A
Ari
I'm getting repeated false alarms of a spyware program that
has already been removed from the system (before MSAS).
At first scan MSAS detected and removed the remains of the
spyware in the registry. The log says:
"
10.1.2005 14:48:28::Remove Threat (ID:14826)
10.1.2005 14:48:28::Clean Threat MyWay Search Bar (ID:14826)
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
[=64E4104A-AD8F-4468-9D81-3290F77798CC
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
10.1.2005 14:48:28::Removing registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
[=1859849278
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10.1.2005 14:48:28::Removing registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10.1.2005 14:48:28::Clean Threat MyWay Search Bar
(ID:14826) Complete
10.1.2005 14:48:28::Remove Threat (ID:14826) Complete
"
After that it has occasionally on logon made a realtime
protection alert of MyWay Search bar.
When "remove" is selected, it seems to remove the threat.
The log reads
"
11.1.2005
21:03:48::------------------------------------------------------------------
11.1.2005 21:03:48::Initializing Clean - (ScanID: 0)
11.1.2005 21:03:48::Remove Threat (ID:14826)
11.1.2005 21:03:48::Clean Threat MyWay Search Bar (ID:14826)
11.1.2005 21:03:48::Generating threat
11.1.2005 21:03:56::Clean Threat MyWay Search Bar
(ID:14826) Complete
11.1.2005 21:03:56::Remove Threat (ID:14826) Complete
11.1.2005 21:04:02::Unititializing Clean
11.1.2005
21:04:02::------------------------------------------------------------------
"
When a scan (with any options) is done, nothing is detected.
The registry keys MSAS deleted on the first run have not
come back. Neither there seems to be any other sign of MyWay.
While I otherwise do not consider this funny, the line
"11.1.2005 21:03:48::Generating threat"
is causing some amusement.
Any ideas how to get rid of this ?
has already been removed from the system (before MSAS).
At first scan MSAS detected and removed the remains of the
spyware in the registry. The log says:
"
10.1.2005 14:48:28::Remove Threat (ID:14826)
10.1.2005 14:48:28::Clean Threat MyWay Search Bar (ID:14826)
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
[=64E4104A-AD8F-4468-9D81-3290F77798CC
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
10.1.2005 14:48:28::Removing registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
[=1859849278
10.1.2005 14:48:28::Removing registry value
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10.1.2005 14:48:28::Removing registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}
10.1.2005 14:48:28::Clean Threat MyWay Search Bar
(ID:14826) Complete
10.1.2005 14:48:28::Remove Threat (ID:14826) Complete
"
After that it has occasionally on logon made a realtime
protection alert of MyWay Search bar.
When "remove" is selected, it seems to remove the threat.
The log reads
"
11.1.2005
21:03:48::------------------------------------------------------------------
11.1.2005 21:03:48::Initializing Clean - (ScanID: 0)
11.1.2005 21:03:48::Remove Threat (ID:14826)
11.1.2005 21:03:48::Clean Threat MyWay Search Bar (ID:14826)
11.1.2005 21:03:48::Generating threat
11.1.2005 21:03:56::Clean Threat MyWay Search Bar
(ID:14826) Complete
11.1.2005 21:03:56::Remove Threat (ID:14826) Complete
11.1.2005 21:04:02::Unititializing Clean
11.1.2005
21:04:02::------------------------------------------------------------------
"
When a scan (with any options) is done, nothing is detected.
The registry keys MSAS deleted on the first run have not
come back. Neither there seems to be any other sign of MyWay.
While I otherwise do not consider this funny, the line
"11.1.2005 21:03:48::Generating threat"
is causing some amusement.
Any ideas how to get rid of this ?