Ultraview plus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by buslick, Mar 15, 2006.

  1. buslick

    buslick Private E-2

    I ran Webroot Spysweeper on my system like I always do. I added a rootkit scan which I had never done before. It found something called ultraview plus. I did a search here and on Google and could not find out much about this program except that it is a keylogger. I have it quarantined at the moment. I was wondering if I really had it and if so how it may have got on my machine? Could I run the program to see what it has been recording? Would that tell me who installed it on my machine? What is the best way to get rid of it? I am presently running some of my other spyware programs to see what they may find. Thanks for any help. Let me know if you want me to post any HJT logs.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who is the owner of this PC?
     
  3. buslick

    buslick Private E-2

    I am the owner. My wife uses it to check her email. Sometimes I forget to log out so if I am still logged in when she gets on she or anyone else could have admin rights to install something. When she is logged in under her own account she does not have admin rights. She is not very computer savvy.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. buslick

    buslick Private E-2

    No I have always owned this computer. I asked my wife if she installed anything to spy on my web browsing and she said no. Not sure if I really have it or if it is a false alarm. I had already found those same threads on my own. They don't really say how to get rid of it.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    True commercial keyloggers like that normally require that the person (usually the administrator) uninstall them. That's because they are normally totally hidden so only the person knowing it was installed and having the passwords too it can uninstall it.

    Try running the steps and let's see what we find:

    Let's first get an installed programs list from HijackThis

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.


    Now download Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the log file here.
     
  7. buslick

    buslick Private E-2

    false alarm

    Looks like I had a false positive scan. Everything came up clean on Spycop and Blacklight Beta after I unquarantined the two false postivie registry listings found by SpySweeper. Of note it seems SpySweeper has also been updated so that it no longer flags these two false postive registry lines. I had none of the files or registry changes listed at the Symantec site. See these threads for more info:

    http://castlecops.com/t149165-System_Monitor_ultrview_plus.html

    http://www.dslreports.com/forum/remark,15618681

    Thanks for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: false alarm

    So are you now saying you have no malware problems to e concerned with?

    If so, that's great!
     
  9. buslick

    buslick Private E-2

    No Malware at this time. I follow all the instructions on this site to keep myself protected as much as I can. The only time I ever get into trouble is when my wife goes to a site or opens an email that causes a problem. I try to encourage her to use an old computer I gave to the kids so that she doesn't mess up my computer. I love the site. Thanks for the help now and in the past.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds