Pomoc-trojanci

2

Pomoc-trojanci

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

ComboFix 09-02-26.02 - bojana 2009-02-28 15:42:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.256.66 [GMT 1:00]
Running from: c:\documents and settings\bojana\Desktop\ComboFix.exe
AV: Eset NOD32 antivirus system 2.51 *On-access scanning disabled* (Updated)
AV: F-Secure Anti-Virus Client Security 5.55 *On-access scanning enabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams.
ADS - explorer.exe: deleted 100 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 15:12 . 2009-02-28 15:12 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\bojana\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-28 14:19 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 14:17 . 2009-02-28 14:17 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-27 19:08 . 2009-02-28 15:08 <DIR> d-------- C:\USBNoRisk
2009-02-27 10:24 . 2009-02-27 10:24 537,088 -r-hs---- c:\windows\system\wmibus.exe
2009-02-27 10:23 . 2009-02-27 10:24 537,088 --a------ c:\windows\system32\fr.exe
2009-02-27 09:58 . 2009-02-27 19:06 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-27 09:58 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-27 09:58 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-27 09:58 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-27 09:58 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-02-27 09:58 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-27 09:57 . 2009-02-27 10:11 <DIR> d-------- c:\program files\Trojan Remover
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\bojana\Application Data\Simply Super Software
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a--c--- c:\windows\system32\dllcache\fetnd5.sys
2009-02-27 06:56 . 2009-02-27 06:55 537,088 --a------ c:\windows\system\wmibus.exe.vir
2009-02-27 06:55 . 2009-02-27 06:55 537,088 --a------ c:\windows\system32\hn.exe
2009-02-26 12:23 . 2009-02-26 12:23 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-26 11:53 . 2009-02-26 11:53 530,944 --a------ c:\windows\system32\ml.exe
2009-02-26 08:26 . 2009-02-26 08:26 530,944 --a------ c:\windows\system32\yj.exe
2009-02-26 08:25 . 2009-02-26 08:25 530,944 --a------ c:\windows\system32\hz.exe
2009-02-26 08:25 . 2009-02-26 08:25 530,944 --a------ c:\windows\system\wmisys.exe.vir

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 05:09 --------- d-----w c:\program files\ESET
2006-10-11 08:04 61,036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2006-09-02 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GW Port Controller"="c:\progra~1\samsung\smarthru\PORTCTRL.EXE" [2004-02-09 163840]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-05-31 921600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-02-15 1214856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 10:18 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\hz.exe"=
"c:\\WINDOWS\\System32\\yj.exe"=
"c:\\WINDOWS\\System32\\ml.exe"=
"c:\\Program Files\\RZZO\\Apoteka 2.1\\Obrada Recepata.exe"=
"c:\\WINDOWS\\system\\wmibus.exe"=

S2 WMIBUS;WMI Bus Database; [x]
S2 WMISYS;WMI System App; [x]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [2006-03-18 9344]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NTMSSVC
*NewlyCreated* - SYSMONLOG
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
DPF: DirectAnimation Java Classes - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\bojana\Application Data\Mozilla\Firefox\Profiles\9wde14uz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-28 15:44:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\imon.dll
.
Completion time: 2009-02-28 15:47:08
ComboFix-quarantined-files.txt 2009-02-28 14:46:51

Pre-Run: 2,688,925,696 bytes free
Post-Run: 2,793,836,544 bytes free

131

Dopuna: 28 Feb 2009 16:14

jel to to?



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8628
  • Gde živiš: Novi Beograd

Ponovo iskljuci Nod.

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\system\wmibus.exe
c:\windows\system32\fr.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system32\hn.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe
c:\windows\system32\hz.exe
c:\windows\system\wmisys.exe.vir

Driver::
WMIBUS
WMISYS

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\hz.exe"=-
"c:\\WINDOWS\\System32\\yj.exe"=-
"c:\\WINDOWS\\System32\\ml.exe"=-
"c:\\WINDOWS\\system\\wmibus.exe"=-


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.



offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

evo ga:

