LGB.exe preventing prog running, win 7

Discussion in 'Malware Help (A Specialist Will Reply)' started by yodel99, Apr 19, 2011.

  1. yodel99

    yodel99 Private E-2

    Hello,
    Win 7 computer, when I try to run a program getting a constant user account control message wanting to run "lgb.exe" from unknown publisher... when I say 'no', it goes back to win explorer file listing.... searched and could not find the lgb.exe file anywhere... it also pops up by itself... so at the moment I have 8 blinking win 7 shields and cannot run anything. ideas?
    Yodel99
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. yodel99

    yodel99 Private E-2

    Hello,
    I've only now found time to work on this... I started the instructions, but the computer will not allow me to run any programs, or open explorer... i continually get the user account control dialog box asking me to install lgb.exe..when i say no it comes back.. 2-3 times. At one point somehow explorer finally came up.... i was able to drag ccleaner, hijackthis, avg_free, spybotsd162 and pcsafedoctor to the root dir... going to try and run them from command line...will keep you posted.. thanks!! yodel99
     
  4. yodel99

    yodel99 Private E-2

    Hello again,
    i was able to run hijackthis from cmd line and save a log file... figured out the removeable drive letter (it was J... for some reason i think the virus created d, e, f, g, h and i... as fakes). here is the log file... any help is SUPER appreciated!! thanks yodel99

    Logfile of HijackThis v1.99.1
    Scan saved at 7:44:49 PM, on 4/22/2011
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16766)
     
    Last edited by a moderator: Apr 24, 2011
  5. yodel99

    yodel99 Private E-2

    Also, in safe mode i can run 'regedit' without problems... i searched for lgb but did not find anything... i'd be glad to work in the registry if you have ideas.. thanks yodel 99
     
  6. yodel99

    yodel99 Private E-2

    To all:
    Forgive my prev post of not following all the instructions... I was nervous...
    I have gone through all of them now, and wish to report findings; some went well, others were strange. Although all seems working now, I'm not confident

    step 1- prevented from following because lgb popped up everytime and programs would not run
    step 2 - same
    step 3 - same
    step 4 - from safe mode cmd line was able to ensure msconfig normal startup
    step 5 - control panel allowed to work, did not find any from the list
    step 6 - from safe mode cmd line, ran defogger successfully
    step 7 a - put files on a cd and copied to root dir
    step 7 b - could not disable uac from windows; found info at howtogeeks to do manually, it worked
    step 7 c - installed and ran SAS, at beginning a dialog box popped up 'lgb.exe app error, unable to start, 0xc0000005"... SAS kept running even though the dialog box would not go away, ran for about 1 hour, found 2 files, but did not give a log file; so i tried the portable version; ran found zero, after all steps, searched win for *.log and found log from first time i ran (found 2 files), and from second time (found none); attached the first one
    step 7 d - ran malwarebytes; it installed and launched, but a dialog came up asking what program the computer should use to run regsvr32.exe... i skipped it, mb kept running, found and fixed 5 files, opened the log and saved to a notepad file
    step 7 e - combofix had problems. it kept thinking that mcafee was running, i disabled and got same results, then totally uninstalled mcafee, and combofix still thought it was running, said ok, it loaded, got to the blue screen saying scanning for infected files, and then it said \STARtools\StarToolUP\ error, program unexpected at this time, left for 30min, no change, closed myself and re-did, got same startool msg and left for over 60min, no change
    step 7 f - skipped rootrepeal since 64 bit;
    mgtools ran, and all seemed ok, got log file

    So, now the pc appears ok.... I'm not sure how to know if it is or not. I have not continued the steps, as I'm hopefully to hear from you on if I should or do something else. Many Many thanks!! yodel99
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell Kestel how things are working now!
     
  8. yodel99

    yodel99 Private E-2

    Hi!
    followed the instructions and attached the two logs... but there was a few odd things; when avenger executed, a dialog came up "cmd.exe -no disk, there is no disk in the drive, please insert a disk into drive \device\harddisk1\dr1 .... it gave cancel, continue and try again choices... i hit try again 2-3 times and the dialog went away, and it finished. ran ccleaner with only temp files selected, ok, ran getlogs ok, but never saw the trendmicro agreement.. it just ran through... does this make sense? thanks for your help, yodel99
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Avenger didn't run properly. Did you include everything in the quote box? Let's see if you can just remove them manually:

    Use windows explorer to find and delete:
    C:\vsyfbum.txt
    C:\Users\Jamie\AppData\Local\ln54jmg5d0c0
    C:\ProgramData\1u0ht75dqlgd1e6l07o0sy6qerxj
    C:\ProgramData\ln54jmg5d0c0

    Let me know if you have any problems doing that. You also need to tell me how things are running!!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  10. yodel99

    yodel99 Private E-2

    Hello,
    When I ran avenger, the first time I didn't realize I needed to type in 'files to delete'" ... and it gave errors... second type I cut and paste all from notepad and it ran without errors.

    Was not just able to find and delete the files you indicated, ok.
    Ran getlogs and the log is attached. I never got a microtrend message to accept...it was all inside a cmd diaglog box and end with a press any key to continue.... (this is Win7 if it makes a difference).

    Computer appears to run ok, no more lgb. But I have not finished the orignal malware steps (still haven't changed the uac or system restore stuff).

