Trojanci, Crv i nepoznato; potreban savet

1

Trojanci, Crv i nepoznato; potreban savet

offline
  • Pridružio: 17 Apr 2006
  • Poruke: 215
  • Gde živiš: Novi Sad

Pre neki dan mi brat doneo rachunar da mu resim problem sa trojancem:) elem

Avast (kutjna verzija 4.7) je registrovao sledece
Trojance: win32.Small-BLF fajl: DLH9JKDQ1.exe
win32.small-AGK fajl: zgame2[1].exe
win32.Tibs-TB fajl: ztool1[1].exe
win32.small-APN fajl: DLH9JKDQ5.exe
win32.small-AGK fajl: VXGAME2.exe
win32.tibs-TB fajl: VXGAMET1.exe
win32.Small-BLF fajl: zgame3[1].exe
Crv: BANWARUM-M fajl: adir.dll

Nepoznato: pritiskanjem kombinacije tastera "CtrlAltDel" dobijam poruku: pristup windows task menadzeru zabranjen od strane administratora. (Da li se ovo nekome desilo? )

Shtetocinama se zarazio na sajtu nostalgija.com pritiskajuci kojekake banere. Stalno se radjaju novi trojanci i Avast im ne moze nishta.
Obzirom da se i sam borim protiv virusa, influenca (scan by "Dr." ), planiram da formatiram HD bratovog PC-a.- Da li ce to reshiti problem?

offline
  • Rogi  Male
  • Mod u pemziji
  • Najbolji košarkaš koji
  • je ikada igrao ovu igru
  • Pridružio: 31 Avg 2005
  • Poruke: 11687

- problemi sa task manager-om
www.mycity.rs/phpbb/viewtopic.php?t=22334
www.mycity.rs/phpbb/viewtopic.php?t=24697
www.mycity.rs/phpbb/viewtopic.php?t=24943
www.mycity.rs/phpbb/viewtopic.php?t=25615

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Jesi li probao skeniranje iz SafeMode-a?
Mozes li te zarazene fajove da mi posaljes spakovane 7zip-om na bobby[_at_]mycity.rs ?

offline
  • Pridružio: 17 Apr 2006
  • Poruke: 215
  • Gde živiš: Novi Sad

@rogi23
Hvala!
Nekoliko puta do sada sam koristio pretragu u okviru "mycity" i bilo je bezuspeshno, probao sam opet i radi pa sam pored linkova koje si ostavio posetio josh neke.

to all:
Pre nekoliko dana kada je problem uochen: skenirao sam Avast-om i AdAware-om iz safe mod-a, iskljuchivao sam "sistem restore".
Nishta nije pomoglo jer su se shtetochine vracale momentalno i uvek u vecem broju.
Racunar sa sve internetom (dial up) radi usporeno, avast viche "virus je pronadjen" kao pokvarena plocha, nemam pristup TaskManager-u... sve to me nateralo na Format C: .
Pitao sam da li ce formatiranje HD-a pomoci?, iz razloga sto dugo nisam imao slicnih problema pa rekoh da proverim da virusi nisu mozda postali otporni na "Format C:" .

@bobby
Nashao sam 7-zip, kada prikljucim zarazeni PC, pre formatiranja, cu pokushati da povatam shtetochine i 7zipiujem.
Koliko sam shvatio: treba da prema putanjama, koje mi Avast bude dao, nadjem zarazene fajlove i 7zipujem svaki posebno.


Da li ljudi iz AV kompanija krstare internetom i klikcu po kojekakim banerima i tako sakupljaju viruse, trojance....... ? (pitam se)

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Mozes sve zarazene fajlove da strpas u jednu arhivu, nije potrebno da spakujes svaki posebno.

Sto se formatiranja tice, virusi nisu otporni na formatiranje, ali ne zaboravi da mozda imas zarazene fajlove na drugim particijama ili snimljenim CD-ovima.

Ja nisam pristalica formatiranja paricije kada se naidje na problem, ali neznam koliko imas strpljenja da se ovim pozabavimo rucno.
Ukoliko zelis da se malo mlatimo ovime, kazi, pa da ti napisem uputstva od cega da krenemo.

offline
  • Pridružio: 17 Apr 2006
  • Poruke: 215
  • Gde živiš: Novi Sad

Ma sada i mene interesuje da li mogu da se izborim sa tim "virusima" i da li mogu bez formatiranja da mom starijem bratu podesim racunar da radi stabilno i da bude adekvatno zashticen dok je na "net-u". (on je Pravi pochetnik shto zadatak chini tezim)

Voleo bih pre svega da instaliram ovaj moj SBBmodem na njegov PC pa posle da mu sva podesavanja vratim na njegov "dial-up".

