Noob needs help with WinAntiSpy or UWAS6_0001....NetInstaller.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by steveidahousa, Sep 9, 2006.

  1. steveidahousa

    steveidahousa Private E-2

    Hello, and thanks for helping a Noob,

    I have been assisting an elderly Man with his computer, on one of the occasions that I was helping, he brought to my attention a new Icon on his desktop and in the System Tray. I was unable to find anything regarding it in Add\Remove Programs, and started the work of researching how to remove it.

    Several attempts have been made, and it keeps comming back. Norton Antivirus finds it and gives category of Security risk Threat. We have even gone as far as contacting Symantec, which resulted in $69.99 for a Analyst to take over the system remotely, delete the file and tell us that the issue had been resolved.

    Once that was done, we restarted the computer and promptly ran another Norton Antivirus Scan. Only to discover that the program was back and not removed after all.

    Please assist, as it seems that even Symantec is hard pressed to get this undercontrol.

    The Symantec Analyst (Indonesia we guess) downloaded and installed Hijack this, we were privy to watch as this was run, so we can more than likely get a log file if that is what will need to be done.

    Just let us know.

    Thanks
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome to Majorgeeks!

    Below is our 1st steps guide for you to run on that PC, its a proven set of steps to initially get us to a point when most of the malware on a PC are removed or highlighted in which then a custom tailored set of fruther removal steps are posted from our experts in malware removal,

    Run this first as IIRC ( and Chas or the guys will remind me ) that WinAntiSpy is related to WinFixer Virtumonde aka Trojan Vundo Removal - some people also refer to this as WinFixer

    The follow the below guide.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. steveidahousa

    steveidahousa Private E-2

    Thank you Halo, I will get back to this as soon as I can (next I am up there)
    Amazing 6 hrs with Symantec and 2 attempts to remove has not gotten rid of this, does anyone know the purpose of this code?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton cannot fix this and never has been able to do so. In addition they do not even detect all the related files and problems that come with it. You should request a refund and send them an email stating that their tech support line is rather incompetent. They don't even know the correct way to remove this malware and this is supposed to be their specialty. As Halo stated, it is part of the Virtumonde family. You may have Virtumonde and winlogonhook. After you attach all the logs we will know, and we will also fix your PC the right way. Virtumonde can cause a variety of problems including popups and also can slow your PC down.
     
  5. steveidahousa

    steveidahousa Private E-2

    I am now at the computers home, I have attached the results of the vundo fix, although it looks like the scan that I just did has overwritten the results of the scan that Symantec did over the weekend. (Our recent scan found nothing.

    Am working on further Scans now.
     

    Attached Files:

  6. steveidahousa

    steveidahousa Private E-2

    Have run all other scans, as well as the Norton Anti Virus, Now it seems that the Software is gone, or maybe because I updated Norton Defs, they have told Norton to ignore?

    Anyway, it seems that the old proffessor is very happy with his system not being infected. Thank you for all of the help, I will be back with other Questions I suppose....Thank you all again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but the VundoFix log just indicated that you did not have a Virtumonde problem that it could find.
     
  8. steveidahousa

    steveidahousa Private E-2

    yes,Thanks, as I said, the Symantec analyst ran the Vundofix first, had I thought about it first, I would have posted his log, however attempting to follow the advice that was provided here, I ran Vundofix again. Which as far as I could tell wrote over his log with a new one when I ran it a second time. Shortly after posting that reply, we ran the Norton AV and found that the infection was no longer found, where it went I dont know, how it got removed between the last scan it was present and then I dont know either...

    But thanks to all for the assistance.

    Steve
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it does not overwrite. It appends to the file. Take a look at the log you post and you will see it has two different dates it was run.
     
  10. steveidahousa

    steveidahousa Private E-2

    He hehe he.......
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds