Abebot: wml.exe error message

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lindsay.Nicole, Apr 23, 2008.

  1. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    Recently, my moms computer started getting red and white pop warning messages telling me I have wml.exe/abebot. I also get a yellow triangular warning icon indicating I have security issues. If I click on any of these warnings I get directed to a page to buy anti-spyware. Before finding this site antivirus was able to find and delete Zlob.

    My problem is, I am trying so hard to run all of the steps you guys want us to run first to remove malware, but her computer is so jacked up, it's not allowing me to complete everything. It won't let me run programs. It was let me install ad-aware (even in safemode...it says I don't have permission, what the poo?). It's not letting me install other programs you guys suggest to install. I find that when I try to run the online anti-virus the graphics fudge up so I can't see what I'm supposed to do. This happened when I tried to search the internet to find out how to remove the virus.....there were alot of blank spaces and I could only read every other sentence or so. At first the task manager would not work. Occasionally it won't let me go to Control Panel or Run, it gives me a strange error message about a shortcut.

    Her comp is completely taken over and I don't know how to work around it so I can complete the malware removal steps.

    Any suggestions?

    She is running Windows XP Media Edition.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try running the part of the the cleaning procedure for MGtools. It should run as it normally does even with this infection. If it runs, attach the requested C:\MGlogs.zip file.
     
  3. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    Thanks so much for responding!

    I ran MGtools and was actually able to run Malwarebytes as well. Both logs are attached. There were 4 files MGtools had a problem getting rid of. If you need me to list them, let me know. After a reboot the machine seems operable (task manager works, run works, control panel opens, a program that would not run now runs; all of which I seemed to have a problem with previously). It is late and I have to go to bed, but I tomorrow I will try to do the preliminary steps again and see if I can actually complete them.

    I appreciate all of your help!!!

    Lindsay

    [EDIT] Well, some functionality is not working. While trying to open IE or Firefox I get a message saying C:\Program Files\Mozilla Firefox\firefox.exe is not a valid Win32 application. If I open these browsers right after the computer starts up, they appear to work. But if I wait to open them until later I get this message. When trying to instal SS&D, I get an error saying not enough quota is available to process this command. And NOW while trying to open task manager it does nothing. So after trying to open it thru Run, it says "Attempt to access invalid address." Poop.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MGlogs.zip file was from safe boot mode. Can you run in normal boot mode now? Also see if you can now run SUPERAntispyware and then ComboFix. If you can then attach the logs from them.

    Is your copy of Spy Sweeper a paid version or free trial?
     
  5. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    I caught your response just before shutting down for the night.

    I went ahead and took care of everything you asked. Attached are the logs all ran in normal mode. As for the Spy Sweeper, if I'm not mistaken that was purchased in a store. Is there a way for me to find out for sure?

    I will check this when I get a minute tomorrow and see what I need to do next. Thanks!

    Lindsay
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you run scans with it does it fix anything or does it only report?


    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 2
    SpyHunter
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [msci] "C:\DOCUME~1\Owner\LOCALS~1\Temp\20061217174228_mcinfo.exe" /insfin
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    Spy Sweeper is a paid version.

    These files did not show up when I ran Run C:\MGtools\analyse.exe as instructed:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [msci] "C:\DOCUME~1\Owner\LOCALS~1\Temp\20061217174228_mcinfo.exe" /insfin

    There were no files or folders from previous dates to delete in:

    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Received a "Success" message after merging fixme.reg.

    Things appear to be running normally. This time around I have not had any problems opening task manager or control panel, etc, as I have had problems in the past. The only thing is it won't connect to the internet, but I'm pretty sure that's something I have to fix with the wireless, which I will mess with when I have a chance to.
     

    Attached Files:

  8. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    Add or Remove Programs takes an awfully long time to load. Haven't experienced this before on this machine...that is the only odd problem I'm experiencing right now.

    [EDIT] While trying to correct wireless issues, I attempted to uninstall the wireless driver via Add or Remove Programs (which took forever to load). It never successfully removed the driver, so I attempted to reboot and try to uninstall via cCleaner. It would not reboot or do anything so I had to hold the power button and shut down...not something I enjoy doing. Now after I type in the password to log in, I get a blue screen that sits there forever, and finally, minutes later, the desktop loads. Poop...what have I done?
     
  9. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    I have tried everything I can think of to get the wireless internet working on this darn computer but am not having any luck. It won't grab an IP address. Do you think because of the virus it has corrupted a file and is not allowing me to connect?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    Based on previous logs it does not look to be related to malware.

    Make sure that you are not blocking it within your firewall or any other protection software.

    Also make sure that you have set your network connections Internet Protocol (TCP/IP) configuration to Obtain and IP address automatically and that you also have Obtain DNS server address automatically. You can check this as below:

    • Go into Control Panel -->Network Connections.
    • Right click on your connection
    • and click Properties.
    • On the Properties page, highlight Internet Protocol(TCP/IP)
    • Click Properties. This will bring up another page.
    • Select Obtain DNS Server Automatically.
    • Also select Obtain DNS server address automatically.
    • Click the ok button. The page will close.
    • Press ok on the page in front of you.
    • Restart the computer.
    If this does not work it may be better to work this in the Networking Forum. Does your Wireless card have good signal strength. Maybe you just need to release and renew your connection.
     
  11. Lindsay.Nicole

    Lindsay.Nicole Private E-2

    Okay, thanks so much for all of your help!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds