PDA

View Full Version : Application.Keystroke Spy


hidana
09-08-2008, 06:14 PM
Here's what I did:
1) Reformatted my PC using my Toshiba system recovery disk that came with my computer (cable unplugged)
2) Installed and turned on Zone Alarm
3) Plugged in cable
4) Downloaded all Windows updates
5) Installed and Ran Spyware Doctor, and Spyware Doctor reported an infections:

Application.Keystroke Spy
A legitimate application. Under certain circumstances, however, some people may find it undesirable.

File
c:\windows\unvise32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broadband\Remove Desktop Dialer.lnk

Startup Program
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\SharedDLLs, C:\Windows\unvise32.exe =1

Registry Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\SharedDLLs, C:\Windows\unvise32.exe

I am running on Vista Home.

Is it possible that the above is a false positive? I really don't expect to see any infection after spending 4 hours on a system reformat. I didn't see this problem in my previous reformat. Yes I've removed it using Spyware Doctor, but I have sensitive info on my PC so I just wanted to dig further to make sure that I am safe.

Many thanks for your help.

Ditto
09-09-2008, 12:06 AM
unvise32.exe does seem to be a malware according to my search on google. Have a go.

similar named program unwise32.exe is valid and legal program, but I believe unvise32.exe is not a windows program.

It's just my opinion, but I don't think this is FP.

hidana
09-09-2008, 01:05 AM
Thanks ditto.

Any suggestion on what I could've done to prevent getting a spyware during a system reformat? This malware wasn't there before.

And, once I've removed it using Spyware Doctor (and don't see it again in subsequent rescanning), can I be sure that I have removed it for good?

Thank you so much.

AChen
09-09-2008, 01:17 AM
Hi hidana,

Could you please zip up the file unvise32.exe and send this to me. I'll send you a private message with my email address. We will analyze this and will let you know as this is most likely not a false positive, but we want to make sure :)