Za sada bez naslova

1

Za sada bez naslova

offline
  • Pridružio: 17 Sep 2007
  • Poruke: 9

Ovako... klinci su nesto svlacili sa torrenta na muzevljev lap-top, i u jednom trenutku se restartovao i Windows vise nije hteo da se podigne. Inace nema instaliran neki antivirus. Kada se restartuje, Windows krene da se podize do onog prozora kada pita koji user hoce da se uloguje, a onda se na trenutak prikaze plavi ekran sa nekim podacima koji jako brzo prodju i ne vidim sta pise. U safe modu ne mogu da instaliram neki antivirus kako bih eliminisala viruse kao razlog, posto je mozda i hardverski problem - memorija, ili tako nesto? U safe-u sam uspela da odradim log:

Logfile of HijackThis v1.99.1
Scan saved at 10:33:17 AM, on 9/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Kabo\Desktop\New Folder\bb.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com/
F3 - REG:win.ini: run=C:\WINDOWS\ServicePackFiles\winlogon.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: bho3 Class - {58FB2CBB-C874-45FC-A1C9-B62CC9E3BED9} - C:\WINDOWS\system32\916225735.dll
O2 - BHO: (no name) - {6158B5C8-413D-46D4-BE59-C7C1C4260889} - C:\Program Files\ComPlus Applications\hoke4444.dll
O2 - BHO: 0 - {63625F58-EB9B-41DE-939D-142C6764D3D6} - C:\Program Files\Online Services\lavuka.dll
O2 - BHO: (no name) - {9AE7632C-E816-4B41-A4CF-BA794BC205E7} - C:\Program Files\ComPlus Applications\hoke83122.dll
O4 - HKLM\..\Run: [xem] C:\WINDOWS\ServicePackFiles\winlogon.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [Microsoft GLink] C:\WINDOWS\ServicePackFiles\mmxs.exe
O4 - HKLM\..\Run: [GoogleBot.exe] C:\WINDOWS\system32\GoogleBot.exe
O4 - HKLM\..\Run: [Microsoft WWW] C:\WINDOWS\ServicePackFiles\free.exe
O4 - HKLM\..\Run: [Microsoft MDM] C:\WINDOWS\system32\arcac.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [xem] C:\WINDOWS\ServicePackFiles\winlogon.exe
O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
O4 - HKCU\..\Run: [Brave-Sentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} (ProxyModule Class) - online.deltabanka.rs/RetailDLL/SGCMSCCD.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{677666A1-11AB-4C2F-AFDA-54B0A951EA4A}: NameServer = 194.106.162.2,194.106.162.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3D6662F-2615-4A42-96B6-0EE79E0B8E35}: NameServer = 194.106.162.2,194.106.162.3
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wincqt32 - C:\WINDOWS\SYSTEM32\wincqt32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: QLqZBKluSsGPcV - {A8DD2183-0277-8B29-3D6A-83769E049393} - C:\WINDOWS\system32\nbgoth.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

Sta mi je dalje ciniti, i da li uopste ista moze da se uradi osim formatiranja? Hvala.

Sad nadjoh na netu da je ovaj brave sentry u stvari spyware. Da li je moguce da je on napravio ovaj haos? Vidim da ima raznih nacina za njegovo uklanjanje, vredi li pokusati? Ima nesto sto se zove SmitfraudFix. Mogu li njega da upotrebim?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav, masha71...

Kompjuter je u jako lošem stanju i višestruke infekcije su vidljive već na prvi pogled. Takođe, činjenica da ulazak u Normal Mode Windows-a nije moguć, je veoma problematična, te nisam u mogućnosti da ti garantujem da ćemo ovo moći sve rešiti.

No, mislim da treba da pokušamo.

Za početak pronađi sledeće file-ove i upakuj ih u jedan zip:

C:\WINDOWS\system32\916225735.dll
C:\WINDOWS\ServicePackFiles\winlogon.exe
C:\Program Files\ComPlus Applications\hoke4444.dll
C:\Program Files\Online Services\lavuka.dll
C:\Program Files\ComPlus Applications\hoke83122.dll
C:\WINDOWS\system32\spoolsvv.exe
C:\WINDOWS\ServicePackFiles\mmxs.exe
C:\WINDOWS\system32\GoogleBot.exe
C:\WINDOWS\ServicePackFiles\free.exe
C:\WINDOWS\system32\arcac.exe
C:\WINDOWS\system32\vedxg6ame4.exe
c:\windows\system32\ldcore.dll
C:\Documents and Settings\All Users\Documents\Settings\bot.dll
C:\WINDOWS\SYSTEM32\wincqt32.dll
C:\WINDOWS\system32\nbgoth.dll
C:\WINDOWS\system32\aspimgr.exe

a zatim taj zip uploaduj preko sledeće forme:
http://www.mycity.rs/ambulanta-upload.php

