popup box for mwsbar.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by dancer1, Jul 15, 2010.

  1. dancer1

    dancer1 Private E-2

    I have been working to get a pc used primarily my by niece & nephew repaired. My brother, and a friend of my niece also use it occasionally. It is running XP svc pack 2. It has 4 different user profiles.

    It has been running slow for ages. In all profiles on start up a dialogue box appears: rundll, error loading c:\proga~1\mywebs~1\bar\1.bin\mwsbar.dll, the specified module could not be found.

    I hope that I have correctly followed all of the 7 steps for removing malware.. I did each step to each user profile then moved on to the next step for each profile. Before completing all the steps the dialog box stopped appearing, but I did not think to note when that happened. I continued on completing all of the steps. I then toggled system restore.

    I then restored running teatime.exe to each profile. I then ran a scan using Spybot S&D. It reported one problem:sbi$ebeb7409 mywebsearchbar, hkey_local_machine\software\Microsoft\windows\current version\run\my websearch bar. I had Spybot remove it. The pop up dialog box began to show up again once I did that. Running regedit and deleting the line did not help. On reboot the line would reappear in the registry and the popup box kept coming back. I did a restore that stopped it from appearing. I then scaned again using Spybot. It again found the same problem. This time I did not have Spybot remove it. The pop up dialog box began to show up once again. I again did a restore, which has stopped it.

    It appears that the pc still has malware on it. So I am here requesting assistance.

    I have all the log files requested for each profile. I think that it is 5 downloads for each profile.

    I will start by posting them for just one of the profiles.

    Thank you for this stellar forum, and all the help it (you volunteers) provide.
     

    Attached Files:

  2. dancer1

    dancer1 Private E-2

    retry for 5th log

    5th log of first profile
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes the dialogue box you refer to relates to MyWebSearch. Not a major problem and the scanners seem to have dealt with it.

    You should not have done this until I have finished reviewing your logs!

    Ask Toolbar <--- Go to add/remove programs and uninstall this garbage.

    Mozilla Firefox (3.5.10) <--- You need to update this if you use it.

    What are these??

    • C:\awuakqbw.exe
    • C:\fsc.tmp
    • C:\fshvfgai.exe
    • C:\hpdjyy.exe
    • C:\sgncjm.exe
    • C:\splp.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\program files\ryads.exe
    C:\Program Files\Internet Explorer\SIGNUP\SET225.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET3CE.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET43.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET5B.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET6E.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SETBE.tmp
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running now!
     
  4. dancer1

    dancer1 Private E-2

    I have removed the Ask toolbar, but did not do it until after I had done the others things you requested. I somehow overlooked it at first.

    The PC being be Malware cleaned is not currently connected to the internet. So, I was not able to update FireFox yet. It belongs to my brother, and is used primarily by my niece & nephew.

    I did not know what any of the below were for:

    * C:\awuakqbw.exe
    * C:\fsc.tmp
    * C:\fshvfgai.exe
    * C:\hpdjyy.exe
    * C:\sgncjm.exe
    · C:\splp.exe

    Therefore, I used “shift, right click, delete” to remove them, and keep them out of the recycle bin.

    I think that I have followed your other instructions.

    I went away from pc while combofix was running. When I returned, I had been logged out of that profile. I logged back in. Combofix appeared to still be running, and was at the step where it was creating a log report. I let it finish. I think it did what it was suppose to do.

    I have attached the logs you requested.

    Scanning with Spybot S&D no longer shows the "my websearch bar” problem. This profile now appears to be fine.

    This is a PC with 4 different profiles. Is the correct sequence to work on one profile at a time, and then move on to the next profile? If yes, do I start a new thread or continue with this thread and post the 5 logs for the next profile within this thread?

    Thank you so much for your assistance Kestrel13!

    P.S. In my younger days I used to fly a hang glider, the specific model that I flew was a “Kestrel”.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It would be best to keep things neat and tidy if you were to make fresh posts for each profile, no confusion then and the thread won't become too lengthy. :)


    You are most welcome! *smiles*

    Oh I do envy you, I have always wanted to do this! :) How often did you get to fly?

    Now, back to finishing this profile off for you.

    c:\program files\Ask.com <--- delete this bold folder if it still exists.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job <--- delete this too.
    C:\tpjtsip.exe <--- and finally delete this file as well.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. dancer1

    dancer1 Private E-2

    I never lived very close to good hang gliding sites. I am in eastern MA. When I was flying it was never often enough. Wind speed and direction has to be just right. It was not unusual when the weather forecast sounded good for flying conditions in the White Mountains of NH, and we had driven 3 hours to get there, and then hiked a good distance with our 40 lb kites to the launch location only to find unsafe or poor flying conditions once we arrived. I did have around 15 flights from a mile long 30 feet high sand dune cliff near the entrance to Cape Cod. Those flights typically lasted about an hour when I had to land mostly due to lack of circulation to my legs from sitting on my swing seat harness for so long. Usually those flights were in heavy Nor East rainstorms with winds of 30 mph or more with 10 to 20 other hang gliders in the air at the same time. It was a miracle that there were never any mid air collisions with so many kites up at once in such a small flying zone. I am now 60 years old and it has been about 35 years since I last flew a hang glider. It is a very dangerous sport at the more advance level, but very exhilarating. Soaring above the fall foliage of the White Mountains is an unforgettable memory of beauty. A beginner lesson is typically very safe and hugely exciting. Hang gliding requires a lot of shoulder and up arm strength during the taking off, but then it is usually not too strenuous.

    Now back to the matter at hand.
    c:\program files\Ask.com is no longer there.

    I received a success message for adding fixME.reg to the registry.

    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job was no longer there once I removed the app using add & remove programs.

    I deleted C:\tpjtsip.exe

    It appears that this profile is now clean. I have 3 more to do. I will hold off doing the 1 to 9 last steps until the other profiles have been cleaned too.

    I will run the 5 apps for the next profile, and post them under a new thread as you have requested.

    Thanks again Kestrel13 for you superb help. It is greatly appreciated.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh it must have been quite literally breath-taking. :cloud9 I had dreams of flying when I was a little girl, maybe I should go get myself a lesson or two ;)

    You are most welcome for the assistance. Safe surfing and take care. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds