Help I was a Bad boy !!!

Discussion in 'Software' started by ghott, Feb 19, 2009.

  1. ghott

    ghott Private E-2

    Ok I have a store bought copy of 4x4 Evolution by Terminal reality. I was a bad boy and DL'd 4x4 Evolution 2 from a torrent and installed it also. Ever since then....BOTH the 4x4.exe and 4x42.exe files have shown this.....
    probably unknown NewHeur_PE Only ESET NOD32 shows this...however, since my bad boyness....and total removal of both programs......Every time I try to reinstall the store bought 4x4 Evolution......the 4x4.exe file still shows.....probably unknown NewHeur_PE

    I have used the Western digital Diagnostics Disk to totally wipe my primary HD (over write with zeros) and reinstalled Windows from scratch. Still the same problem occurs every time I try to install 4x4 Evolution, which leads me to believe that...either my BIOS or the firmware of my CD/DVD's (both) or the firmware of my HD's has been infected with: probably unknown NewHeur_PE

    No other scanner shows this infection, however, since it 1st occured 4x4 Evolution (the store bought copy) continues to try to connect to the internet. I can block it with Zonealarm....but I'd still like to find the infection and remove it.

    Scanners I run:
    Symantec Corporate AV 10.1.0.6000
    Malwarebytes
    Spybot S&D
    SuperAntiSpyware
    Resplendence Roothook Analyzer
    AVG Root Hook scanner
    ...and NO online scan (except NOD32) shows any problems, and I have no problems with any other programs. I also have ALL Windows Default $hares disabled in the registry...including the $IPC share. I have also upgraded the firmware on the CD/DVD burners.

    My System:

    Operating System: Windows XP Pro 5.1.2600 w/SP2
    Motherboard: ASUS M2N32 SLI Deluxe, Wireless Edition (1603 BIOS)
    Processor: AMD Athlon 64 X2 5000+ (B.E.) Brisbane 2.6GHz Dual-Core (Overclocked to 3.2Ghz)
    CPU Fan/Heatsink: ZALMAN CNPS9500A 2 Ball CPU Cooling Fan/Heatsink
    Memory: CORSAIR Dominator 2GB (2 x 1GB) 240-Pin DDR2 1066 (PC2 8500) Dual Channel
    Video Card: EVGA 01G-P3-1280-AR GeForce GTX 280 1GB 512-bit GDDR3 PCI Express 2.0 (stock)
    Hard Drive #1: WD 36GB 10,000rpm Raptor SATA I
    Hard Drive #2: Seagate ST3250410AS 250GB 7200rpm SATA II
    Optical Drive # 1: LG HL-DT-ST DVD-RAM GH22LS30 CD/DVD Burner SATA
    Optical Drive # 2: Lite-On LH-18A1P CD/DVD Burner IDE
    Power Supply: PC Power & Cooling Silencer 750 Quad (Black) EPS12V
    Case: Mid Tower (Gerneric) 5x 80mm case fans (2 front intake, 2 rear exhaust, 1 side exhaust)
    Sound Card: none
    Monitor: ViewSonic G90FB Black 19" CRT Monitor

    Idle temps: CPU: 26C Motherboard: 26C GPU: 35C (fan @ 100%)

    Load Temps: CPU: 48C Motherboard: 27C GPU: 52C (fan @ 100%)

    Drivers: nVidia 9.35 Chipset.....nVidia 177.41 Video


    Any help with this would be sorely appreciated...HJT logs show clean also.

    As I have neither 4x4 Evo or 4x4 Evo 2 installed, here I believe is where the problem stems from.....removing these entries does nothing, as soon as I reboot they re-appear.

    http://img102.imageshack.us/img102/7431/image1vb1.jpg

    I would really like to be able to install the store bought 4x4 Evolution Game without it instantly being reinfected. Also, scanning the store bought CD itself with NOD32 shows it to be clean.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, ghott.

    It very well may be a False Positive --- see the below link:

    http://www.eset.com/threat-center/encyclopedia/glossary/newheurpe

    What online scanners have you run?

    If you wish us to check your machine, please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes, you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is advised that after completing the READ & RUN ME you also read this sticky:
    4. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.

    dr.m
     
  3. ghott

    ghott Private E-2

    Already did all that bro...and thx for the timely response :) I've been workin on comps for almost 30 years....thing that's messin me up is that before the "bad boy" incident .......4x4 Evolution never tried to connect to the internet, however I was on a different mother board...ASUS A7N8X and I didn't have 20/20 FIOS which is always on :/ Anyways, I've run EVERY online scanner, I've used CCleaner for at least 2 years, I also use Glary Utilities and JV16 Powertools. Also Malwarebytes, SuperAntiSpyware, Spybot S&D, Zonealarm (free), Symantec Corporate 10.1.6000 AV and HiJackThis. Thats just what I use....I also have on other HD: Windows defender, Avast, ESET NOD32, Avira, ATF, Combofix, CWS, FixVundo, and FixDownadup. ONLY ESET sees 4x4.exe as a NEWHeur....

    I just updated to Java6_12...I've had it on 2nd HD for a while...just don't like it that much. I ONLY use IE6 for MS Tuesday or when a news site says MS has just released a Critical Thursday patch etc. My services are trimmed to the bone and ZA is locked down as much as possible. I don't Youtube, facebook, IM, WMP online, etc. Not Silver light, no FTP clients, no net framework. Only thing I do is surf with FF and play D2. Even with firefox I run NOscript and Adblock Plus.

    My machine is squeaky clean and tight as a Virgin..ian :) I just can't figure out why 4x4 Evolution was flagged by ESET and tries to connect to the internet...it not supposed to ! No other scanner flags it....but since new motherboard and FIOS 20/20 it just seems to want to go out and play :/

    Here's my ZA settings:

    http://img172.imageshack.us/img172/5135/image1sw2.jpg
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you do not want to post any logs from the READ & RUN ME and this does not appear to be a malware problem, the thread is being moved to the Software Forum where others may be able to comment on the game software. Also you may wish to address the issue with ESET.
     
  5. Just Playin

    Just Playin MajorGeek

    You may also wish to contact Terminal Reality. They may have some insight, especially if it is a false positive.
     
  6. ghott

    ghott Private E-2

    ok heres all your logs as requested:

    order run, as detailed:
    CCleaner
    SAS
    Spybot
    MBAM
    COMBO
    MGtool

    logs are all attached in one .rar file

    Yes I know Java6_7 should be updated to Java6_12 and I did it yesterday and Diablo II and myself don't like it at ALL....so I went back to Java6_7...until at least Sun Java gets their act together and makes an update that works properly and isn't as bloated as the latest Nero's :)

    My normal ping with update 7 is 15ms on D2....with update 12 its over 100ms which is ridiculous and unplayable.
     

    Attached Files:

  7. ghott

    ghott Private E-2

    and here's the SAS log...seems not to like my big .rar file :)
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds