at wit's end. Does ANYONE know anything about cookingluck?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by paulbeagle, Feb 25, 2008.

  1. paulbeagle

    paulbeagle Private E-2

    So I've posted on 4 forums and no one can help. Here is my DSS Scan Log which contains the HiJackThis log and the DSS Extra Report. Can't ANYONE help please?

    Deckard's System Scanner v20071014.68
    Run by Paul McVicker on 2008-02-24 17:30:53
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------
     
    Last edited by a moderator: Feb 25, 2008
  2. Lev

    Lev MajorGeek

  3. paulbeagle

    paulbeagle Private E-2

    Well, I tried to follow all instructions. The MGTools did not do a separate zip file, so I attached the logs separately. So far, no improvement. The Browser opens by itself, or windows open in the browser automatically. Usually, not always, the first window opened is s3.cookingluck.com/?pid=6082&v=16 Subsequent windows are similar or not. So far I've spent 6 hours and $75. following your instructions. The remaining logs are attached to a separate entry. thanks.
     

    Attached Files:

  4. paulbeagle

    paulbeagle Private E-2

    Here are the remaining logs. I really appreciate your expertise and assistance. I do hope you can help!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes it did. It is right where the READ & RUN ME told you it would be. Check again. ;) But you also did not allow the program to properly finish running. I can see this from the newfile.txt log which reveals the scan was terminated before finishing. Thus your logs are incomplete. Also note that you did not follow the instructions on downloading MGtools.exe to your C:\ folder. You ran it directly from the website download link (i.e., you Opened it rather than Saved it).

    How did you spend $75 dollars following our instructions? Everything we have you run is free.

    What are the below items that you put in your C:\Program Files folder? They should not be here in this folder.
    Code:
     
     
    2008-01-23 20:59 256 ----a-w C:\Program Files\pool.bin
    2007-11-07 02:49 2,629 ----a-w C:\Program Files\upgrade.log
    2007-01-24 13:54 101 ----a-w C:\Program Files\iloptcfg.cfg
    2007-01-19 00:03 958,591 ----a-w C:\Program Files\Synchronize.dll
    2007-01-19 00:03 389,203 ----a-w C:\Program Files\CE.dll
    2007-01-19 00:03 139,264 ----a-w C:\Program Files\WebLink.dll
    2007-01-19 00:03 1,609,728 ----a-w C:\Program Files\SwitchMediaCardWizard.exe
    2007-01-19 00:02 884,736 ----a-w C:\Program Files\LoaderLauncher.dll
    2007-01-19 00:02 585,728 ----a-w C:\Program Files\MultimediaManager.dll
    2007-01-19 00:02 2,142,208 ----a-w C:\Program Files\product.dll
    2007-01-19 00:02 1,212,416 ----a-w C:\Program Files\DesktopMgr.exe
    2007-01-19 00:01 774,144 ----a-w C:\Program Files\rim_media_manager.exe
    2007-01-19 00:01 618,634 ----a-w C:\Program Files\rim_hh.dll
    2007-01-19 00:01 462,848 ----a-w C:\Program Files\backuprestore.dll
    2007-01-19 00:01 352,256 ----a-w C:\Program Files\DeviceOptions.dll
    2007-01-19 00:01 348,299 ----a-w C:\Program Files\rim_asci.dll
    2007-01-19 00:01 270,336 ----a-w C:\Program Files\DeviceSwitch.dll
    2007-01-19 00:01 229,514 ----a-w C:\Program Files\RIMCXLServer.dll
    2007-01-19 00:01 11,012 ----a-w C:\Program Files\desktopapi.tlb
    2007-01-19 00:01 1,605,632 ----a-w C:\Program Files\RIMShellExt.dll
    2006-11-10 19:06 70,312 ----a-w C:\Program Files\BlackBerry_Desktop_Software_Help.chm
    2006-10-18 16:49 49,152 ----a-w C:\Program Files\Inetwh32.dll
    2006-10-18 16:49 401,408 ----a-w C:\Program Files\toc_updt.exe
    2006-10-18 16:49 4,178 ----a-w C:\Program Files\conn_install.cfg
    2006-10-18 16:49 39,116 ----a-w C:\Program Files\ILSYNC.HLP
    2006-10-18 16:49 28,887 ----a-w C:\Program Files\DESKTOP.HLP
    2006-10-18 16:49 2,506 ----a-w C:\Program Files\ConnectorToXlatorMaps.txt
    2006-10-18 16:49 10,871 ----a-w C:\Program Files\desktop.cnt
    2006-10-18 16:49 1,743 ----a-w C:\Program Files\ilsync.cnt
    2002-07-27 00:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
    
