Solved Virtool win32 Obfuscator.xz detected w/ MSE

Quadra, try right clicking on the CKscanner.exe and choose Run as Administrator .
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
@VistaKing Thanks, got it to work, just left mouse alone and let it do its thing. Posted results in my previous post via an edit.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
The programs that Cottonball has you use you would need to right click on them and choose Run as administrator. That is only needed in Windows 7 and Vista . Windows XP doesn't require that .
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Quadra,

ESET is normally effective at finding cracks, serials and keygens on a system, and your report presents a quandary.

I am not into gaming, but, there is a CheatEngine showing there, and numerous entries identifying a Win32/GameHack application in C:\Users\Squall\Downloads\

You mention:
These are modifications for the games I own.
What kind of modification? Are these "modifications" legal?

Any unauthorized user of copyrighted or patented material is considered engaging in software piracy.

The next step is to run ESET once again, and check the option: Remove found threats

I need to talk to someone her that has first hand knowledge of the policies of this forum.
In forums where I also work, assisting anyone suspected of having obtained their software illegally is not allowed.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
@ Cottonball I will run ESET as instructed.

In regards to Cheatengine and the modifications they are legal. I use them to modify certain values in my games. For example I may be playing a game where I want my character to be invincible or wear certain armor or use a certain weapon. I'll use cheatengine (in the case of invincibility) to find the address for my characters health and change that value to the point where my character cannot die.

Here's a simple description of CheatEngine and its uses. Cheat Engine - Wikipedia, the free encyclopedia
Here's a description of the modifications. Trainer (games) - Wikipedia, the free encyclopedia
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
Results of second ESET using threat removal.

C:\Users\All Users\Codecv\bhoclass.dll a variant of Win32/Adware.MultiPlug.B application
C:\ProgramData\Codecv\bhoclass.dll a variant of Win32/Adware.MultiPlug.B application cleaned by deleting - quarantined
C:\Users\Squall\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BRHE5WVN\4f79ed8629923[1].exe multiple threats cleaned by deleting - quarantined
C:\Users\Squall\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BRHE5WVN\optimizerpro[1].exe a variant of Win32/Adware.SpeedingUpMyPC.A application cleaned by deleting - quarantined
C:\Users\Squall\AppData\Local\Temp\Addons\{A4951A8C-DEB0-54C5-B62E-96927F76387A}\codecc_extension.exe multiple threats cleaned by deleting - quarantined
C:\Users\Squall\AppData\Local\Temp\Addons\{A4951A8C-DEB0-54C5-B62E-96927F76387A}\OptimizerPro.exe a variant of Win32/Adware.SpeedingUpMyPC.A application cleaned by deleting - quarantined
E:\Users\Administrator\Desktop\mplayer_Setup.exe a variant of Win32/Adware.iBryte.D application cleaned by deleting - quarantined
E:\Users\Administrator\Desktop\Port\GOT+8Tr-LNG.exe a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined
E:\Users\Administrator\Downloads\GOT-1100+8Tr-LNG.rar a variant of Win32/Packed.VMProtect.AAH trojan deleted - quarantined
E:\Users\Administrator\Downloads\GOT-1300+8Tr-LNG(1).rar a variant of Win32/Packed.VMProtect.AAH trojan deleted - quarantined
E:\Users\Administrator\Downloads\GOT-1300+8Tr-LNG.rar a variant of Win32/Packed.VMProtect.AAH trojan deleted - quarantined
E:\Users\Administrator\Downloads\GOT_8Tr-LNG.rar a variant of Win32/Packed.VMProtect.AAH trojan deleted - quarantined
E:\Users\Administrator\ps3tools\ps3tools\tools\PKG_ContentID.exe probably unknown NewHeur_PE virus deleted - quarantined
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
Please download Farbar Service Scannerand run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hello Jacee,

As requested Farbar log:

