Something keeps trying to make a connection to an infected site.

I am sick of hearing “Threat has been detected” in my headphones.

Malwarebytes and Avast don’t seem to remove or delete whatever is making the connection but every few hours Avast will stop a remote/scheduled connection to the IP 94.130.97.189 because it is infected with JS:Cryptonight [Trj].

While it is great that the Web Shield is detecting this how to I find the root cause?

Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892

I’m getting this, too, but only in Chrome. (I’m using a tower pc, Windows 7.)
Here’s a screenshot of Avast’s message: