Windows 7 Forums


Windows 7: Virtool win32 Obfuscator.xz detected w/ MSE

21 Mar 2013  
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
4,207 posts
 
 

Quadra,

Have you run the ESET scanner ? If so upload the log file please.

ADDED:



I saw that you uninstalled Daemon Tools and Power ISO . You might also want to run this little tool below .

SCSI Pass Through Direct (SPTD), which is a well known BSOD causer. Uninstall the program at first(which you did already) . Then download SPTD standalone installer and execute the downloaded file as guided below :
download For 32-bit OS

download For 64-bit OS

Double click to open it.

Click this button only: (look at image below )


Note   Note
If it is grayed out, as in the picture, there is no more SPTD in your system, and you just close the window.

Last edited by VistaKing; 21 Mar 2013 at 03:18 PM..
My System SpecsSystem Spec

21 Mar 2013  
Quadra

Windows 7 Home Premium 64 Bit SP1
19 posts
 
 

@VistaKing ESET is still running it's at about 450k files scanned right now, seems to be scanning my C: too.

@LaybackBear Yes.
My System SpecsSystem Spec
21 Mar 2013  
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
4,207 posts
 
 

It scans the entire drive .

After the scan has completed do the steps I added HERE it will help you in the long run .
My System SpecsSystem Spec
.


21 Mar 2013  
Quadra

Windows 7 Home Premium 64 Bit SP1
19 posts
 
 

Just a follow-up. ESET is still running and I'm about to turn in for the night. So I'm gonna let it run overnight and last I checked it found 300 items, so yeah.... If I have time before work I'll post that list from ESET. If not it'll be later in the day tomorrow. Thanks again for all your assistance everyone.
My System SpecsSystem Spec
21 Mar 2013  
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
4,207 posts
 
 

Take your time we are here to help
My System SpecsSystem Spec
21 Mar 2013  
cottonball

Windows 7 Home Premium
1,216 posts
On East 4th Street, USA
 
 

Quadra,

Whenever you are ready, just attach the results.

Just make sure that the option Remove found threats is not checked. We need to make sure there are no crucial system files removed!

Sometimes scans take a Windows file in their sweep, and then there is a problem bigger than what you had before.

Will take a look at the results whe you provide them, and we'll go from there.
My System SpecsSystem Spec
22 Mar 2013  
Quadra

Windows 7 Home Premium 64 Bit SP1
19 posts
 
 

Hello again,

ESET finished up. Looked over the log and just wanted to point out there are a bunch of false-positive hits that look like this: E:\Users\Administrator\Desktop\tesv-Squall17.exe a variant of Win32/GameHack.BE application

These are modifications for the games I own. Other than that I don't really recognize the rest of this stuff.

@VistaKing About to start SPTD

Thanks again.


Edit: SPTD came back greyed out as you have depicted VistaKing.
Attached Files
File Type: txt ESETScan.txt (43.5 KB, 17 views)

Last edited by Quadra; 22 Mar 2013 at 01:04 PM.. Reason: Info Update
My System SpecsSystem Spec
22 Mar 2013  
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
4,207 posts
 
 

Good the SPTD tool didn't find any left over files when you uninstalled daemon tools .
My System SpecsSystem Spec
22 Mar 2013  
cottonball

Windows 7 Home Premium
1,216 posts
On East 4th Street, USA
 
 

Quadra,

Please download CKScanner:
http://downloads.malwareremoval.com/CKScanner.exe

Important: - Save it to your Desktop

Double-click CKScanner.exe, then, click: Search For Files
When a list appears, click: Save List To File
A message box verifies the file saved.

Double-click the CKFiles.txt on your Desktop, and copy/paste the contents in your reply.

Thanks.
My System SpecsSystem Spec
22 Mar 2013  
Quadra

Windows 7 Home Premium 64 Bit SP1
19 posts
 
 

@Cottonball Everytime I try to run CKScanner it does not respond. My mouse pointer turns into that aquamarine ring when a program doesn't respond. When I click on the CKScanner window it says "not responding." Is this one of those scans where I shouldn't touch the keyboard or mouse?

Edit: Managed to get it to work.

CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
c:\program files (x86)\dragon age 2\addins\da2_prc_eye\module\audio\vo\de-de\facialanimations\fxe_eye400_cave_crack.crf
c:\program files (x86)\dragon age 2\addins\da2_prc_eye\module\audio\vo\en-us\facialanimations\fxe_eye400_cave_crack.crf
c:\program files (x86)\dragon age 2\addins\da2_prc_eye\module\audio\vo\fr-fr\facialanimations\fxe_eye400_cave_crack.crf
c:\program files (x86)\dragon age 2\addins\da2_prc_eye\module\data\cln_eye400_cave_crack.crf
c:\program files (x86)\steam\steamapps\chaoz14\counter-strike source\cstrike\materials\sprites\store\crackedbeam.vmt
c:\program files (x86)\steam\steamapps\chaoz14\counter-strike source\cstrike\materials\sprites\store\crackedbeam.vtf
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\.rsync\.pack\addons\acex_sm_c_sound_wep_crack.pbo.acex_sm.bisign.gz
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\.rsync\.pack\addons\acex_sm_c_sound_wep_crack.pbo.gz
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\.rsync\.pack\addons\acex_sm_s_wep_crack.pbo.acex_sm.bisign.gz
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\.rsync\.pack\addons\acex_sm_s_wep_crack.pbo.gz
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\addons\acex_sm_c_sound_wep_crack.pbo
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\addons\acex_sm_c_sound_wep_crack.pbo.acex_sm.bisign
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\addons\acex_sm_s_wep_crack.pbo
c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\@acex_sm\addons\acex_sm_s_wep_crack.pbo.acex_sm.bisign
c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\sounds\fire_small_crackle_slick_op.ogg
scanner sequence 3.DK.11.AEAPTI
----- EOF -----
My System SpecsSystem Spec
Reply

 Virtool win32 Obfuscator.xz detected w/ MSE problems?



Thread Tools



Similar help and support threads for: Virtool win32 Obfuscator.xz detected w/ MSE
Thread Forum
Unable to get rid of virtool.win32/obfuscator.XZ System Security
Solved MSE found virtool.win32/obfuscator.XZ but couldn't get rid of it. System Security
Infected by virtool.win32/obfuscator.XZ System Security
Infected by virtool.win32/obfuscator.XZ on Windows 7 System Security
Kaspersky: Trojan.Win32.AutoRun.atq. Has it been detected on MSE yet? System Security


All times are GMT -5. The time now is 10:25 PM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd