I tako nakon dobrih 6 godina imam zaražen komp, a da ni sam ne znam kako i zašto. evo par slikica koji pokazuju problem.
Avast mi već par dana divlja, na google chrome sam dobio (i uspješno uklonio) lebdeće reklame. U Taskmanager postavljen zadatak automatskog pokretanja skočnog prozora, kojeg sam također uklonio.
Sada imam problem što svaki par sati avast prijavi prijetnju, veceras sam si zadao posla i krenuo u potragu za izvorom tih prijetnji, pronašao sam (pogledati na slici) nepoznat korisnički račun sa svim privilegijama, koji ne mogu ukloniti..
još jedan zanimljiv podatak ono što ne pronađe Avast, to pronađe Malwarebytes i obrnuto..
Zadnje skeniranje, avast je pronašao prijetnju u otpadu kamo sam prije skeniranja premjestio niz datoteka iz temp mape.
ovo je avast log koji sam pronašao preko regedit-a
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\AVAST Software\Avast\PUB-Removed
Class Name: <NO CLASS>
Last Write Time: 19.3.2015. - 21:18
Value 0
 Name: 1d06004d824671c
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\MICROSOFT\Windows\TEMPORARY INTERNET FILES\CONTENT.IE5\K5UKV1J1\VOsrv[1].exe
Value 1
 Name: 1d06004de7bfb38
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Roaming\73B6D16A-1426522678-11DD-8287-C3417F19D883\nsjD1C0.tmpfs
Value 2
 Name: 1d06004f457d8a9
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0CUCEZOG\WinCheckSetup[1].exe
Value 3
 Name: 1d06004f77e4a94
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsoAC18.tmp
Value 4
 Name: 1d060055dc4c7d2
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\MICROSOFT\WINDOWS\Temporary Internet Files\Content.IE5\28QN9GPU\SFSetup[1].exe
Value 5
 Name: 1d0600563f01222
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsf6242.tmp
Value 6
 Name: 1d060069e4e1c2b
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0CUCEZOG\Validate[1].exe
Value 7
 Name: 1d06006a46e1bf4
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\Uninstall.exe
Value 8
 Name: 1d06006a7fa026a
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\SearchUpdater[1].exe
Value 9
 Name: 1d06006a80944ac
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsj23F.tmp
Value 10
 Name: 1d06006ae062bf5
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\igsSetup[1].exe
Value 11
 Name: 1d06006b131067e
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsy1361.tmp
Value 12
 Name: 1d06006b344f2b9
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\smt[1].exe
Value 13
 Name: 1d06006b65eb62e
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsj4F5B.tmp
Value 14
 Name: 1d06042647c4901
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\751e49a4-5c1ad15b|>RunApplet.class
Value 15
 Name: 1d060b76e0bd325
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SPJ6ORPP\Setup[1].exe
Value 16
 Name: 1d060b77102adad
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsdF370.tmp
Value 17
 Name: 1d060c84c7dd093
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\Content.IE5\28QN9GPU\Setup[1].exe
Value 18
 Name: 1d060c852b40eda
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsy7C59.tmp
Value 19
 Name: 1d0614f89f50be1
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nssE279.tmp
Value 20
 Name: 1d061c96680a9d6
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K5UKV1J1\Setup[1].exe
Value 21
 Name: 1d061c969839bc0
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nszEDE.tmp
Value 22
 Name: 1d0625405c7f442
 Type: REG_SZ
 Data: |C:\Users\Nix\AppData\Local\Temp\nsp6600.tmp
Value 23
 Name: 1d06281dc7390c7
 Type: REG_SZ
 Data: |C:\$Recycle.Bin\S-1-5-21-3527698899-3033453596-2140015394-1000\$R4MQG8P.tmp
Molim savjet kako se riješiti napasnika.
Hvala
 
     
    
    
