HELP! UAB optiva Boss Eye found. What the heck is it?!

Okay i am extremely scared. When i started my daily scan with f-secure, and looked at the scanning status, like which files it was checking. It came upon C:\Program File\UAB optiva\Boss Eye
I did a lil bit of check and found two sites that say it is an keylogger and that it takes screenshots of my computer. THE SCARIEST PART was that none of my antivirus tools spotted it. Not Norton Free security scan (although it found 2 infostealer.gambas), not F-secure, Not AVG, not anything i had on my pc. They found the files, cheked them and found nothing, allthough it is clearly there! I need help now guys. I need to get this thing out of my PC.

Keyloggers are always though things as many software don’t detect them. SAS doesn’t even try to, and I don’t think MBAM will also, so we have to try something else…

Anyway, if I remember right,
ad-aware should be able to take care of this one. Download, install update and scan and reboot

Then post back a hijackthislog so we can see if it worked


Ad-aware found nothing :confused: Double checked with every single scanner. All scanned the exact file where it is but came up with nothing. Now what? Posting my Hijackthis file also. Look below for it.

Logfile of HijackThis v1.99.1
Scan saved at 15:51:27, on 9.10.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
Scanned again with AVG, Ad-Avare, Norton Free Scan, F-secure, and eXterminate it!-programs. Nothing. But still thinking it is in my computer. Somebody, help please?

Well except that you’re running a lot of antivirus/antispyware programs I couldn’t find anything in the hijackthis log… Have you tried malwarebytes antimalware, Superantispyware or Spybot search and destroy ? I know I said they probably wouldn’t catch it but you never know …

How do you know it’s still on your computer ?


Here are some tools that might help you.

a-squared Anti-Malware 4.0 trial (30 days testing)
You can try a-squared free but free version dont haw new engine.

ESET Online Antivirus

BitDefender Online Scanner

Spyware Terminator

i remembered that Spyware Doctor 6 is very good you can try this too



Any help i can get is apreciated. Thank you so much people. (L)

As long as you give us feadback :wink:

Have you tried the free malware removal done by comodo experts ? they might be able to help you …

(Internet explorer sujested)


CA seems to be aware of it:

I never tried their programs - i can’t recommend based on assumptions - but their AS could be able to remove it.

Perhaps VIPRE can detect it.

You can also try Dr.Web CureIt. It’s free.

Right now doing the ESET Online scan, and isntalling a-squared and BitDefender trial edition. Keep those programs comming (as long as they don’t take too much space :P)

And now we get to the things i can’t find. First of all, it should have done this to my registry:


When i open my regedit, and search for this, there is absolutely no sign of it I also can’t find these files from anywhere:

%program_files%\uab optiva\boss eye demo\player.exe
%program_files%\uab optiva\boss eye demo\player.mld
%program_files%\uab optiva\boss eye demo\res\beeng.bin
%program_files%\uab optiva\boss eye demo\res\logo.bin
%program_files%\uab optiva\boss eye demo\res\logoeng.bin
%program_files%\uab optiva\boss eye demo\res\player.ini
%program_files%\uab optiva\boss eye demo\res\sa.bin
%program_files%\uab optiva\boss eye demo\sdk.dat
%program_files%\uab optiva\boss eye demo\server.exe
%program_files%\uab optiva\boss eye demo\shootsrv.mld
%program_files%\uab optiva\boss eye demo\help\akis.chm
%program_files%\uab optiva\boss eye demo\help\eye.chm
%program_files%\uab optiva\boss eye demo\install.log
%program_files%\uab optiva\boss eye demo\uninstall.exe
%programs%\boss eye demo\boss eye demo.lnk
%programs%\boss eye demo\boss eye server.lnk
%programs%\boss eye demo\help.lnk
%program_files%\uab optiva\boss eye demo\player.exe
%program_files%\uab optiva\boss eye demo\uninstall.exe
%program_files%\uab optiva\boss eye demo\server.exe

BUT, still my Norton Free scan scanned the file C:\Program Files\UAB Optiva\Boss Eye fews ago. Weird huh?

A free little fellow WinPatrol, from , shall both detect and remove this malware.