Ever since a few days ago when I clicked on a random link at Facebook (rarely do, but lesson learned) I've had random webpages popping themselves up on my screen.. I click it off, then a few minutes later, it pops up again with the same URL.. sometimes it will take a few hours, then change back to a few minutes. the next day I get online, and the URL has changed. I do not know what this is, but I've run Malwarebytes and Avira over and over, and the first few times had some Malware, and a few Trojans removed, but its still popping up, please help! Thank you! The URL today is... hxxp://lgecdqddnthx/
AdwCleaner: # AdwCleaner v2.301 - Logfile created 05/18/2013 at 19:02:26 # Updated 16/05/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : CTMystic - CRYSTALEQUILIBR # Boot Mode : Normal # Running from : C:\Users\CTMystic\AppData\Local\Microsoft \Windows\Temporary Internet Files \Content.IE5\LUV3HAK5\adwcleaner.exe #
Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\END Folder Deleted : C:\Program Files (x86)\Free Offers from Freeze.com Folder Deleted : C:\ProgramData\AVG Security Toolbar Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\WeCareReminder Folder Deleted : C:\Users\CTMystic\AppData\Local\Google\Chrome \User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla Folder Deleted : C:\Users\CTMystic\AppData\LocalLow\AVG Security Toolbar Folder Deleted : C:\Users\CTMystic\AppData\Roaming\Babylon ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Key Deleted : HKCU\Software\AVG Security Toolbar Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\Default Tab Key Deleted : HKCU\Software\GamePlayLabs Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\pc optimizer pro Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKCU\Software\Microsoft\Internet Explorer \SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6- 8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D- BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Default Tab Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\Software\VDownloader\OpenCandy Key Deleted : HKLM\SOFTWARE\Wow6432Node\5955dd8cbd3abf49 Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0- 8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE- 3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7- 832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2- 6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{618AAD04-921F-44C2-BE38-C0818AF69861} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{B5D2ED96-62F9-4C2C-956D-E425B1F67337} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \jmfkcklnlgedgbglfkkgedjfmejoahla Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \ocphobfcfafpclibolpjdafgaffkaoci Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41 -A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659- 4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{30B15818-E110-4527 -9C05-46ACE5A3460D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{419EDA30-6DFF- 432C-B534-E15D899ABEE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{618AAD04-921F-44C2 -BE38-C0818AF69861} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5D2ED96-62F9- 4C2C-956D-E425B1F67337} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D3A412E8-1E4B-47D2 -9B12-F88291F5AFBB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion \Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16576 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www2.delta-search.com/? affID=121846&babsrc=HP_ss&mntrId=2C3E002710B7FEB9 --> hxxp://www.google.com -\\ Google Chrome v [Unable to get version] File : C:\Users\CTMystic\AppData\Local\Google\Chrome\User Data \Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [3729 octets] - [03/09/2012 06:20:01] AdwCleaner[S1].txt - [4985 octets] - [18/05/2013 19:02:26] ########## EOF - C:\AdwCleaner[S1].txt - [5045 octets] ##########
Malwarebytes Log: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.16.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16576 CTMystic :: CRYSTALEQUILIBR [administrator] 5/18/2013 7:08:52 PM mbam-log-2013-05-18 (19-08-52).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 448707 Time elapsed: 1 hour(s), 14 minute(s), 15 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Security Checkup: Results of screen317's Security Check version 0.99.63 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9
Antivirus/Firewall Check: Windows Firewall Enabled!
AVG Anti-Virus Free Edition 2012 Antivirus out of date! (On Access scanning disabled!)
Anti-malware/Other Utilities Check:
Malwarebytes Anti-Malware version 1.75.0.1300
Java(TM) 6 Update 21 Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Process Check: objlist.exe by Laurent
AVG avgwdsvc.exe AVG avgtray.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe
`System Health check
Total Fragmentation on Drive C: 3%
End of Log
AdwCleaner: # AdwCleaner v2.301 - Logfile created 05/18/2013 at 19:02:26 # Updated 16/05/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : CTMystic - CRYSTALEQUILIBR # Boot Mode : Normal # Running from : C:\Users\CTMystic\AppData\Local\Microsoft \Windows\Temporary Internet Files \Content.IE5\LUV3HAK5\adwcleaner.exe #
Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\END Folder Deleted : C:\Program Files (x86)\Free Offers from Freeze.com Folder Deleted : C:\ProgramData\AVG Security Toolbar Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\WeCareReminder Folder Deleted : C:\Users\CTMystic\AppData\Local\Google\Chrome \User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla Folder Deleted : C:\Users\CTMystic\AppData\LocalLow\AVG Security Toolbar Folder Deleted : C:\Users\CTMystic\AppData\Roaming\Babylon ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Key Deleted : HKCU\Software\AVG Security Toolbar Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\Default Tab Key Deleted : HKCU\Software\GamePlayLabs Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\pc optimizer pro Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKCU\Software\Microsoft\Internet Explorer \SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6- 8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D- BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Default Tab Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\Software\VDownloader\OpenCandy Key Deleted : HKLM\SOFTWARE\Wow6432Node\5955dd8cbd3abf49 Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0- 8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE- 3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7- 832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2- 6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{618AAD04-921F-44C2-BE38-C0818AF69861} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{B5D2ED96-62F9-4C2C-956D-E425B1F67337} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface \{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \jmfkcklnlgedgbglfkkgedjfmejoahla Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \ocphobfcfafpclibolpjdafgaffkaoci Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41 -A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659- 4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{30B15818-E110-4527 -9C05-46ACE5A3460D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{419EDA30-6DFF- 432C-B534-E15D899ABEE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{618AAD04-921F-44C2 -BE38-C0818AF69861} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5D2ED96-62F9- 4C2C-956D-E425B1F67337} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D3A412E8-1E4B-47D2 -9B12-F88291F5AFBB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion \Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16576 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www2.delta-search.com/? affID=121846&babsrc=HP_ss&mntrId=2C3E002710B7FEB9 --> hxxp://www.google.com -\\ Google Chrome v [Unable to get version] File : C:\Users\CTMystic\AppData\Local\Google\Chrome\User Data \Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [3729 octets] - [03/09/2012 06:20:01] AdwCleaner[S1].txt - [4985 octets] - [18/05/2013 19:02:26] ########## EOF - C:\AdwCleaner[S1].txt - [5045 octets] ##########
Malwarebytes Log: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.16.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16576 CTMystic :: CRYSTALEQUILIBR [administrator] 5/18/2013 7:08:52 PM mbam-log-2013-05-18 (19-08-52).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 448707 Time elapsed: 1 hour(s), 14 minute(s), 15 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Security Checkup: Results of screen317's Security Check version 0.99.63 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9
Antivirus/Firewall Check: Windows Firewall Enabled!
AVG Anti-Virus Free Edition 2012 Antivirus out of date! (On Access scanning disabled!)
Anti-malware/Other Utilities Check:
Malwarebytes Anti-Malware version 1.75.0.1300
Java(TM) 6 Update 21 Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Process Check: objlist.exe by Laurent
AVG avgwdsvc.exe AVG avgtray.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe
`System Health check
Total Fragmentation on Drive C: 3%
End of Log