My Way Search Assistant

Today I was visiting some forums which I regularly visit. I found out that people are having problems with a toolbar called My Way Search Assistant. So I thought that it would be a good idea that I write about it.

What is My Way Search Assistant:

MyWay Searchbar, also known as MyWay Speedbar, MyWay Search Assistant, Webfetti Toolbar, MyWebSearch, or MyWeb Searchbar, is a malware and search toolbar program that allows the user to query Google, Ask Jeeves, Yahoo!, and LookSmart search engines. HP and Dell pre-install this software on some of their commercially sold PCs. It is also bundled with some versions of Kazaa. It is also a part of the FunWebProducts suite of utilities such as Smiley Central, Webfetti, Cursor Mania, My Mail Stationary, My Mail Signature, My Mail Stamps, FunBuddyIcons, PopSwatter, and Popular Screensavers.

How does it work:

MyWay Searchbar attaches itself to the Internet Explorer and Netscape Navigator browsers, adding search functions and pop-up blocking. MyWay also collects data about the user’s surfing habits and sends it back to the MyWay server to tailor ads toward the user’s interests.

How to remove it:

There are so many ways to remove My Way Search Assistant but this way seems like the most easy and the most effect one for the people. Please follow the instructions below:
-Go to Start –> Run
-Write(or copy and paste) the following:
msiexec.exe /x{78d944d7-a97b-4004-ab0a-b5ad06839940}
-Press Enter
-If a prompt comes, select yes.
You’re all done. My Way Search Assistant has been removed from your computer :-).
Do tell me about your experiences.
References:
wikipedia


Posted

in

, ,

by

Comments

16 responses to “My Way Search Assistant”

  1. Joseph

    I followed your suggested remedy and got a prompt: This option is only valid for products that are installed.
    A question: Is my Web Search Assistant the same as MyWay.MyWebSearch? If not, could you please suggest a solution?
    Thank You

  2. Sanix

    Joseph MyWay.MyWebSearch is different. Please post your hijackthis log so that I may be able to see what exactly is creating the problem for you. To post the hijackthis log, please see the following article and copy and paste the log here in comments.
    How to use Hijackthis

  3. dawn

    great stuff! so easy lol the owner of this desk before i started working here seemed to have contracted this bug lol and i havent been able to fully remove it.

  4. MXS

    Great. Worked. Resolved. Thank you!

  5. Chris

    I had a problem with what you described. I tried a complete norton virus scan, complete windows defender scan and it was still there but could not remove it. Thank you for the info. I clicked start/run/then copy and pasted your info. then said o.k. It removed it. Thanks again.

  6. Troy

    msiexec.exe /x{78d944d7-a97b-4004-ab0a-b5ad06839940} worked for me!
    Thanks!

  7. Linda Hinners

    Recently my home page was taking a very long time to load tho I have a cable connection with turbo boost. Have been concentrating on getting rid of My Way SA for a day with no success until I got to your site. Very easy to use and finally wiped out My Way SA. Thank you.
    Still have a problem and think it may be related to Yahoo’s new page – the m.www.yahoo.com. So that is where I’m going next.

  8. Amanda

    I am having problems with my password. Ive went through all the hints and dont have another email to send a new 1 to what should I do? Ijust set up the account and would really like to use it. Please help!

  9. Confused

    I have the same problem as Joseph. When I try your fix, I get
    this action is only valid for products that are installed. I am running Windows 7. Can you suggest a fix. It does not show up in the control panel so I can’t get rid of it that way, nor can I find it under Program files. It’s really driving me crazy.

  10. Maria

    I am having the same problem as “Confused”. When I ran your program, replied that it was only valid for programs installed on my computer. Everytime I log onto the internet, I get a screen saying “Internet explorer has been corrupted. Then goes on to say it has been corrupted by My Way (Results.MyWay.com). Then I automatically get the pop-up screen where I usually manage my search providers. My way shows up as default provider. All the buttons are disabled that would allow me to delete it or change my default provider to bing or yahoo (my other 2 listed. I have a terrible time doing searches now, because many of them are redirected to various ad/unwanted web sites. When I access “manage default providers” without accessing the internet, I cannot find MyWay listed anywhere. None of my antivirus/antimalware programs have detected it on my computer.
    Help!!!!!!!