Farbar Service Scanner Version: 03-03-2013
Ran by Administrator (administrator) on 23-03-2013 at 14:28:11
Running from "E:\Users\Administrator\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
E:\Windows\System32\nsisvc.dll => MD5 is legit
E:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
E:\Windows\System32\dhcpcore.dll => MD5 is legit
E:\Windows\System32\drivers\afd.sys => MD5 is legit
E:\Windows\System32\drivers\tdx.sys => MD5 is legit
E:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
E:\Windows\System32\dnsrslvr.dll => MD5 is legit
E:\Windows\System32\mpssvc.dll => MD5 is legit
E:\Windows\System32\bfe.dll => MD5 is legit
E:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
E:\Windows\System32\SDRSVC.dll => MD5 is legit
E:\Windows\System32\vssvc.exe => MD5 is legit
E:\Windows\System32\wscsvc.dll => MD5 is legit
E:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
E:\Windows\System32\wuaueng.dll => MD5 is legit
E:\Windows\System32\qmgr.dll => MD5 is legit
E:\Windows\System32\es.dll => MD5 is legit
E:\Windows\System32\cryptsvc.dll => MD5 is legit
E:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
E:\Windows\System32\svchost.exe => MD5 is legit
E:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
all i guess is it must be false positive if it is really reloaded upload because MSE detects every crack also as virus while they do not harm or act like any trojan which sends your private infos to someone else that is why i removed MSE from my PC
 

My Computer My Computer

At a glance

Windows 7 Ultimate2.60 ghz8 gb1 gb
Computer type
Laptop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Ultimate
CPU
2.60 ghz
Memory
8 gb
Graphics Card(s)
1 gb
Screen Resolution
1366x768
Hard Drives
320gb
Internet Speed
20 mbit
Antivirus
comodo firewall+comodo antivirus free edition
Browser
Google Chrome
Quadra,

Back to:
E:\Users\Administrator\Desktop\FNIS\fa\NBA.2k13-RELOADED.ISO
E:\Program Files (x86)\2k Sports\NBA 2k13\rld.dll

Let's do some searching...

Please download SystemLook.

64-bit:
http://jpshortstuff.247fixes.com/SystemLook_x64.exe
Save to your Desktop.

Right-click on SystemLook.exe, and select: Run As Administrator

Copy the content inside the following quote box into the main textfield:

:filefind
E:\Users\Administrator\Desktop\FNIS\fa\NBA.2k13-RELOADED.ISO
E:\Program Files (x86)\2k Sports\NBA 2k13\rld.dll

lick the Look button to start the scan.

When finished, a notepad window opens with the results.

Please post the SystemLook.txt (found on the Desktop) in your reply
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Hello Cottonball,

As you requested.
 

Attachments

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
The log is a bunch of numbers and boxes
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Dont know why it appears that way. Here's whats in the log though.

SystemLook 30.07.11 by jpshortstuff
Log created at 19:47 on 23/03/2013 by Administrator
Administrator - Elevation successful

========== filefind ==========

Searching for "E:\Users\Administrator\Desktop\FNIS\fa\NBA.2k13-RELOADED.ISO"
No files found.

Searching for "E:\Program Files (x86)\2k Sports\NBA 2k13\rld.dll"
No files found.

-= EOF =-
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
It's not locating those files .
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Is that good or bad? Assuming good since MSE associated those w/ the virus.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
You did manually delete the iso. That is why the ISO didn't show up .

How does the log look with ESET scan
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
About to run ESET.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
ESET scan finished and found 0 infected files.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
:thumbsup:
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Cool. So I am in the clear? If so, should I mark the thread as solved?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 Bit SP1Intel Core i7NVIDIA GTX 560 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Home Premium 64 Bit SP1
CPU
Intel Core i7
Graphics Card(s)
NVIDIA GTX 560 Ti
Antivirus
Microsoft Security Essentials
Browser
Firefox
Back
Top