I tako nakon dobrih 6 godina imam zaražen komp, a da ni sam ne znam kako i zašto. evo par slikica koji pokazuju problem.
Avast mi već par dana divlja, na google chrome sam dobio (i uspješno uklonio) lebdeće reklame. U Taskmanager postavljen zadatak automatskog pokretanja skočnog prozora, kojeg sam također uklonio.
Sada imam problem što svaki par sati avast prijavi prijetnju, veceras sam si zadao posla i krenuo u potragu za izvorom tih prijetnji, pronašao sam (pogledati na slici) nepoznat korisnički račun sa svim privilegijama, koji ne mogu ukloniti..
još jedan zanimljiv podatak ono što ne pronađe Avast, to pronađe Malwarebytes i obrnuto..
Zadnje skeniranje, avast je pronašao prijetnju u otpadu kamo sam prije skeniranja premjestio niz datoteka iz temp mape.
ovo je avast log koji sam pronašao preko regedit-a
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\AVAST Software\Avast\PUB-Removed
Class Name: <NO CLASS>
Last Write Time: 19.3.2015. - 21:18
Value 0
Name: 1d06004d824671c
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\MICROSOFT\Windows\TEMPORARY INTERNET FILES\CONTENT.IE5\K5UKV1J1\VOsrv[1].exe
Value 1
Name: 1d06004de7bfb38
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Roaming\73B6D16A-1426522678-11DD-8287-C3417F19D883\nsjD1C0.tmpfs
Value 2
Name: 1d06004f457d8a9
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0CUCEZOG\WinCheckSetup[1].exe
Value 3
Name: 1d06004f77e4a94
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsoAC18.tmp
Value 4
Name: 1d060055dc4c7d2
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\MICROSOFT\WINDOWS\Temporary Internet Files\Content.IE5\28QN9GPU\SFSetup[1].exe
Value 5
Name: 1d0600563f01222
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsf6242.tmp
Value 6
Name: 1d060069e4e1c2b
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0CUCEZOG\Validate[1].exe
Value 7
Name: 1d06006a46e1bf4
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\Uninstall.exe
Value 8
Name: 1d06006a7fa026a
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\SearchUpdater[1].exe
Value 9
Name: 1d06006a80944ac
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsj23F.tmp
Value 10
Name: 1d06006ae062bf5
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\igsSetup[1].exe
Value 11
Name: 1d06006b131067e
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsy1361.tmp
Value 12
Name: 1d06006b344f2b9
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\28QN9GPU\smt[1].exe
Value 13
Name: 1d06006b65eb62e
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsj4F5B.tmp
Value 14
Name: 1d06042647c4901
Type: REG_SZ
Data: |C:\Users\Nix\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\751e49a4-5c1ad15b|>RunApplet.class
Value 15
Name: 1d060b76e0bd325
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SPJ6ORPP\Setup[1].exe
Value 16
Name: 1d060b77102adad
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsdF370.tmp
Value 17
Name: 1d060c84c7dd093
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\Content.IE5\28QN9GPU\Setup[1].exe
Value 18
Name: 1d060c852b40eda
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsy7C59.tmp
Value 19
Name: 1d0614f89f50be1
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nssE279.tmp
Value 20
Name: 1d061c96680a9d6
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K5UKV1J1\Setup[1].exe
Value 21
Name: 1d061c969839bc0
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nszEDE.tmp
Value 22
Name: 1d0625405c7f442
Type: REG_SZ
Data: |C:\Users\Nix\AppData\Local\Temp\nsp6600.tmp
Value 23
Name: 1d06281dc7390c7
Type: REG_SZ
Data: |C:\$Recycle.Bin\S-1-5-21-3527698899-3033453596-2140015394-1000\$R4MQG8P.tmp
Molim savjet kako se riješiti napasnika.
Hvala