wbl.exe Security popup box with virus detection

Discussion in 'Malware Help (A Specialist Will Reply)' started by BestSteak, Apr 8, 2011.

  1. BestSteak

    BestSteak Private E-2

    I have an old computer that is in my business. It's main function is video survailence for my business, however it does have internet. I came to work yesterday to find this computer popping up a bogus page stating it had a virus and it looked like a virus scanner running. I was told that they tried to close it but it kept popping back up. I tried to run avg but it found nothing. I tried to run spybot but during the scan it gave me errors stating something like i didnt have the proper permissions to perform these actions. There are no user accounts set up on this computer because the video security system reboots automatically every night and erases a certain amount of space on the hard drive to make room for the next days recordings. This computer would not let me on the internet except when i did attempt to get on the net it would first bring up the bogus security firewall page then i could control alt delete and it would then bring up an internet explorer page. I tried running trend micro house call but it found nothing. even in safe mode I was still having these same issues. I tried running spybot from a flash drive but still got the same errors. I disabled everything in msconfig. i was finally able to download avast and ran it. IT FOUND the virus and i told it to delete it. I no longer have the bogus scanner and security system popping up BUT I still have some major problems. If i click internet explorer i get the dialouge box that ask me what program i want to use to open it with, when i select internet explorer it goes to the browser then changes to c:\Documents and Settings\Owner. It will no longer run any .exe i try as it keeps asking me what program to use to open it with. I can not perform any of your steps in the read me first section as my computer will not cooperate. Even in control panel most everything i click on comes up C:\WINDOWS\system32\rundll32.exe Application not found. But from the run box i can do sysdm.cpl and it brings up my system properties....


    System:
    Microsoft Windows XP
    Home Edition
    Version 2002
    Service Pack 3

    Registered to:
    Owner
    None
    76477-OEM-0061581-25877

    Computer:
    AMD Athlon(tm) XP 2200+
    1.80 GHz, 224 MB of RAM

    I am at a loss for what to do except to wipe it out and start over. However as old as this machine is I would probably be better off just buying a new one and swap out the video card and install the security system software. I am in no real dange of loosing anything importants as i have all my documents and stuff already backked up form about 6 months ago.

    I also need to add that at some point earlier when i was attempting to find out what was harrassing my machine i went in to the registry and deleted 2 lines. But my memory fails me as to exactly where and what but it had something like default and the string had wbl.exe in it. I found that simply fromnoticing the processes running and I had to keep killing the wbl.exe process so I looked for it in regedit.

    Any help or suggestions you can throw my way would be greatly appreciated. Sorry I can't perform all the required stuff in the read me but I gotta start somewhere.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans

    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. BestSteak

    BestSteak Private E-2

    Thank You for your help. While I was waiting for some one to reply to this and figuring I had nothing to lose, my son and I did some work on our on to this computer and got it in decent shape. We upgraded to Internet Explorer 8 and installed Avast! and Spy-Bot Search and Destroy. We did this using Firefox from a flash Drive and got things somewhat going again. Spy-Bot found somethings and we deleted them also Avast! found somethings and we also deleted them. We also opened up the computer and replaced the ram chip to Total Physical Memory 1,024.00 MB. Anyway We got this thing somewhat functional to be able to perform the tasks that you requested. I went through your list and completed them all!

    Notes:
    After running rkill.exe I got the message about the proxy server:
    Windows was configured to use a proxy! Proxy settings have been removed.

    The Proxy Server that was configured is:

    If this was a valid setting, please double-click on the rk-proxy.reg file on your desktop and allow the data to be merged to restore your proxy settings.
    I DID NOT CLICK THE rk-proxy.reg that now sits on my desktop!

    I also got error #4 when running MGTools and DID NOT make the fix to the Microsoft .NET Framework

    Otherwise all went well and I am attaching the logs.
     

    Attached Files:

  4. BestSteak

    BestSteak Private E-2

    Plus this 5th log.

    I also noticed that before you told me to do these task we could not update Windows Using Automatic updates . But after running SAS it popped up asking me to turn it on in system tray but I have not done anything as of yet. This also happened with my firewall at the same time and we still have not taken any action on it either.

    Also, I forgot to mention earlier.... BEFORE getting your instructiuons I deleted JAVA and JSE and Active X from add/remove programs. Java was then reinstalled but nothing else.

    Thank You for your time and help!
     

    Attached Files:

    Last edited: Apr 10, 2011
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please go here and download and run the AVG Removal Tool.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Owner\Local Settings\Application Data\8j0y77kdip5go827e8k57d33
    C:\Documents and Settings\All Users\Application Data\8j0y77kdip5go827e8k57d33
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG8_TRAY]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. BestSteak

    BestSteak Private E-2

    I disabled Spybots tea timer per your instructions.
    I then ran the AVG Removal tool as instructed.
    I then disabled all anti virus and anti spyware programs as instructed.
    I ran C:\MGtools\analyse.exe as instructed.... I found all the lines you wanted check marks in except
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
    Those 2 lines were not there to put a check in the box, but I continued with your instructions.
    I followed your instructions for the Combo Fix program. Dragging the text box and dropping to the combofix.exe as instructed but I noticed even after doing so they were still seperate items on my desktop but afterwards the CFScript.txt turned into an Internet Explorer icon that now works.

    I ran Ccleaner and only left check marks in the temporary system files and the temporary internet files, all else was unchecked under the first tab. I did not even go the the other tab.

    I then ran the C:\MGtools\GetLogs.bat File but never saw the license agreement pop up. I also got an error while running this. (Process Dll.exe - Application Error The Application Failed to Intialize Properly (0xc0000135). Click on OK to terminate the application.

    So where did the C:\ComboFix.txt file go to? I can not find it to included for you.
    I am attaching the C:\MGlogs.zip file.

    Everything seems to working properly however I have noticed it looks like I still have some avg files on this computer. C:\$AVG8.VAULT$

    Not sure if I am completely fixed or not.

    I found the C:\ComboFix.txt by searching for it and attached it for you.

    Thank You!
     

    Attached Files:

    Last edited: Apr 14, 2011
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. You can just manually delete the C:\$AVG8.VAULT$ folder.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds