LeBag Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by cheesiemonster, Jan 17, 2013.

  1. cheesiemonster

    cheesiemonster Private E-2

    Hi there,

    I was looking at tennis scores about 2 hours ago, when I started getting persistent UAC prompts for the Command Processor.

    I tracked the UAC prompts to a process (pmnnfrwl.exe) and stopped it, which also stopped the UAC prompts. I then found some random exe files like pmnnfrwl.exe (the one pushing the UAC prompts) in temp.

    These were the exact same filenames as when I got infected about 5 months ago with Win32/Ramnit.D. You guys successfully help me get rid of it (I'm very grateful), so I immediately ran the 4 scans you recommend.

    I ran the 4 scans prescribed and have attached the logs - however I wasn't brave enough to turn off UAC before I did the scans, for fear of something bad happening. Also, following the instructions for running each of the scanners, I didn't delete any of the detected items, except in MalwareBytes, where I selected "remove selected". MalwareBytes identified the trojan as "LeBag", although the filenames seemed the same as Ramnit.D from last time... After the reboot post MalwareBytes, the Command prompt still came up.

    I run my PC using a non-administrator account and have antivirus (Avira) and both this and the PC are up-to-date.

    Any help at all would be greatly appreciated!
    Thanks in advance
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to disable UAC as requested and then you need to download and use the current version of MGtools also as requested and attach the new log. You should not be keeping old versions of MGtools around. You should have complete final instructions last time which includes removing anything related to MGtools.
     
  3. cheesiemonster

    cheesiemonster Private E-2

    Thanks for your help! I will disable uac and run the scans again. As for removing the last version of MGtools, I don't think I got instructions last time. Could you let me know what I should do there?

    I'm very grateful for your help, thank you.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You only need to download and run the current version of MGtools and attach the new log.

    You're right. I went back and look at your last thread and you were never given final instructions so that was not your fault. However, for future reference, you should always download and use current versions of tools anytime you have a problem.
     
  5. cheesiemonster

    cheesiemonster Private E-2

    Here is the MGtools log using the latest version. Just want to add that I did this in my admin account, UAC disabled and my antivirus disabled. I've turned UAC back on after the scan.

    Thanks for your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but there are two issues with doing this:

    1. You need to run the cleaning process/scans on the user account that is having problems so that we can see the problems. There are no signs of problems in the admin account.
    2. You must keep UAC disabled until we finish any cleanup otherwise it will just keep getting in the way and you will have to keep disabling it and rebooting after disabling in order for the change to take effect. And you will have to keep doing this before ever fix we provide. Thus it is easier to just keep it disabled.
    However we will attempt some cleanup anyway. But before doing this, temporarily change the "Ron" user account into an admin account and then reboot and log into the Ron user account to do the below.

    If UAC is enabled, you will have to disabled it and reboot again into the Ron account.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\amdkyf.txt
    C:\Windows\azypjit.txt
    C:\Windows\is-71VBC.exe
    C:\Windows\is-71VBC.lst
    C:\Windows\is-71VBC.msg
    C:\Users\Ron\AppData\Local\pbxgppoo\xhpsapuf.exe
    C:\Users\Ron\AppData\Local\Temp\pmnnfrwl.exe
    C:\Users\Ron\AppData\Local\Temp\xhpsapuf.exe
    C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xhpsapuf.exe
    C:\Users\Ron\AppData\Local\pbxgppoo
    C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    C:\ProgramData\mlkjqdtd.log
    C:\Windows\TEMP\*.*
    C:\Users\Admin\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "InnoSetupRegFile.0000000001"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\RunOnce]
    "InnoSetupRegFile.0000000001"=-
    [HKEY_USERS\S-1-5-21-3965089189-2858296701-1019616836-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "XhpSapuf"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 20, 2013
  7. cheesiemonster

    cheesiemonster Private E-2

    Thank you for your reply and your help!

    I've turned off UAC and given admin status to the Ron account, and done the OTM steps as you said - log attached below.

    However, MGTools Getlogs. bat did not run properly, there was an error message saying MGTools.zip could not be created.

    Some other observations - the pmnnfrwl.exe program which was pushing the UAC prompt (when UAC was on) does not show on task manager>processes anymore. Also my last run of MGTools using the Admin account (my last post) left MGTools.zip on the Admin account desktop instead of C:\ (where I have MGTools.exe). Also even my last C:\MGTools.zip (from the last scan which successfully created this folder) seems to have disappeared. Not sure if that is relevant but thought I'd tell you.

    Very grateful for your help!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's MGlogs.zip not MGtools.zip Did you use Right Click and select Run As Administrator to run GetLogs.bat ?

    It puts in in both locations. ( the desktop of the account that ran it and the root folder and it is MGlogs.zip ). The one on the Desktop could not exist if the one in C:\MGlogs.zip does not exist because that is where it is copied from.
     
    Last edited: Jan 20, 2013
  9. cheesiemonster

    cheesiemonster Private E-2

    Hi there,

    Yes I did right click and choose run as administrator.

    Sorry I meant MGlogs.zip. There is one on the Admin desktop from yesterday afternoon when I did my last MGTools scan using the Admin account, and the C:\ version was still there (in fact I uploaded it from C:\). But MGlogs.zip is not on the C:\ anymore, although the one on Admin desktop is still there.

    Thanks for the help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on C:\MGtools\ReZip.bat and select Run As Administrator, then look in the C:\MGtools folder for a slightly different zip file named MGlogsR.zip Attach it to your next message.
     
  11. cheesiemonster

    cheesiemonster Private E-2

    Here it is...

    Thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs look good. Are you having any more problems?
     
  13. cheesiemonster

    cheesiemonster Private E-2

    Great!

    The computer seems to be running fine, but I can't turn UAC back on - when I click the option in the control panel, dialogue box doesn't open.

    Thanks so much for your help
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if following the below reenables it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. cheesiemonster

    cheesiemonster Private E-2

    That works! Great - the computer now seems to be running normally.

    Thanks so much for your help - hugely appreciated :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds