Myway Search Assistant Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xstitcher, Jul 8, 2009.

  1. xstitcher

    xstitcher Private E-2

    I was infected on Sunday July 5th and ran the Superantispy software and that seem to clear the issue, but I still have the Myway Search Assistant as a listed program. I see a previous post with the same issue and followed all the instructions up to including the post from Chaslang on 07-05-05 14:43 (http://forums.majorgeeks.com/showthread.php?t=66855). I believe the threat has been removed, but like rookiegirl it still shows in my "add/remove programs" and I want to make sure the threat is completely removed.

    I didn't know if the delmyway.reg given to rookiegirl would work directly for my PC. Attached are the log files. Please let me know if there's more to be done and how to get rid of the final traces of the Myway Search Assistant

    Thanks in advance for you help!
    (first time msg board, so please let me know if I've committed any faux paus!)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We cannot continue until you attach the last log that was requested which is the C:\MGlogs.zip file created by running MGtools.
     
  3. xstitcher

    xstitcher Private E-2

    Sorry :-o, here's the MGlog.zip...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 11
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O15 - Trusted Zone: http://*.ameritrade.com
    O15 - Trusted Zone: *.antimalwareguard.com
    O15 - Trusted Zone: *.gomyhit.com
    O15 - Trusted Zone: http://*.tdameritrade.com
    O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
    O15 - Trusted Zone: *.gomyhit.com (HKLM)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. xstitcher

    xstitcher Private E-2

    Took a few days for me to wrestle the laptop from hubby, but I've followed the instructions and attached are the logs. The Myway Search Assistant is still listed in the add/remove programs. Also, there's a really big gap in the programs listing between "AusLogics Disk Defrag" and "Autodesk Learning Assistance" (but that was there when I started looking at this).

    I do appreciate all your help, thanks for not giving up on me!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs it is not in your uninstall list so I'm not sure why it would show up. We will have to search for it in the registry inorder to create a fix.

    I'm not sure what you are referring to. Are you talking about the list of programs in the Add/Remove Programs list? And by "gap" do you mean a time gap/lag between listing items or are you referring to a space? If you are referring to a time gap, this is not something I can do anything about as it is your PC and software you are running not malware.

    I had a typo in my last fix which caused a few items not to get fixed. So let's fix them again and also search for MyWay.


    Now download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and past)
      • Myway
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. xstitcher

    xstitcher Private E-2

    I followed your instructions and it's still in the add/remove programs and is listed as "My Way Search Assistant".

    The gap I referring to was in the Add/Remove Programs list, there's a large amount of space (oodles of page/scroll down) between the 2 programs "AusLogics Disk Defrag" and "Autodesk Learning Assistance".

    Let me know if there's more I can do, I sure do appreciate your attention and help!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this registry patch and let me know if it is gone afterwards.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    I cannot help you with this. You can try the Software Forum.
     
  9. xstitcher

    xstitcher Private E-2

    Followed your instructions, I got one msg asking if I was sure I wanted to add to the registry and then next one saying it was successful (sorry didn't write down the exact msgs).

    I went back into add/remove programs and saw that it had the remove button now. So I clicked on it and got...

    Windows installer window:
    The feature you are trying to use is on a CD-ROM or other removable disk that is not available.
    Insert the 'My Way Search Assistant' disk and click OK.

    I hit OK, but I'm thinking that may have been a stupid thing to do, but not sure what it did, then popped up with another Windows Installer window:
    The path " cannot be found. Verify that you have access to this location and try again, or try to find the installation package 'MYWYDESA.MSI' in a folder from which you can install the product My Way Search Assistant. OK

    I hit OK, then a brief message "preparing to remove" it was removed from the list, but when I went back into add/remove programs, it was still there!

    Please don't give up on me yet. I sure do hope there's more to do! Thanks again for your time and patience!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's progress. Repeat the RegSearch I gave you earlier and attach the new log.

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log
    • C:\MGlogs.zip
     
  11. xstitcher

    xstitcher Private E-2

    I ran the registry search and when I went to run the MGTools, I accidentally ran the c:\MGtools.exe. I realized that wasn't the right thing, I then ran the c:\MGtools\GetLogs.bat, but I didn't find the zip file in MGtools subdirectory, but in the C:\ directory was one and I think it overwrote it when I ran the correct program. Let me know if I messed up.

    Here are the requested logs. I do want to mention that I haven't rebooted the machine for a few days, hubby hates to wait and puts it into hibernation. If I need to reboot, then let me know.

    I'm glad to hear we're making progress!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should reboot. Your logs do not show any signs of MyWay anymore. See what happens after a reboot.
     
  13. xstitcher

    xstitcher Private E-2

    Rebooted and it's still there. Is there more to do/check? Please let me know. Again, thanks for your time and patience!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly how does it show in Add/Remove Programs?

    Note this is really not worth worrying about since it is just a dead entry. The software is no longer active or installed. It does not even show in the registry via the name My Way Search. If could be using one of many numerical IDs referred to as a CLSID like the below one show in my previous fix

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D25F924-B9FE-4682-BF72-8AB8210D6D75}
     
  15. xstitcher

    xstitcher Private E-2

    The program appears as "My Way Search Assistant".

    Well, glad there's nothing to it. Thanks again for your help and all your time and patience!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it appears like the above with a space inbetween My and Way, then try the below.

    Doubleclick regsearch.exe to start the program.
    See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and past)
    • My Way
    • Assistant
    Then click "OK".
    Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    Attach this RegSearch.txt file.
     
  17. xstitcher

    xstitcher Private E-2

    Here's the file as instructed.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Did we get it?
     
  19. xstitcher

    xstitcher Private E-2

    WOO HOO!! THAT DID IT!!:celebrate I looked and looked for it and it is gone! Thanks so much for all your help!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds