So I recently downloaded something, then uninstalled it once I realized how sketchy it was. Since I’ve uninstalled it, Avast has been popping up with the Threat Blocked pop-up, saying “We’ve safely aborted connection on lastone.royalwebhosting.net because it was infected with URL:Blacklist .”
It’s great that Avast is blocking the threat, but this message has been popping up once every 10 minutes it seems. So I wondering how to actually remove the threat, not just block it. Can anyone help me?
Pondus
June 14, 2019, 5:03am
2
Try clear your browsers surf history
You may also run a scan with Malwarebytes Antimalware and Malwarebytes AdwCleaner
If still problems, follow instructions here and attach requested logs https://forum.avast.com/index.php?topic=194892.0
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HomePage: Default -> hxxp://securesearch.lavasoft.com/?source=f439e2c0&tbp=homepage&toolbarid=adawaretb&v=2_5&u=C471C661BA6A8330237A72516CA6CB3D
CHR StartupUrls: Default -> "hxxp://securesearch.lavasoft.com/?source=f439e2c0&tbp=homepage&toolbarid=adawaretb&v=2_5&u=C471C661BA6A8330237A72516CA6CB3D","hxxp://mysearch.avg.com/?cid={5E1B7022-A8C0-4B17-A1F6-645FA360C5F1}&mid=7637aa12f94647d39d3209d421652461-bb6f39865645ca1148a1a592b4546bba6b68b34f&lang=en&ds=oc011&pr=sa&d=2013-05-27 19:13:39&v=15.2.0.5&pid=safeguard&sg=1&sap=hp"
2019-06-14 03:18 - 2019-06-15 00:46 - 001388448 _____ () C:\Users\Public\ASR.dat
2019-06-14 03:18 - 2019-06-14 03:18 - 000004608 _____ () C:\Users\bdruin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.