Ukoliko ne vidiš neki od nabrojanih file-ova, potrebno je da aktiviraš prikaz skrivenih file-ova/foldera po sledećem uputstvu: http://www.mycity.rs/Uputstva-sa-ex-SuperSajta/Kako-videti-skrivene-fajlove.html

offline
  • Pridružio: 17 Sep 2007
  • Poruke: 9

Izvini, ne videh da si mi odgovorio, ovo dugmence refresh je mnogo dobra stvar ako znas da ga koristis... uploadovala sam fajlove, ako nesto znaci zove se ambulanta.zip. Nisam mogla da iskopiram jedino C:\Documents and Settings\All Users\Documents\Settings\bot.dll, a on ima onaj uzvicnik kao da je inace hidden.

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

1) Pokreni HijackThis, skeniraj i štikliraj sledeće linije:

F3 - REG:win.ini: run=C:\WINDOWS\ServicePackFiles\winlogon.exe
O2 - BHO: bho3 Class - {58FB2CBB-C874-45FC-A1C9-B62CC9E3BED9} - C:\WINDOWS\system32\916225735.dll
O2 - BHO: (no name) - {6158B5C8-413D-46D4-BE59-C7C1C4260889} - C:\Program Files\ComPlus Applications\hoke4444.dll
O2 - BHO: 0 - {63625F58-EB9B-41DE-939D-142C6764D3D6} - C:\Program Files\Online Services\lavuka.dll
O2 - BHO: (no name) - {9AE7632C-E816-4B41-A4CF-BA794BC205E7} - C:\Program Files\ComPlus Applications\hoke83122.dll
O4 - HKLM\..\Run: [xem] C:\WINDOWS\ServicePackFiles\winlogon.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [Microsoft GLink] C:\WINDOWS\ServicePackFiles\mmxs.exe
O4 - HKLM\..\Run: [GoogleBot.exe] C:\WINDOWS\system32\GoogleBot.exe
O4 - HKLM\..\Run: [Microsoft WWW] C:\WINDOWS\ServicePackFiles\free.exe
O4 - HKLM\..\Run: [Microsoft MDM] C:\WINDOWS\system32\arcac.exe
O4 - HKCU\..\Run: [xem] C:\WINDOWS\ServicePackFiles\winlogon.exe
O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
O4 - HKCU\..\Run: [Brave-Sentry] C:\Program Files\BraveSentry\BraveSentry.exe
O21 - SSODL: QLqZBKluSsGPcV - {A8DD2183-0277-8B29-3D6A-83769E049393} - C:\WINDOWS\system32\nbgoth.dll
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe

A zatim klikni na Fix Checked.
----------------------------------------------------------

2) Pronađi i obriši sledeće file-ove:

C:\WINDOWS\system32\916225735.dll
C:\WINDOWS\ServicePackFiles\winlogon.exe
C:\Program Files\ComPlus Applications\hoke4444.dll
C:\Program Files\Online Services\lavuka.dll
C:\Program Files\ComPlus Applications\hoke83122.dll
C:\WINDOWS\system32\spoolsvv.exe
C:\WINDOWS\ServicePackFiles\mmxs.exe
C:\WINDOWS\system32\GoogleBot.exe
C:\WINDOWS\ServicePackFiles\free.exe
C:\WINDOWS\system32\arcac.exe
C:\WINDOWS\system32\vedxg6ame4.exe
C:\WINDOWS\system32\nbgoth.dll
C:\WINDOWS\system32\aspimgr.exe
--------------------------------------------------------

3) Opet pokreni HijackThis. Pod Other Stuff, klikni na Config... taster a zatim, pod Configuration, klikni na Misc Tools. Nakon toga klikni na taster Open ADS Spy...
Dečekiraj opciju Quick scan (Windows base folder only) i zatim klikni na Scan. Kada skeniranje bude gotovo, klikni na Save log... i sačuvaj file kao Adslog.txt ( čiji sadržaj ćeš ovde kasnije da iskopiraš ). Zatvori HT.

-------------------------------------------------------

4) Sada ćemo odraditi jedan AV sken pomoću programa Dr. Web CureIt.