ComboFix 09-02-26.02 - bojana 2009-02-28 16:25:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.256.33 [GMT 1:00]
Running from: c:\documents and settings\bojana\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\bojana\Desktop\CFScript.txt
AV: Eset NOD32 antivirus system 2.51 *On-access scanning disabled* (Updated)
AV: F-Secure Anti-Virus Client Security 5.55 *On-access scanning enabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\system\wmibus.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system\wmisys.exe.vir
c:\windows\system32\fr.exe
c:\windows\system32\hn.exe
c:\windows\system32\hz.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system\wmibus.exe
c:\windows\system\wmibus.exe.vir
c:\windows\system\wmisys.exe.vir
c:\windows\system32\fr.exe
c:\windows\system32\hn.exe
c:\windows\system32\hz.exe
c:\windows\system32\ml.exe
c:\windows\system32\yj.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WMIBUS
-------\Legacy_WMISYS
-------\Service_WMIBUS
-------\Service_WMISYS


((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 15:12 . 2009-02-28 15:12 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\bojana\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-28 14:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-28 14:19 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-28 14:19 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 14:17 . 2009-02-28 14:17 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-27 19:08 . 2009-02-28 15:08 <DIR> d-------- C:\USBNoRisk
2009-02-27 09:58 . 2009-02-27 19:06 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-27 09:58 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-27 09:58 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-27 09:58 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-27 09:58 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-02-27 09:58 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-27 09:57 . 2009-02-27 10:11 <DIR> d-------- c:\program files\Trojan Remover
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\bojana\Application Data\Simply Super Software
2009-02-27 09:57 . 2009-02-27 09:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
2009-02-27 09:39 . 2001-08-17 12:13 27,165 --a--c--- c:\windows\system32\dllcache\fetnd5.sys
2009-02-26 12:23 . 2009-02-26 12:23 <DIR> d-------- c:\windows\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 05:09 --------- d-----w c:\program files\ESET
2006-10-11 08:04 61,036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-02-28 15:31:00 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_6dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2006-09-02 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GW Port Controller"="c:\progra~1\samsung\smarthru\PORTCTRL.EXE" [2004-02-09 163840]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-05-31 921600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-02-15 1214856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 10:18 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\RZZO\\Apoteka 2.1\\Obrada Recepata.exe"=

S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [2006-03-18 9344]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
DPF: DirectAnimation Java Classes - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\bojana\Application Data\Mozilla\Firefox\Profiles\9wde14uz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-28 16:31:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2009-02-28 16:36:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-28 15:36:46
ComboFix2.txt 2009-02-28 14:47:10

Pre-Run: 2,820,771,840 bytes free
Post-Run: 2,744,020,992 bytes free

150

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8628
  • Gde živiš: Novi Beograd

Ima li kakvih problema sada?

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

sad je cini mi se sve ok
Jesi raspolozen za jos jednog pacijenta, izgleda da je odatle potekla zaraza?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8628
  • Gde živiš: Novi Beograd

bojanp ::sad je cini mi se sve ok
Jesi raspolozen za jos jednog pacijenta, izgleda da je odatle potekla zaraza?


Moze, ali neka otvori novu temu.

Ti uradi jos ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 46

ok, hvala puno

Ko je trenutno na forumu
 

Ukupno su 2171 korisnika na forumu :: 89 registrovanih, 8 sakrivenih i 2074 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 4719 - dana 07 Dec 2025 13:00

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, 6.5lapua, 9191vs, A.R.Chafee.Jr., Ailton, ArchaBasha, Belac91, bobo85, bojanstros9, bolimejoli, Botovac, Cicumile, Crazzer, croato, darionis, darkkran, Dogma21, Dorcolac, dradex, dragan_mig31, dulleo, Ercomero, goxin, Hardenberg, HogarStrashni, igorkozar83, ikan, ivica976, jeen yuhs, Jovan1983, Kamov, kolle.the.kid, kozhedub, Kozi-RS, Kudun, LastTsar, Leonov, Malahit, Marko00, marko_s, Markovic, MB120mm, Mcdado, mdp92, mkukoleca, mocnijogurt, moldway, museum, mxzzz, nelezele, nemkea71, neutrino, nevjerna beba, Nmr, oldtimer, Oscar, Panter, pceklic, Pilence, ping15, Pururin, rodoljub, ruma, samocitam, sap, sasa87, Singidunumac, Skywhaler, sluga, sparkie, sspp, Stanislav1970, starlights, stegonosa, Tila Painen, tooljan, TTN, Vanderx, vathra, VekiJ, vlad4, vladetije, Vrač, vrlenija, zaoka, zrno, zvomar, Čivi, 79693