Malware removal request

Hello,
what must I do to correct this problem ?
Additionnal information about the context :

  • it appears with my chrome navigator
  • it appears with my firefox navigator
  • it appears on different PC

It seems that the problem is on the internet server, not on my PC !
Thank’s in advance for your help.

Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892

Thank’s for your reply.
See attached the requested files.

“Addition.txt” is missing.

We do need the Addition.txt file to make a complete cleaning.

Also, can you tell me why you are using a Proxy service on your internet connection (if you know)?

See attached Addition.txt file.
For the question : I don’t know that I use a proxy ! ???
How can I modify it ?

Uninstall Web Companion

  • Open Notepad (click Start button → type notepad.exe → press Enter)
  • Copy text from code block below and paste it into Notepad
ProxyEnable: [.DEFAULT] => Proxy est activé.
ProxyServer: [.DEFAULT] => http=127.0.0.1:56656;https=127.0.0.1:56656
RemoveProxy:
  • Go to FileSave As
  • Make sure that UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

see attached file.

Are you still getting that message?

Yes, I get your las message.
After I did the following actions:

[ol]- I uninstall webcompanion

  • I fix with FRST
  • I attach “fixlog.txt” [/ol]

and I wait for instructions.

Which pages are loaded in browser when Avast show message about blocked threat?

Sass Drake, check router settings (DNS etc) also.

I don’t know what to verify in my box : I am a “poor lonesome user” !

As I wrote it in my first message, this trouble happens also on a different PC
I make a new essay : I connect my usual PC to Internet through my smartphone (Bouygues Telecom), and I get the same problem as with my Box provider (SFR).

The probem happens when I make something on the login page of a personnal Wordpress blog hosted by OVH: if I log me in, or if I click to acces as a standard reader of the blog.

The problem doesn’t happen when I go directly as simple reader of the blog.

Will this help ?

Can you give us link to that blog?

yes, but with private adresse if possible ?

Whatever. If you are getting message only on that blog then you should contact website owner/administrator. Your system is clean.

The following will implement some post-cleanup procedures:

=> Please download [https://toolslib.net/downloads/finish/2-delfix/[b][u]DelFix[/u][/b][/url] by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

alpage - You can send the information via a Private Message. Just click on the user name and select Send PM on the next page (the User’s Profile page).

@alpage

I’ve read your message and can’t find problematic JS URL.

Please attach Avast report located at

C:\ProgramData\AVAST Software\Avast\report\WebShield.txt

In case yor system doesn’t show hidden files and folders just paste path I bolded above in dialog box for selecting file to upload.

did Saas Drake receive my PM ?

Find attached files:

  • Delfix_1 : with only “Remove disinfection tools” checked
  • Delfix_2 : with “Remove disinfection tools” + “Create registry backup” + “Purge System Restore” checked

Yes I received them and ot bee able to find problematic JS file. Attach Avast report please as I instructed in post just above yours.