Strpljiv sam a mogao bih skoro svako poslepodne da odvojim po nekoliko sati (ma "neka cheka Ceca") za reshavanje problema.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Procitaj uputstvo sa sledeceg linka. Postupi po uputstvu i postavi nam ovde log-fajl.

offline
  • Pridružio: 17 Apr 2006
  • Poruke: 215
  • Gde živiš: Novi Sad

@bobby
Pishe link ali nema linka. Pretpostavljam da treba HJT Log file da postavim.

btw: Prikljucio sam zarazen racunar i kada prikljucim ptt liniju blokira mi telefone u stanu tako da sam bio primoran da zovem SBB i spojim cable modem
7zip mi nije na engleskom vec holandskom ili slicno pa se tesko snalazim

Dopuna: 02 Nov 2006 18:04

Logfile of HijackThis v1.99.1
Scan saved at 17:15:27, on 2006-11-03
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\kernels8.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Windows\xpupdate.exe
C:\WINDOWS\System32\taskdir.exe
C:\windows\system32\_mzu_stonedrv3.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\dlh9jkdq6.exe
C:\WINDOWS\System32\dlh9jkdq7.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\totalcmd\TOTALCMD.EXE
C:\Documents and Settings\PC Centar NS\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.rs/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PowerMenu] "%systemroot%\system32\powermenu.exe" -hideself on
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels8.exe
O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\kernels8.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\System32\taskdir.exe
O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Izvini za link... znaci starenja (razmisljam o penziji) Smile

Sto se tice loga - brrr, najezio sam se Smile
Jako je hrabro sto niste updateovali Windows, posto vidim da je SP1 instaliran. Pod hitno resiti pitanje upgrade na SP2.

Sledece linije loga su nepozeljni programi i procesi:

C:\WINDOWS\System32\kernels8.exe
C:\Windows\xpupdate.exe
C:\WINDOWS\System32\taskdir.exe
C:\windows\system32\_mzu_stonedrv3.exe
C:\WINDOWS\System32\dlh9jkdq6.exe
C:\WINDOWS\System32\dlh9jkdq7.exe


O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels8.exe
O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\kernels8.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\System32\taskdir.exe
O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll

Osim ovih fajlova, negde mora da je prisutan i taskdir.dll (posto imas taskdir.exe). I on je isto maliciozan.

Udji u Safe Mode, pronadji sve fajlove koje sam nabrojao.
Nemoj ih odmah brisati, vec prvo napravi rezervnu kopiju, tj. spakuj ih sve u ZIP fajl (7zip je bolja solucija, ali u nedostatku istog...).
Kada uspes da napravis rezervnu kopiju, onda brisi.
Ukoliko imas mogucnosti, posalji mi te fajlove na bobby[_at_]mycity.rs, ali u ZIP-u zasticenim lozinkom (opet, sa 7zipom bi ovo bilo daleko lakse...).

Nakon brisanja restartuj komp, i vidi da li se podize desktop.
Preimenuj fajl HijackThis.exe u H1.exe i napravi novi log koji ces da postavis ovde.

Ukoliko Windows ne moze da se podigne, obavezno zapisi poruku o gresci koju prijavljuje, i postavi je ovde.

Ukoliko imas mogucnosti da skines AVG AntySpyware (bivsi Ewido) probaj prvo njime da se resis bede:
http://www.ewido.net/en/download/

Pozdrav i puno srece.

Dopuna: 02 Nov 2006 18:41

btw. nemoj da te mrzi da postavis novi log nakon sto ocistis komp od ovih fajlova, jer je potrebno da sredimo i registry nakon ciscenja.
Moze da se desi i da se neki fajl ponovo pojavi, pa onda moramo da potrazimo gde je dropper ili rootkit.

btw2. nista opasno, sve su matore infekcije u pitanju, i ne bi trebalo da bude tesko da se rese.

offline
  • Pridružio: 17 Apr 2006
  • Poruke: 215
  • Gde živiš: Novi Sad

ne mrzi me nishta
seo sam za racunar veceras reshen da Reshim problem
skinuo sam AVG AntySpyware
pokusavam 7zip naterati da prica engleski

Dopuna: 02 Nov 2006 19:14

jednom u zivotu sam pravio arhivu nekim arhiverom (valjda winRAR-om)
valjda nije komplikovano

Dopuna: 02 Nov 2006 21:56

u safe modu pronasao i zapakovao fajlove sa winzip8.1 (potom obrisao originale)
ne mogu da posaljem (yahoo NEda) probacu jos nekako kasnije
skenirao sa: AdAwareSE personal (nadjena 73 critical entries0
AVG AntiSpyware (jos 24 bad entries)
postavljam HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 21:36:58, on 2006-11-03
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\PC Centar NS\Desktop\HJT\h1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.rs/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PowerMenu] "%systemroot%\system32\powermenu.exe" -hideself on
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels8.exe
O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\kernels8.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\System32\taskdir.exe
O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ko je trenutno na forumu
 

Ukupno su 1257 korisnika na forumu :: 54 registrovanih, 9 sakrivenih i 1194 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, airsuba, Alibaba1981, amonsrb, Apok, aramis s, bagor10, Bobrock1, bokisha253, Boris Bosiljčić, celik, cemix, cifra, dankisha, Darko001, darkstar101, dejina811, djordje92sm, flash12, Georgius, GORDI, goxin, havoc995, HrcAk47, ILGromovnik, ivicasimo, JOntra, kikisp, kjkszpj, Koridor, KOV, krkalon, Krvava Devetka, kybonacci, Litostroton, LUDI, MB120mm, mercedesamg, Mercury, mikrimaus, mile23, moldway, nextyamb, raso7, Reinhardt, Rogan33, Shinobi, slonic_tonic, vathra, wizzardone, wolverined4, Zaledjeni, zixmix, 1107