webpageclick.net

Good Day,

I have been using avast for several years and it is an excellent software. I want to purchase the premier, however, I just got this annoying >:( webpageclick.net through chrome on my computer. I have removed other viruses before through a long tedious process, but this one I am not sure of. I have avast to scan daily because of the dangers but for some reason, it did not catch this. I have installed spyhunter and though it lists these other dangers, I have not seen webpageclick in the list. I have gone through another company that claims all these ‘bugs’ are in your computer and after purchase they were not as many as they previously said there were. I want to know how Avast can get these out of here or is it another way to remove this webpageclick.net and to keep them from coming in. I have added metascan in now to just protect until I get an answer before I purchase the premier. How can someone help me? :-[ :-\ :cry: Thank you…Janet

Hi Janet and welcome to Avast Forums.

First, uninstall SpyHunter. It is not a reputable program and some would say it is even rogueware.

Then follow this guide: http://forum.avast.com/index.php?topic=53253.0

and attach ( Do not copy/paste ) logs for Malwarebytes’ ( MBAM ), Farbar Recovery Scan Tool ( FRST ), and aswMBR.exe.

an expert in the removal of malware will help you. You have to be patient. Most specialists are located in Europe and it is very late there right now.

Thank you Iroc9555, Before I read your post, I had removed the Spyhunter software. I did however, purchase the premium of Malwarebytes Anti-malware. I found out about this process when I looked into the post that you have placed link in reply to me prior. I have attached the log for the 1st scan with Malwarebytes. I noticed in the log that the Rootkit was not enabled, possibly should have been when scanning. All of the scans are attached to this reply. Again, thank you so much for your quick response. I will be patient with this and thank you in advance for your continued support regarding my issue. Blessings…Sheliyahh Janet E Brown :slight_smile:

OK once we are done I will show how to set Avast to block PUP’s :slight_smile:

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe CHR HKU\S-1-5-21-37291140-3391384578-1375884785-1002\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKU\S-1-5-21-37291140-3391384578-1375884785-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:56219;https=127.0.0.1:56219 BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File BHO-x32: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKU\S-1-5-21-37291140-3391384578-1375884785-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-37291140-3391384578-1375884785-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Winsock: Catalog9-x64 01 C:\WINDOWS\system32\myradioplayer64.dll [464120] (myradioplayer) Winsock: Catalog9-x64 02 C:\WINDOWS\system32\myradioplayer64.dll [464120] (myradioplayer) Winsock: Catalog9-x64 03 C:\WINDOWS\system32\myradioplayer64.dll [464120] (myradioplayer) Winsock: Catalog9-x64 04 C:\WINDOWS\system32\myradioplayer64.dll [464120] (myradioplayer) Winsock: Catalog9-x64 15 C:\WINDOWS\system32\myradioplayer64.dll [464120] (myradioplayer) 2015-03-06 05:10 - 2015-03-07 08:58 - 00000000 ____D () C:\Users\DrJanet\AppData\Roaming\Enigma Software Group CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.

Good Day,

Here is the fixlog.txt for your review

Thank you and onward to do the next process.

Sheliyahh Janet

Blessings, here is the last of the scans using adwcleaner[so] for me. I have had a funfilled several hours and going to rest will look for the reply post in email. Thank you again…Sheliyahh Janet :slight_smile: PS…I will say this…it is moving a lot faster since all the extra weight is gone. Will give it a good run later. Now I can finish doing my podcasts and writing my books.

We did remove a modicum of junk :slight_smile:

Could you let me know what problems remain