Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

FixWareout download link doesn't work, could someone upload it again?


  • Please log in to reply
11 replies to this topic

#1 SuperSZ

SuperSZ

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 31 October 2008 - 10:42 AM

First of all, I've gotta say that I am new at this forum, so sorry if I posted this thread in a wrong location. Well now:
I wanted to play Counter Strike 1.6 with SXE (anti-cheat software required) and the SXE clossed and the notepad displayed this error:

ERROR: [(Dirty). (sXe Injected subsystem altered 2[74])]


I searched in internet, and said that I needed FixWareout to fix that problem. I found 2 download links:

http://downloads.subratam.org/Fixwareout.exe

http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

But both of them, when I try to download the software it says 404 ERROR: Page Not Found! So, I would really appreciate if someone could upload that software so I can I downnload it


Thanks :thumbsup:

BC AdBot (Login to Remove)

 


#2 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:36 PM

Posted 01 November 2008 - 09:24 AM

Anti-Malware programs need to be a constant state of change to keep one step ahead of the malware writers. I believe this wasn't the case anymore with Fixwareout. Try Malwarebytes and post the log in the Am I Infected? forum
-----------------------------------

Malwarebytes Anti-Malware and save it to your desktop.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.

Edited by garmanma, 01 November 2008 - 09:26 AM.

Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#3 SuperSZ

SuperSZ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 01 November 2008 - 12:32 PM

Anti-Malware programs need to be a constant state of change to keep one step ahead of the malware writers. I believe this wasn't the case anymore with Fixwareout. Try Malwarebytes and post the log in the Am I Infected? forum
-----------------------------------

Malwarebytes Anti-Malware and save it to your desktop.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.


Is Malwarebytes freeware?

#4 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:36 PM

Posted 01 November 2008 - 12:52 PM

Yes it is. Just click on my link and it should download to your desktop or prompt you where to download
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#5 SuperSZ

SuperSZ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 01 November 2008 - 01:05 PM

Yes it is. Just click on my link and it should download to your desktop or prompt you where to download



oh thanks :thumbsup: !!!. I am scaning right now, if I can play Counter Strike again (and not get the SXE error message anymore) I would be sooo happy :flowers:

#6 SuperSZ

SuperSZ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 01 November 2008 - 01:17 PM

OMG!!!!!! IT WORKED, I CAN PLAY COUNTER STRIKE AGAIN, AND NOT ONLY THAT, MY PC IS FASTER!!!!!!!! YOU RULE SO MUCH :thumbsup: :flowers: :trumpet: :inlove: :huh:

#7 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:36 PM

Posted 01 November 2008 - 01:59 PM

That's all well and good but post the log and let's make sure nothing's lurking in the backround
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#8 SuperSZ

SuperSZ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 01 November 2008 - 03:08 PM

That's all well and good but post the log and let's make sure nothing's lurking in the backround


this is the log

Malwarebytes' Anti-Malware 1.30
Versión de la Base de Datos: 1352
Windows 5.1.2600 Service Pack 3

01/11/2008 04:07:34 p.m.
mbam-log-2008-11-01 (16-07-34).txt

Tipo de examen : Examen Rápido
Objetos examinados: 54358
Tiempo transcurrido: 3 minute(s), 45 second(s)

Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 1
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 20
Carpetas Infectadas: 1
Ficheros Infectados: 3

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
HKEY_CLASSES_ROOT\sexvid (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdhhe.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9f2d7278-3491-487b-88ae-a945819fe8fb}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a874c00c-7a88-4d2b-8605-127b0aa0141f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.60;85.255.112.237 -> Quarantined and deleted successfully.

Carpetas Infectadas:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Ficheros Infectados:
C:\WINDOWS\system32\kdhhe.exe (Rootkit.DNSChanger.H) -> Delete on reboot.
C:\WINDOWS\Domino.EXE (Worm.Anilogo) -> Quarantined and deleted successfully.
C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.


#9 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:36 PM

Posted 01 November 2008 - 03:26 PM

Reboot your computer and run it again please
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#10 SuperSZ

SuperSZ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 01 November 2008 - 03:47 PM

Reboot your computer and run it again please


I've just done it. This is the new log:

Malwarebytes' Anti-Malware 1.30
Versión de la Base de Datos: 1352
Windows 5.1.2600 Service Pack 3

01/11/2008 06:39:04 p.m.
mbam-log-2008-11-01 (18-39-04).txt

Tipo de examen : Examen Rápido
Objetos examinados: 54153
Tiempo transcurrido: 4 minute(s), 44 second(s)

Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 0
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 4
Carpetas Infectadas: 0
Ficheros Infectados: 0

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
(No se han detectado elementos maliciosos)

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{660cced7-3153-42f5-bda1-53517a53cde6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.145 192.168.1.254 -> Quarantined and deleted successfully.

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Ficheros Infectados:
(No se han detectado elementos maliciosos)


And I've noticed that I've got some things in quarantine:

Posted Image

is it serious?

Edited by SuperSZ, 01 November 2008 - 03:51 PM.


#11 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:03:36 PM

Posted 01 November 2008 - 06:54 PM

I would do a follow-up with a Hijack this log. Read the preparation guide:
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
Then post your log with a brief description in the Hijack This Forum:
http://www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#12 Alzie

Alzie

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:36 PM

Posted 04 May 2009 - 01:18 PM

Malwarebytes' Anti-Malware 1.36
Databasversion: 2074
Windows 5.1.2600 Service Pack 3

2009-05-04 20:08:47
mbam-log-2009-05-04 (20-08-47).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 71683
Förfluten tid: 2 minute(s), 4 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 1

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\Documents and Settings\Administratör\Lokala inställningar\Temp\is-FB8TD.tmp\is-55FPU.tmp (Rogue.Installer) -> Quarantined and deleted successfully.


Please answer asap, my Internet is going crazy, and if this helps I got alot of svchost.exe running, no idea why.
Thanks!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users