Help with xtendmedia malware please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by LGMcCaw, Feb 8, 2013.

  1. LGMcCaw

    LGMcCaw Private E-2

    A freind asked me to help remove this bug from her laptop, it appears as a small window on the bottom left of internet explorer and seems to redirect to different advertising pages. She had alread tried removing it, and at this point, it just shows up and an empty frame with a red X in the top right.

    I followed the steps for removing redirected, no dice. Then continued with general removal instructions, still no dice so I'll post the logs created and hopefully someone can help us wipe this thing out.

    Thanks,

    L.G. McCaw
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing it in your logs. Please use windows explorer to find and delete:
    C:\ProgramData\nidtmantpeifdhy

    You can try resetting IE to defaults:
    Reset IE to defaults
     
  3. LGMcCaw

    LGMcCaw Private E-2

    Thanks for the response. As suggested, I deleted the folder abd reset IE back to defaults. I also purged the DNS Cache and restarted IE. something is still going on because the frame is still there when I go to different web pages although there's nothing in it. I also get a popup from Malware bytes saying it's blocked access to certain IP adresses. I'll attach the malwarebytes protection log.

    Thanks,

    L.G.M.
     

    Attached Files:

  4. LGMcCaw

    LGMcCaw Private E-2

    Spoke too soon. It's still there, depending on the website the frame gets blocked, but others contain ads for Iview or PCSpeedup. I'm guessing it changes ad servers and Malwarebytes is only blcoking a portion of them.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  6. LGMcCaw

    LGMcCaw Private E-2

    Downloaded Combofix as advised, here's the resulting log file.

    Thanks again,
    L.G.M.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What version of IE are you using?
     
  8. LGMcCaw

    LGMcCaw Private E-2

    It's IE9 on Windows 7, it says 9.0.8112.16421 with update 9.0.12 (kb2761465) 256bit encryption.

    Thanks,

    L.G.M.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try downgrading to IE8 and see if that works.
     
  10. LGMcCaw

    LGMcCaw Private E-2

    Downgraded to IE8, restarted, still same issue. Now Malwarebytes isn't poping up with blocked site, but the frame is still there. Depending on what site I'm at it says FHServ.COM or AD.xtendmedia for the domain info.

    Thanks,
    L.G.M.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Manage Add-ons in IE Tools and see if Xtendmedia appears there. If so, disable it.
     
  12. LGMcCaw

    LGMcCaw Private E-2

    Thanks for the response, as requested I looked, nothing there. I checked loaded, run without permission, downloaded. Some HP printer stuff, some microsoft stuff,an orcle java and some adobe addons. No accelerators and only Google for a search engine. I've also reset IE defaults again.

    Thanks,

    L.G.M.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. LGMcCaw

    LGMcCaw Private E-2

    It didn't find any threats, but it DID find the HOSTS file had a bunch of blank lines and false entries that it corrected. That seems to have done the trick. I'm guessing the hosts file was redirecting to reinfect, mayware bytes was blocking the redirect.
    I'll keep an eye on it a day or two and see what happens before I close out this thread.

    I hope Karma returns the favor since I can't!

    Thanks guys,
    L.G.M.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your hosts file looked semi normal ( per you MGlog.zip ) attachment, but he blank lines only made it seem like this. It looked like the end of file and all was good, but inserted down at the end after many blank lines were the below redirects:


    The 93.115.241.27 address sent you to Romania.
     
  16. LGMcCaw

    LGMcCaw Private E-2

    Gota give'em credit, they're pretty tricky. I dunno what got rid of the initial infection, she'd (the owner) already run a few things before she called me. It was still there, because I had created a new hosts file, and it continually was modified to add the lines to the end. (I'm guessing ComboFix did the trick, but it didn't clean out the HOSTS file.) Is there anything else beside turning her AV back on that I need to do in the way of cleanup? I've already reinstalled JAVA (from a known source), flash and adobe reader. I've also reinstalled (or will) IE9 and all the other MS updates.

    Thanks again,
    L.G.M.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  18. LGMcCaw

    LGMcCaw Private E-2

    OK, seems all is good so far. Combofix uninstalled and other utilities & cleanup completed. Licensed Malware bytes. My friends very happy, machine even seems "quicker" according to her.

    Thanks so much,
    L.G.M.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds