Myway Speedbar will not go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ITALI, Nov 4, 2004.

  1. ITALI

    ITALI Private E-2

    I have downloaded and used all the tools recommended in "Major Attitude" article 3507 and deleted the BHO {014DA6C1-189F-421a-88CD-07CFE51CFF10} using a number of tools as well as manually editing the registry. Every time I boot up, the Myway.speedbar's BHO is reinstalled. I have run Hijack This and would like to post the log file. I appreciate any help at all.
     
  2. Kodo

    Kodo SNATCHSQUATCH

    post your log as a text file attachment and we'll look at it.
     
  3. ITALI

    ITALI Private E-2

    Ok, here's the Hijack This log file (attached)
     

    Attached Files:

  4. ITALI

    ITALI Private E-2

    Hello out there. I see Kodo asked to look at my 'Hijack This' log file and a couple of other folks have viewed this thread since then. Does anyone have a clue how to resolve this issue?

    I did uninstall the 'Myway Speedbar', but when I noticed that it continued to attempt to reinstall, I contacted 'My Search Customer Service' who sent me an uninstaller file 'fiunins.exe'. When I executed the file, it indicated the PC was clean.

    As I said in my earlier post, I did download and use all the tools recommended in article 3507 following the instructions step by step. However, this 'Myway Speedbar' continues to attempt to reinstall at each reboot and actually installs the BHO
    {014DA6C1-189F-421a-88CD-07CFE51CFF10} in my registry. There doesn't seem to be a DLL or any file associated with it. I am using 'GIANT Antispyware' which alerts me to the attempted install and allows me to delete it, but there appears to be no way to prevent it from installing in the first place.

    I am really in need of some help at this point. Hope to hear from one of you experts soon.
     
  5. Kodo

    Kodo SNATCHSQUATCH

    you can load HJT and get rid of these

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)

    Other than that, I don't see any problem. People are reporting that Giant has been giving false positives so you could be experiencing that.
     
  6. PhilliePhan

    PhilliePhan Guest

    Hi ITALI,

    This particular malware often comes bundled with something that you knowingly put on your computer and didn’t bother to read the EULA – Kazaa and Fun Web Products are two of the more popular culprits.

    Perhaps you should use Windows Explorer to run a search of your computer for anything related to My Way, My Search, SpeedBar, Fun Web and the like and see what you turn up.

    Also, I wonder what some of those unnamed 016s in your log are.

    Just a thought,

    PP
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The O2 line Kodo gave was from Exact Search and/or MySearch. Fix it.


    Also fix these:
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
    O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} -
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -

    If that does not work, you need to also do what PP said and search your disk for those entries and also search your registry.
     
  8. ITALI

    ITALI Private E-2

    OK guys, thanks for the response. My latest HJT log is attached and you can see that that BHO is back again after fixing all the suggested items. I have also searched numerous times for related files & DLL's and removed any that applied. I still have missed something since the thing keeps reappearing in my registry. This is not likely a false positive since 'BHO Cop' confirms its existence and I can scan the registry and find that BHO in various places.

    Any other ideas? I can't believe this is so difficult to eliminate.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure BHO Cop is not what is preventing it from being deleted?

    Did you do searches of the registry as requested?
     
  10. Kodo

    Kodo SNATCHSQUATCH

    chas,
    I researched those last three O16's and they were ok. fyi.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But why was there nothing after the CLSID? I take that to be equivalent of file missing? O16 are always say to delete when in doubt anyway.

    And this one O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - appears on Giant as MiniBug.

    http://www.giantcompany.com/antispyware/research/spyware/spyware-MiniBug.aspx
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Itali,

    You also need to use Add/Remove programs to uninstall AWS Weather Bug. See the below line:
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
     
  13. Kodo

    Kodo SNATCHSQUATCH

    I saw that earlier. I added it to Lojack but forgot to post it in my post.

    I would agree that the file looks to be non-existant. I just wanted to let you know that those clsid's were associated with legit programs.
     
  14. ITALI

    ITALI Private E-2

    This is something I didn't notice earlier. The 3 O16's chas refers to only reappeared after I rebooted, just like the BHO reappears. Look at the attached HJT log which was run after I cleaned those 4 out, but before I rebooted. What's going on here?
     

    Attached Files:

  15. ITALI

    ITALI Private E-2

    ChasLang, to answer your comment about Weatherbug... I did uninstall it a couple of days ago. I guess the uninstall was not complete.

    I'll be back tomorrow guys. Thanks for your input so far.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not for the one I showed you on Giant's site.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay fix the next line with HJT:
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1

    Then reboot in safe mode and delete:
    C:\Program Files\AWS <-- the whole directory
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds