Remove Obfuscator.xz Virus Tool

italicus3000

New member
Local time
9:20 AM
Messages
5
Location
Italy
Hi to all,

I scanned with MSE and it found virtool.win32/obfuscator.XZ but when I tried to clean the system it fails.

So after a research in the forum I found that some users recomend to follow that guide:

How to Remove VirTool:Win32/obfuscator.XZ Completely and Effectively (Step-by-step Removal) - Tee Support Blog

So I decided to follow the manual removal, but I'm not really sure of what I'm doing, so I would really appreciate some help :D .....

ok so....Now I'm finding the registry entries that I have to remove, like the manual said, but I find some registry entries with different values. Let me to take an example:

I have found

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS " CERTIFICATEREVOCATION" = '1'

instead of

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS " CERTIFICATEREVOCATION" = '0'

Do I have to remove that key anyway???


Edit

While I was waiting for some responses, I have scanned my pc ( in safe mode) using Microsoft Safety Scanner, ESET online, Hitman Pro and Malwarebytes but Now nothing has been detected:
Does this mean that I'm safe again???
 
Last edited:

My Computer My Computer

OS
Windows 7 Ultimate 64 Bit
CPU
i5 750 2.66 Ghz
Motherboard
P7P55D
Memory
2 x 4 Gb Kingston Hyperx
Graphics Card(s)
GeForce 8800 GT
Hi to all,

I scanned with MSE and it found virtool.win32/obfuscator.XZ but when I tried to clean the system it fails.

So after a research in the forum I found that some users recomend to follow that guide:

How to Remove VirTool:Win32/obfuscator.XZ Completely and Effectively (Step-by-step Removal) - Tee Support Blog

So I decided to follow the manual removal, but I'm not really sure of what I'm doing, so I would really appreciate some help :D .....

ok so....Now I'm finding the registry entries that I have to remove, like the manual said, but I find some registry entries with different values. Let me to take an example:

I have found

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS " CERTIFICATEREVOCATION" = '1'

instead of

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS " CERTIFICATEREVOCATION" = '0'

Do I have to remove that key anyway???


Edit

While I was waiting for some responses, I have scanned my pc ( in safe mode) using Microsoft Safety Scanner, ESET online, Hitman Pro and Malwarebytes but Now nothing has been detected:
Does this mean that I'm safe again???
I'd remove it because on my computer, the keys don't exist.
 

My Computer My Computer

Computer Manufacturer/Model Number
Acer Aspire 5517
OS
Windows 7 Ultimate x64
CPU
AMD athlon x64 dual core 1.6 Ghz
Memory
4GB
Graphics Card(s)
ATI Radeon HD 3200 Graphics 1915 MB memory
Monitor(s) Displays
15.6" widescreen
Screen Resolution
1366x768
Hard Drives
320GB
Internet Speed
10mbps
I'd remove it because on my computer, the keys don't exist.

Yes it does :) They're not keys by the way, they're values.

Code:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Windows\System32>reg query "HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURR
ENTVERSION\INTERNET SETTINGS"

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS
    IE5_UA_Backup_Flag    REG_SZ    5.0
    User Agent    REG_SZ    Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    EmailName    REG_SZ    User@
    PrivDiscUiShown    REG_DWORD    0x1
    EnableHttp1_1    REG_DWORD    0x1
    WarnOnIntranet    REG_DWORD    0x1
    MimeExclusionListForCache    REG_SZ    multipart/mixed multipart/x-mixed-rep
lace multipart/x-byteranges
    AutoConfigProxy    REG_SZ    wininet.dll
    UseSchannelDirectly    REG_BINARY    01000000
    WarnOnPost    REG_BINARY    01000000
    UrlEncoding    REG_DWORD    0x0
    SecureProtocols    REG_DWORD    0xa0
    PrivacyAdvanced    REG_DWORD    0x0
    ZonesSecurityUpgrade    REG_BINARY    CB69B4C6195DCD01
    DisableCachingOfSSLPages    REG_DWORD    0x0
    WarnonZoneCrossing    REG_DWORD    0x0
    [COLOR=Red][B]CertificateRevocation    REG_DWORD    0x1[/B][/COLOR]
    EnableNegotiate    REG_DWORD    0x1
    MigrateProxy    REG_DWORD    0x1
    ProxyEnable    REG_DWORD    0x0
    ProxyOverride    REG_SZ    *.local
    GlobalUserOffline    REG_DWORD    0x0

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\5.
0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\CA
CHE
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Co
nnections
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Ht
tp Filters
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Lo
ckdown_Zones
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\P3
P
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Pa
ssport
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Pr
otocols
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Te
mplatePolicies
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Wp
ad
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Zo
neMap
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\Zo
nes

C:\Windows\System32>
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Back
Top