Skini Dr.Web Cureit!, smesti ga na desktopu i sa njim skeniraj kompjuter na sledeci nacin:

dvoklikom pokreni cureit.exe nakon cega ce se pojaviti uvodni prozor, onda pretisni dugme Start,
opet ce se pojaviti jos jedan prozor, izaberi OK,
sacekaj nekoliko minuta da Dr.Web izvrsi uvodno skeniranje memorije,
klikom misa obelezi particije za skeniranje, obelezene su kada se na njima nalazi crvena loptica,
u gornjem levom uglu programa idi na Options->Change settings F9 i uradi kao sto je objasnjeno na slici -> ovde,
na desnoj strani programa pretisni Start i Dr.Web ce zapoceti skeniranje.


Kada sve bude gotovo, postavi ovde novi HijackThis log, Adslog.txt i C:\Documents and Settings\Kabo\DoctorWeb\CureIt.log.

offline
  • Pridružio: 17 Sep 2007
  • Poruke: 9

Au, brate! Pa ja sam plavusa, ali pokusacu... a onaj sto nisam mogla da ga zipujem, njega da ne cekiram?

Dopuna: 17 Sep 2007 16:06

Za pocetak, a sad je ono uvodno skeniranje, kaze system32\ahdp.dll zarazen backdoor.bifrost.167. Cure?

Dopuna: 17 Sep 2007 16:07

yes to all?

Dopuna: 17 Sep 2007 16:11

Mislim, skeniranje radi DrWeb... a zveknula sam yes, valjda tako treba, ha?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Da, da... Dozvoli mu Cure/Delete gde god ponudi...

offline
  • Pridružio: 17 Sep 2007
  • Poruke: 9

Jel' imate neku nocnu sluzbu? Ovaj je iskenirao tek pola...

Dopuna: 17 Sep 2007 19:08

Salim se, naravno.

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Samo neka skenira... Zaboravih da spomenem, CureIt.log bi mogao biti veoma velik, stoga bi mogla da ga priložiš uz poruku ( koristi Prikači Fajl ), pošto ga možda nećeš moći kompletnog iskopirati u poruku.

offline
  • Pridružio: 17 Sep 2007
  • Poruke: 9

Evo ga... Basta puna virusa!

ADSLOG:

C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP78\A0029842.exe : {AE75EF52-6642-B54D-C6C3-9BE256F9BF92} (100 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP79\A0029889.exe : {AE75EF52-6642-B54D-C6C3-9BE256F9BF92} (100 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP82\A0029901.exe : {AE75EF52-6642-B54D-C6C3-9BE256F9BF92} (100 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP86\A0030916.exe : {AE75EF52-6642-B54D-C6C3-9BE256F9BF92} (100 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0042170.exe : exe.exe (51200 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0043165.exe : exe.exe (66048 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0044165.exe : exe.exe (98816 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0045308.exe : exe.exe (98816 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0046304.exe : exe.exe (131584 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0046541.exe : exe.exe (131584 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0046734.exe : exe.exe (131584 bytes)
C:\System Volume Information\_restore{76AC6EA2-0EF9-4B9F-BCC4-BAFBFAA56FC3}\RP92\A0046865.exe : exe.exe (131584 bytes)
C:\WINDOWS\system32\svchost.exe : exe.exe (131584 bytes)



Logfile of HijackThis v1.99.1
Scan saved at 8:20:31 PM, on 9/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Kabo\Desktop\New Folder\bb.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} (ProxyModule Class) - online.deltabanka.rs/RetailDLL/SGCMSCCD.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{677666A1-11AB-4C2F-AFDA-54B0A951EA4A}: NameServer = 194.106.162.2,194.106.162.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3D6662F-2615-4A42-96B6-0EE79E0B8E35}: NameServer = 194.106.162.2,194.106.162.3
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wincqt32 - C:\WINDOWS\SYSTEM32\wincqt32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


CureIt je zaista jako velik, pa evo ga kao file. Hvala ti na trudu, zaista!

mycity.rs/must-login.png

Dopuna: 17 Sep 2007 21:08

Premda, pravo da ti kazem, mislim da ce ipak morati da radi cuveni format... Sada se prilikom podizanja Windowsa vise ne pojavljuje ni plavi ispisani ekran, vec prozorcic u kojem pise: hpqthb08.exe - Aplication Error. The aplication failed to initialize properly (0xc000007b). Kliknes OK i tu ga skroz zablokira.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

To je napredak, tj. bolja je situacija nego kada dobijes plavi ekran, zato nemoj da odustajes Wink

Ko je trenutno na forumu
 

Ukupno su 843 korisnika na forumu :: 9 registrovanih, 0 sakrivenih i 834 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bojank, cikadeda, FAMAS, ILGromovnik, mačković, milenko crazy north, Tvrtko I, yrraf, šumar bk2