Seems like FRST64 has the same result as running manually the commands.
It seems that is something directly hooked into the network connection as the popups appear immediately after activating the wireless interface.
C:\WINDOWS\system32>netsh int ip reset c:\resetlog.txt
Resetting Interface, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , OK!
Restart the computer to complete this action.
rebooted, the popups are still there when I activate the wireless interface
tried to re-run netsh again, now it returns the error from before
Temporary fix (no more warning popups for now), without activating Gaming mode :):
added in hosts file
0.0.0.0 getmuzicas.info
0.0.0.0 getusaaall.info
But I want to find the malware somehow so to understand if my system is safe or not, as I am unsure of the overall effects of the infection (only popups, or something else).
I have windows 8.1 that came with the notebook, I have no CD, neither does the notebook have a CD drive
As I read here http://www.winhelp.us/repair-your-computer-in-windows-8.html#F8 I can access the recovery console, but what should I do from there?
Also, I would like to continue using the current Windows installation and I am not yet ready for a reinstall if it crashes
Insert the USB into the sick computer and start the computer. First ensuring that the system is set to boot from USB
Note: If you are not sure how to do that follow the instructions Here
Windows 8 screen shots
When you reboot you will see this.
Select the language on this screen and keyboard on the next
The notepad opens. Under File menu select Open.
Select “Computer” and find your flash drive letter and close the notepad.
In the command window type e:\frst64.exe and press Enter Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
I was unable to reboot from the USB stick, don’t know why the notebook ignored it even if I selected it as a boot device.
However, I booted in Windows 8.1 recovery and ran FRST64, the result is attached.
Download the attached fixlist .txt to the same location as FRST
Run FRST and press fix
Reboot to normal windows and let me know exactly when you get the alerts again (if you do)
Running the fixlist from Recovery produces an empty file (see fixlog copy).
Anyway I run it from Windows and the log is attached.
In any case, the popups seems to be gone.
I disabled the previously mentioned hosts entries and disconnected and reconnected the wireless and the popups do not show as they did yesterday.
I am unsure what happened, maybe something I did or the malware is just gone, or Avast can no longer stop it.
I will leave for now the hosts entries and hope everything is well.
Thanks for your patience and your help in trying to fix this.
No if it was still there Avast would continue blocking it. Looks like the recovery mode option did the job. Monitor it for a while though and when you are happy let me know and I will tidy up