  11. Maria

    I did what you suggested to “Sanix”, and ran the hijack this program. Here is my log:
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes’ Anti-Malware\mbamservice.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\Malwarebytes’ Anti-Malware\mbamgui.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Windstream_BCUC\McciTrayApp.exe
    c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\DAP\DAP.EXE
    C:\WINDOWS\system32\msiexec.exe
    C:\Documents and Settings\Nathan.MARIA-4FC7BA5D3\Desktop\HijackThis.exe
    R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.windstream.net
    R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windstream.net/
    R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 – HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Windstream
    R3 – URLSearchHook: AVG Security Toolbar BHO – {A3BC75A2-1F87-4686-AA43-5347D756017C} – C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
    O1 – Hosts: ::1 localhost
    O1 – Hosts: 91.212.127.227 winsecure2009.microsoft.com
    O1 – Hosts: 91.212.127.227 winsecure2009.com
    O1 – Hosts: 91.212.127.227 http://www.winsecure2009.com
    O2 – BHO: AcroIEHelperStub – {18DF081C-E8AD-4283-A596-FA578C2EBDC3} – C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 – BHO: AskBar BHO – {201f27d4-3704-41d6-89c1-aa35e39143ed} – C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O2 – BHO: WormRadar.com IESiteBlocker.NavFilter – {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} – C:\Program Files\AVG\AVG9\avgssie.dll
    O2 – BHO: (no name) – {5C255C8A-E604-49b4-9D64-90988571CECB} – (no file)
    O2 – BHO: Search Helper – {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} – C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 – BHO: Windows Live Sign-in Helper – {9030D464-4C02-4ABF-8ECC-5164760863C6} – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 – BHO: AVG Security Toolbar BHO – {A3BC75A2-1F87-4686-AA43-5347D756017C} – C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
    O2 – BHO: Gamevance Text – {BEAC7DC8-E106-4C6A-931E-5A42E7362883} – C:\Program Files\Gamevance\gvtl.dll (file missing)
    O2 – BHO: QUICKfind BHO Object – {C08DF07A-3E49-4E25-9AB0-D3882835F153} – C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
    O2 – BHO: Java(tm) Plug-In 2 SSV Helper – {DBC80044-A445-435b-BC74-9C25C1C588A9} – C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 – BHO: Windows Live Toolbar Helper – {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} – C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 – BHO: JQSIEStartDetectorImpl – {E7E6F031-17CE-4C07-BC86-EABFE594F69C} – C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 – BHO: DAPIELoader Class – {FF6C3CF0-4B15-11D1-ABED-709549C10000} – C:\PROGRA~1\DAP\DAPIEL~1.DLL
    O3 – Toolbar: AVG Security Toolbar – {CCC7A320-B3CA-4199-B1A6-9F516DD69829} – C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
    O3 – Toolbar: Ask Toolbar – {3041d03e-fd4b-44e0-b742-2d9b88305f98} – C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O3 – Toolbar: &Windows Live Toolbar – {21FA44EF-376D-4D53-9B0F-8A89D3229068} – C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 – HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 – HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 – HKLM\..\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
    O4 – HKLM\..\Run: [Adobe ARM] “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
    O4 – HKLM\..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
    O4 – HKLM\..\Run: [Malwarebytes’ Anti-Malware] “C:\Program Files\Malwarebytes’ Anti-Malware\mbamgui.exe” /starttray
    O4 – HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 – HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 – HKLM\..\Run: [IntelliPoint] “c:\Program Files\Microsoft IntelliPoint\ipoint.exe”
    O4 – HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 – HKLM\..\Run: [Windstream_BCUC_McciTrayApp] “C:\Program Files\Windstream_BCUC\McciTrayApp.exe”
    O4 – HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
    O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 – HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -“Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)” -“http://coursewareobjects.elsevier.com/objects/elr/Potter/fundamentals7e/testpage.html”
    O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 – Extra button: Blog This – {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} – C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 – Extra ‘Tools’ menuitem: &Blog This in Windows Live Writer – {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} – C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 – Extra button: Send to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 – Extra ‘Tools’ menuitem: S&end to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 – Extra button: (no name) – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 – Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
    O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
    O16 – DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) – http://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
    O16 – DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) – http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
    O16 – DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) – http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
    O16 – DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 – DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} – http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 – Protocol: linkscanner – {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} – C:\Program Files\AVG\AVG9\avgpp.dll
    O20 – Winlogon Notify: avgrsstarter – avgrsstx.dll (file missing)
    O22 – SharedTaskScheduler: Browseui preloader – {438755C2-A8BA-11D1-B96B-00A0C90312E1} – C:\WINDOWS\system32\browseui.dll
    O22 – SharedTaskScheduler: Component Categories cache daemon – {8C7461EF-2B13-11d2-BE35-3078302C2030} – C:\WINDOWS\system32\browseui.dll
    O23 – Service: AVG Free WatchDog (avg9wd) – AVG Technologies CZ, s.r.o. – C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 – Service: Google Update Service (gupdate) (gupdate) – Google Inc. – C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 – Service: Java Quick Starter (JavaQuickStarterService) – Sun Microsystems, Inc. – C:\Program Files\Java\jre6\bin\jqs.exe
    O23 – Service: MBAMService – Malwarebytes Corporation – C:\Program Files\Malwarebytes’ Anti-Malware\mbamservice.exe
    O23 – Service: McciCMService – Alcatel-Lucent – C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 – Service: NVIDIA Display Driver Service (nvsvc) – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe

    End of file – 9845 bytes

  12. sharife

    whene i ran your program replied that this action is only valid for products that are currently installed

  13. Sanix

    That means that My Way Search Assistant is not installed on your system. I have only given a silent uninstall command for My Way Search Assistant.

  14. Ross

    I am having the same problem. “This action is only valid for products that are currently installed.” This is keeping me from using my IE but only at random. For instance, sometimes I can go to a news site (www.cnn.com for example) and sometimes not, same with google, facebook, my online banking sites. Please help, it is my wife’s computer and I have tried everything I can!

  15. Rhonda

    I laughed as I looked through my program list…..it’s gone, finally. All I could hear playing in my head was the witch is dead song from Wizard of Oz. You are the bomb

  16. Amy

    I’m also getting the message about not being installed. I’ve tried to delete it from the folder directory, but it’s telling me that access is denied. Grrrrr.