Nymaim Trojan In Network

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vvgomez, Jan 25, 2018.

Tags:
  1. vvgomez

    vvgomez Private First Class

    Hi,

    I have just been notified by my internet service provider (Rogers) that I have a Nymain Trojan in my computer. I couldn't detect it with Avast antivirus or Malwarebytes Anti-Malware I had installed, so I need help. I have only 48 hours to clean my computer or my internet account would be suspended, so I would really appreciate any assistance with this issue.

    Please, find attached the log you request

    Thank you for your help and time.

    Viviana

    ps. I noticed that my trial version of Hitman is already expired. I am afraid I had used before, so I was able to create the log, but apparently I won't be able to remove viruses with this version.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun RogueKiller and remove these items:
    ¤¤¤ Processes : 1 ¤¤¤
    [VT.Unknown] CatSysCenter.exe(11220) -- C:\Program Files (x86)\BrandProtect\CatSysCenter\CatSysCenter.exe[-] -> Found

    ¤¤¤ Tasks : 2 ¤¤¤
    [Hj.Shortcut] \{596CF9E0-0C70-4C19-A64D-E880B826699B} -- "c:\program files (x86)\google\chrome\application\chrome.exe" (http://www.skype.com/go/downloading?source=lightinstaller&ver=7.16.0.102&LastError=404) -> Found
    [Hj.Shortcut] \{973D14B4-46AF-4EAC-9D01-74798FB97341} -- "c:\program files (x86)\google\chrome\application\chrome.exe" (http://ui.skype.com/ui/0/6.14.0.104/en/abandoninstall?source=lightinstaller&page=tsPlugin) -> Found

    ¤¤¤ Files : 1 ¤¤¤
    [PUP.Firefox][File] C:\Users\v\AppData\Roaming\Mozilla\Firefox\Profiles\7sbvq1cc.default\Invalidprefs.js -> Found

    Next, use file explorer to find and delete:
    C:\Users\v\Downloads\Adobe cc\Adobe CC 2015 + Patch Gametime Gameplays\Adobe Universal Patcher CC2015.exe
    C:\Users\v\Downloads\Adobe universal patcher\Adobe CC 2015 + Patch Gametime Gameplays\Adobe Universal Patcher CC2015.exe

    Reboot and let's see if we can figure out what is going on with this. We need this to run and create a log. If it is stopping at about 80%, it is a sign of a new MBR infection going around. So let's make sure you are doing it right. ;)
    • Download TDSSKiller from Kaspersky directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7,8 and 10, do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).

    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds1.jpg

    • Click on Run to allow the application to run properly.
    • If you see any popup warnings from your antivirus or firewall about it trying to access the nework or similar, make sure that you allow it to run/have access.
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    You will then see the below window
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds2.jpg

    • Click on the Start scan button to begin the scan and wait for it to finish. When it finishes, you will see a window similar to below accept you may have one indicating infections were found.
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds3.jpg
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should already be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    • Reboot and the infection should hopefully be removed.


    TDSSkiller - How to run
     
  3. vvgomez

    vvgomez Private First Class

    Hi TimW,

    Thank you for your soon response. I will skip step 1, I know CatSysCenter.exe is safe, it belongs to the company I work with, so I will proceed with the rest and come back to you with the new results.
    Thanks,
    vv
     
  4. vvgomez

    vvgomez Private First Class

    Hi TimW,

    TDSSKiller ran without any problem, no need to change names, none warnings, and didn't stop at any percent finishing the scan very quickly with no infections found.

    Please, find attached logs requested.

    Thank you,

    vv
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log is clean.....but I want one more look see:

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  6. vvgomez

    vvgomez Private First Class

    Please, find the logs attached.

    Looking to the windows registry I find some strange chinese symbols... should I delete them? Thank you.
    upload_2018-1-25_23-22-34.png
     

    Attached Files:

    Last edited: Jan 25, 2018
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Definitely remove those registry keys! I have no idea what they are, but they sure aren't normal.

    When done with the above, reboot and please open task manager and click the processes tab and give me a screen shot.
     

    Attached Files:

  8. vvgomez

    vvgomez Private First Class

    Please, find attached the new log.
    I deleted the registry and reboot.
    I have to capture several screen shots for the task manager because of the long list of processes running.
    Thx
     

    Attached Files:

  9. vvgomez

    vvgomez Private First Class

    ... some more screen shots from the task manager

    Thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That looks fine. Let's do one more scan as this infection, though old was once a tool for ransomware.

    MBAM Anti-ransom

    Then, please download and run:
    Zemana Malware Removal to your desktop and run it please.
    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  11. vvgomez

    vvgomez Private First Class

    I can't install MBAM Anti-ransom, I get this message:
    upload_2018-1-26_12-37-51.png

    I also have this notification from windows that an action is needed, but when I click on the link "Open Malwarebytes" nothing happens.

    upload_2018-1-26_12-39-13.png
    so basically I am stuck in this step...
    please, advise

    Thank you,
    vv
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...just forget that for now...run Zemana.
     
  13. vvgomez

    vvgomez Private First Class

    ok, now the computer reboots by itself (scary) and then the notification from windows disappeared and everything looks normal, Still I can't install MBAM Anti-ransom. Seems that the Malwwarebytes installed has included the same feature, should I run this instead?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you mean Zemana...yes.
     
  15. vvgomez

    vvgomez Private First Class

    It took some time to finish the scan, but finally is done.
    Not sure where is the icon to get the report, is that on the right upper corner or should I click next first? Please, let me know. Thank you.
    upload_2018-1-26_16-39-53.png
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please. Make sure you first click next to remove the malware!
     
  17. vvgomez

    vvgomez Private First Class

    Here is the report.
    Thx
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One more scan to be sure:
    Please download and run Emsisoft Emergency Kit.
    Double click EmergencyKitScanner.exe to install EEK
    When the installation of EEK is complete the Emergency Kit scanner will run.
    NOTE: Make sure to enable PUPs detection.
    Click "Yes" to Update Emsisoft Emergency Kit
    Under "Scan" click-on "Malware Scan".
    IMPORTANT: Do not quarantine or delete anything. We just want the scan log without anything being quarantined or deleted.
    Save the scan log somewhere that you can find it (desktop).
    Exit Emsisoft Emergency Kit.
    Attach the log.
     
  19. vvgomez

    vvgomez Private First Class

    report after cleaned...
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Move on to EEK and attach that log, please.
     
  21. vvgomez

    vvgomez Private First Class

    there it goes Emsisoft Emergency Kit report
    thx
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Warning about cracked software Cracked Software.

    How are things running now? What issues are you still having, if any?
     
  23. vvgomez

    vvgomez Private First Class

    Hi TmW,

    I reviewed the article and deleted the files highlighted by the EEK log. I didn't know that ProduKey was a keygen. Guilty for the rest, I guess I did play with fire a long time ago.

    Going back to your question, I had never had any symptom of infection in my pc, but my internet provided keep me warning about some nasty bug called Nymain trojan, detected by them in my pc. They scan my network every 48 hours and if they detect the virus again they will call me. So far, no news from them since January 25th. :)

    Hopefully, those files associated to chrome and mozilla deleted with RogueKiller and Zemana were the culprit. What do you think?

    Thank you so much for all your help and follow up,

    vv
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    C:\Users\v\Downloads\produkey\ProduKey.exe detected: Application.Nirsoft.M --- it would depend on where you downloaded it from.

    If your ISP has not alerted you, then we have been successful.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  25. vvgomez

    vvgomez Private First Class

    Fantastic! I'll proceed with the final steps, then.
    Thank you for taking care of my problem as soon as I posted the threat, for your time, and for being so patience with me to resolve it.
    vv
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds