Hello, First of all I want to say thank you for the amazing service you guys provide in this forum. I have a problem, concerning Shell.exe, DWM.exe and svchost.exe which are identified as trojans. I am running the latest Malwarebytes and it detects those three executables and lets me quarantine and delete them, but they reappear instantly with new creation dates. Here are the files I could not permanently delete as they recreate themselves: C:\Users\Jason\AppData\Roaming\Microsoft\svchost.exe C:\Users\Jason\AppData\Roaming\Microsoft\stor.cfg C:\Users\Jason\AppData\Roaming\Microsoft\Windows\shell.exe C:\Users\Jason\AppData\Local\Temp\dwm.exe There is also a really strange entry in my HJT log stating something about a proxy : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370 I dont use proxies. And for last, there is also a malicious entry that keeps coming back even after delete : F3 - REG:win.ini: load=C:\Users\Jason\AppData\Local\Temp\dwm.exe If you need any logs, let me know and I'll post immediately. Any help will be greatly appreciated. Thank you so much!