Author Topic: Avast popup "Threat Secured" when using google.com caused by darkflags.net  (Read 3974 times)

0 Members and 1 Guest are viewing this topic.

Offline Mohamed275

  • Newbie
  • *
  • Posts: 2
Hello, i am using Google Chrome Version Version 81.0.4044.138 (Official Build) (64-bit). Everytime i search for something on Google.com, Avast Version 20.2.2401 (build 20.2.5130.571) pops up a message saying "Threat secured", details below. I need to get rid of the threat and the pop up, the help is appreciated. Thank you


"Threat secured"
We have safely aborted connection on darkflags.net because it was infected with Other:Malware-gen[Trj]
Threat name: Other:Malware-gen[Trj]
Severity: 1 out of 3
URL: https: //darkflags.net/21db1c5c8b372aecca.js
Process: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Detected by: Web Shield
Status: Connection aborted.
« Last Edit: May 09, 2020, 12:42:22 AM by Mohamed275 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Hi Mohamed275,

Please, make that live link in your post non-clickable like with hxtps or -https,
We do not want visitors here to click that live link to persistent adware.

The following malcode (persistent adware agent) is being detected here:
https://www.virustotal.com/gui/file/63b61970f6bed95eb81325642a2ea7da3810b1ec00b1fb7e224693225c1ecbce/detection 

Avast detects this as Other:Malware-gen [Trj]  (generic adware detection)

This threat could be removed under the guidance of a qualified remover,
wait for one to arrive here and provide us with the logs asked for here:
https://forum.avast.com/index.php?topic=194892.0

Generally the procedure is as follows:
1. Start the computer is Safe Mode with Windows Key + R key.
2. Give in msconfig” and click OK button
3. Choose selective start-up & click these tags: Load system services - Load start up items
4. Go to boot tap and click OK, after giving tags - safeboot & network.
5. Give in Windows keys and R together to open Run Box.
6. Type taskmgr and Click OK button to open task manager.
7. Find malicious process, right click on it and click End Process.
8. Uninstall Adware.Agent.XYI From Control Panel
9. Press Windows key + R key together to open Run window:
10. As input give in Control Panel in Run window and hit Enter key.
11. Select Uninstall a program option under the Programs menu.
12. Find Adware.Agent.XYI (Other:Malware-gen [Trj]) related program
and click on the Uninstall button.

As said earlier, whenever you find yourself less tech savvy and uncomfortable performing those 12 cleansing steps, wait for a qualified remover to appear here to guide you through the removal process of this adware malcode.

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
« Last Edit: May 09, 2020, 12:29:52 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Mohamed275

  • Newbie
  • *
  • Posts: 2
Hi Polomus,

Thanks for the tip about the live link, last thing i want is for other users to get adware. I have followed the instructions mentioned using "Malwarebytes", it had 13 detections and i quarantined them all. After that i performed a restart, and the pop up was gone.

I think i do not need to follow the instructions for "Farbar Recovery Scan Tool" nor the 12 cleansing steps anymore. If you think that there is a necessity for me to do so, please let me know.

Thanks again for your contiribution.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Hi Mohamed275,

You supposedly tackled it well. No need to follow the instructions anymore as mentioned by me.
Have a peaceful day,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!