    I do notice several drives showing that do not exist. e, f, g, h and i. To get the log file my stick maps to j. seems odd.

    thanks, yodel99
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to copy and paste everything in the quote box. You have two new infected items to remove:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. yodel99

    yodel99 Private E-2

    Avenger ran fine.
    ran ccleaner, temp only, ok
    ran getlogs, go msg about steelwerx whoami...followed directions and closed
    now the extra drives appear gone.
    when i attached avenger.txt, got an error 500 from upload tool, after closing and trying again, the file was lost... I cannot find. Did not run again, but can if you want me to.

    mglogs file is attached ok.

    thanks
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Users\Jamie\AppData\Roaming\Microsoft\Windows\Templates\ln54jmg5d0c0
    C:\Windows\System32\drivers\nhhht.sys
    C:\Windows\System32\drivers\uuzpx.sys
    C:\Windows\SysWOW64\drivers\khqgnlbj.sys
    C:\Windows\SysWOW64\drivers\nhhht.sys
    C:\Windows\SysWOW64\drivers\uuzpx.sys
    C:\Windows\SysWOW64\drivers\khqgnlbj.sys
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


    Could you please get this: ÀúS into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Please go to virustotal and upload the following files for analysis, and let me know the results.

    • C:\Windows\ÀúS

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  14. yodel99

    yodel99 Private E-2

    Hi!
    Ran OTM, no problems. Will paste the results.
    Ran the AUS program, and got the collect file. Will attach.
    Went to Virustotal and it said the file in question had already been observed. I will attach a printscreen bmp of the results.
    Ran the getlogs prog, file attached.
    PC performance = seems ok, no more random false drives, pop up everytime I install the usb stick asking to scan or not... i've been saying no.
    Many thanks! I'll be glad to try anything else. thanks yodel99

    OTM
    All processes killed
    ========== FILES ==========
    C:\Users\Jamie\AppData\Roaming\Microsoft\Windows\Templates\ln54jmg5d0c0 moved successfully.
    C:\Windows\System32\drivers\nhhht.sys moved successfully.
    C:\Windows\System32\drivers\uuzpx.sys moved successfully.
    C:\Windows\SysWOW64\drivers\khqgnlbj.sys moved successfully.
    File/Folder C:\Windows\SysWOW64\drivers\nhhht.sys not found.
    File/Folder C:\Windows\SysWOW64\drivers\uuzpx.sys not found.
    File/Folder C:\Windows\SysWOW64\drivers\khqgnlbj.sys not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Amy
    ->Temp folder emptied: 35225147 bytes
    ->Temporary Internet Files folder emptied: 113064483 bytes
    ->Java cache emptied: 9639 bytes
    ->Google Chrome cache emptied: 1905008 bytes
    ->Flash cache emptied: 37947 bytes

    User: David
    ->Temp folder emptied: 2323644 bytes
    ->Temporary Internet Files folder emptied: 55211712 bytes
    ->Java cache emptied: 38997 bytes
    ->Flash cache emptied: 2518 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Jamie
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 184710 bytes
    ->Java cache emptied: 9637 bytes
    ->Flash cache emptied: 532 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
    RecycleBin emptied: 30914 bytes

    Total Files Cleaned = 198.00 mb


    OTM by OldTimer - Version 3.1.17.2 log created on 04242011_204114

    Files moved on Reboot...
    C:\Users\Jamie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    Registry entries deleted on Reboot...
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. yodel99

    yodel99 Private E-2

    Wow!! Think I'm in the clear.
    Many thanks to Kestrel13! and TimW, for your help and patience!!!
    Your willingness to share your incredible skills is very humbling...
    I will do my best to honor your time by staying protected.
    Many blessing to you both.
    Thanks, Yodel99
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On behalf of us both, you're welcome! Safe surfing.
     
  18. yodel99

    yodel99 Private E-2

    Very sorry to bother you again... but I found a glitch.
    One of the standard users won't recognize an exe file. Trying to run a program, or open file explorer causes windows to ask what program you want to use to run the program. Admin does not have this problem. The other standard user does not have this problem. I followed all steps and all was fine until I noticed this last night. How do you want me to proceed?
    thanks again, yodel99
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. yodel99

    yodel99 Private E-2

    Hi!
    Ran the exe fixer - got a message dialog box "reg editor, cannot import... not all data successfully written... some keys are open by the sys or other processes"...

    Since it asked from admin password to copy to the infected pc, I went and insured all logged out execpt standard user in question - re-ran and got same message, rebooted and again got same message.

    went on and ran sas following prev instructions, nothing found, log attached
    ran mb following prev instructions, nothing found, log attached

    will await your direction, thanks yodel99
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running this on the account with the exe problem:

    Now download and Run exeHelper from Raktor[/B]

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
     
  22. yodel99

    yodel99 Private E-2

    Ran exehelper, log is attached, it is actually named exehelperlog.txt
    It appears that I can run exe from all std users and admin user ok.
    thanks, yodel99
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you are having any other malware issues.
     
  24. yodel99

    yodel99 Private E-2

    Hi!
    I don't thinks so... I ran several types of programs from admin and the other 3standard users with no problem. This weekend I'll follow 'how to protect yourself from malware' instructions. Many thanks again. Yodel99
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! And you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds