Today, I didn’t get the pop ups from avast in hardened mode for the first time, but I started getting the “threat has been detected” that many people has been getting lately.

I haven’t read their threads, but they all seem to have trouble with svchost.exe and Win32:Malware-gen according to the first page of the forum. That’s what I got 3 times.

Hi Attacked2015 :slight_smile:

Run FARBAR again and post a fresh FRST.txt log so Essexboy can look at it.

Greetz, Red.

If it is just svchost then

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

Hi!

Should I run it in safe mode?

I have news. I did get the pop ups again, at a different time and twice today. As I said before, it used to happen only once a day, everyday in a period of 2 hours, but now that changed.

I recently got new popups from avast in hardened mode too. It prevented from starting the same .exe that were the object of the threat last night.

Normal mode will be best

Here it is!

Could I have a screenshot of the popup please

I got this one (first pic) 3 times, with 3 different objects from F:/ I could only take a screenshot to one of them. PC is too slow.

Then I got like 8 of these with different objects (pic 2)… Same thing, I couldn’t take screenshots to all of them.

OK that is in system restore so lets reset them

Download and run Delfix
Select the options as shown

https://dl.dropboxusercontent.com/u/73555776/delfix.JPG

Done! Do you need to see the log?

Nope not really :slight_smile: