=
"c:\\Program Files\\RZZO\\Apoteka 2.1\\Obrada Recepata.exe"=
"c:\\WINDOWS\\system\\wmibus.exe"=

S2 WMIBUS;WMI Bus Database; [x]
S2 WMISYS;WMI System App; [x]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [2006-03-18 9344]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NTMSSVC
*NewlyCreated* - SYSMONLOG
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\bojana\Application Data\Mozilla\Firefox\Profiles\9wde14uz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-28 15:44:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\imon.dll
.
Completion time: 2009-02-28 15:47:08
ComboFix-quarantined-files.txt 2009-02-28 14:46:51

Pre-Run: 2,688,925,696 bytes free
Post-Run: 2,793,836,544 bytes free

131

Dopuna: 28 Feb 2009 16:14

jel to to?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ponovo iskljuci Nod.

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\system\wmibus.exe
c:\windows\system32\fr.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system32\hn.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe
c:\windows\system32\hz.exe
c:\windows\system\wmisys.exe.vir

Driver::
WMIBUS
WMISYS

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\hz.exe"=-
"c:\\WINDOWS\\System32\\yj.exe"=-
"c:\\WINDOWS\\System32\\ml.exe"=-
"c:\\WINDOWS\\system\\wmibus.exe"=-


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

evo ga:

ComboFix 09-02-26.02 - bojana 2009-02-28 16:25:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.256.33 [GMT 1:00]
Running from: c:\documents and settings\bojana\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\bojana\Desktop\CFScript.txt
AV: Eset NOD32 antivirus system 2.51 *On-access scanning disabled* (Updated)
AV: F-Secure Anti-Virus Client Security 5.55 *On-access scanning enabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\system\wmibus.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system\wmisys.exe.vir
c:\windows\system32\fr.exe
c:\windows\system32\hn.exe
c:\windows\system32\hz.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system\wmibus.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system\wmisys.exe.vir
c:\windows\system32\fr.exe
c:\windows\system32\hn.exe
c:\windows\system32\hz.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WMIBUS
-------\Legacy_WMISYS
-------\Service_WMIBUS
-------\Service_WMISYS


((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 15:12 . 2009-02-28 15:12 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\bojana\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-28 14:19 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 14:17 . 2009-02-28 14:17 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-27 19:08 . 2009-02-28 15:08 <DIR> d-------- C:\USBNoRisk
2009-02-27 09:58 . 2009-02-27 19:06 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-27 09:58 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-27 09:58 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-27 09:58 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-27 09:58 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-02-27 09:58 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-27 09:57 . 2009-02-27 10:11 <DIR> d-------- c:\program files\Trojan Remover
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\bojana\Application Data\Simply Super Software
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a--c--- c:\windows\system32\dllcache\fetnd5.sys
2009-02-26 12:23 . 2009-02-26 12:23 <DIR> d-------- c:\windows\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 05:09 --------- d-----w c:\program files\ESET
2006-10-11 08:04 61,036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-02-28_15.45.13.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-02-28 15:31:00 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_6dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2006-09-02 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GW Port Controller"="c:\progra~1\samsung\smarthru\PORTCTRL.EXE" [2004-02-09 163840]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-05-31 921600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-02-15 1214856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 10:18 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\RZZO\\Apoteka 2.1\\Obrada Recepata.exe"=

S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [2006-03-18 9344]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\bojana\Application Data\Mozilla\Firefox\Profiles\9wde14uz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-28 16:31:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2009-02-28 16:36:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-28 15:36:46
ComboFix2.txt 2009-02-28 14:47:10

Pre-Run: 2,820,771,840 bytes free
Post-Run: 2,744,020,992 bytes free

150

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ima li kakvih problema sada?

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

sad je cini mi se sve ok
Jesi raspolozen za jos jednog pacijenta, izgleda da je odatle potekla zaraza?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

bojanp ::sad je cini mi se sve ok
Jesi raspolozen za jos jednog pacijenta, izgleda da je odatle potekla zaraza?


Moze, ali neka otvori novu temu.

Ti uradi jos ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

ok, hvala puno

Ko je trenutno na forumu
 

Ukupno su 752 korisnika na forumu :: 31 registrovanih, 5 sakrivenih i 716 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: anbeast, bojank, bojcistv, BSD, Bubimir, Dimitrije Paunovic, DPera, Georgius, goxin, havoc995, ILGromovnik, Karla, kihot, kripo, m0nstrum_, Majka, Mi lao shu, Mixelotti, Nemanja.M, novator, r77adder, Rogan33, slonic_tonic, Stija zmija, tubular, vaso1, Vlad000, Vlajman1957, vrag81, zixmix, šumar bk2