    What is the below doing in your Windows folder?
    Code:
    "C:\WINDOWS\"
    SEARCH~1 Feb 25 2008 "Search And Destroy"
    search~1.txt Feb 25 2008 6658 "Search And Destroy Setup Log.txt
    I will give you some things to do based on your current logs but as I stated, the logs were incomplete.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
    Uninstall the below old versions of software:
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [SearchAndDestroyMFC] C:\Program Files\Search And Destroy\Search And Destroy.exe
    O15 - Trusted Zone: http://www.manhunt.net
    O15 - Trusted Zone: http://www.msworld.org
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
    O21 - SSODL: SetupComponent - {66c03315-6d68-4e30-812d-461342def19b} - C:\WINDOWS\Installer\{66c03315-6d68-4e30-812d-461342def19b}\SetupComponent.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Make sure you allow it to finish running this time.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. paulbeagle

    paulbeagle Private E-2

    I followed all instructions, and it appears that my problem is gone now. THANK YOU VERY MUCH. I've attached the two logs. I can't answer the questions about how the various items got in the programs folder or what that code is doing in the windows folder. I assure you that I did not hand pick them and put them there. :confused I spent the money buying pcregistry cleaner and search and destroy. I know I didn't need to buy the cleaner, but I thought it was a good idea, and the search and destroy wouldn't run unless I bought it. I don't mind that, especially since my machine now seems to be working fine. I've attached the logs you have requested. What should I do now?

    If there is anything I can do to thank you, let me know.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But these are not programs that were part of the READ & RUN ME and thus as I was pointing out, you did not spend this money due to running the READ ME. Neither of these are recommended in the READ ME. And in fact I even question the validity of Search & Destroy since it is trying to capitalize on the fame of the program that we did ask you to run which is Spybot Search & Destroy which is freeware. Note that you also are using Spybot - Search & Destroy 1.3 which is four years out of date and is not what we ask you to use in the READ ME.

    [EDIT] In fact I just downloaded and installed this Search and Destroy program. It is junk / a rogue tool. It is showing non-existent registry keys and problems on my PC. Get your money back A.S.A.P. If you used a credit card, put a stop on the purchase now before they get you money because you may have problems getting it back otherwise.


    You need to uninstall the below as requested in step 1 of the READ ME:
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    You also need to uninstall more old Sun Java versions as was also requested in the READ ME:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The more I looked at what this totall rogue tool is generating the more ridiculous it becomes. It is a totally fabricating non-existent problems. This Search and Destroy tool is a total fake and needs to now be added to our list of things to uninstall as it is a rogue program.
     
  9. paulbeagle

    paulbeagle Private E-2

    Ok, I've gotten rid of seach and destroy (and have asked for my $ back). :eek: What can I say? I was at wit's end! I did say I didn't know what I was doing! - and if I didn't I should have! Oh well. I've also removed the additional programs you instucted me to remove. Is there anything else I can get rid of?

    Anything else I should do?

    THANK YOU.:wave
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't let them try to tell you their program is valid and try to talk you out of uninstalling it (which they are sure to try). Also if on your credit card, put a stop payment on it.

    Did you uninstall the 1.3 version of Spybot Search & Destroy? And did you download and install the latest version from the link in the READ ME? If not please do this.

    Also you should install the below which just came out today:

    SpywareBlaster 4.0


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  11. paulbeagle

    paulbeagle Private E-2

    OK All Done ! ;) Thanks. I also found this program on my c drive: fixwareout Can I delet that? Boy, I feel a lot better! amd more educated now, too. THANK YOU>
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is for fixing WareOut infections.

    I have been having some great laughs about Search and Destroy. It is totally absurd what infections it is inventing. It is even giving infections on drives that do not exist, in folders that do not exist, mention files and registry keys that do not exist and much more. It such a piece junk! Just another tool to add to the 350 or so rogue tools that exist.

    You're welcome and surf safely!
     
  13. paulbeagle

    paulbeagle Private E-2

    Thank you! I'm glad you at least got a couple of laughs out of all this. Too bad that these programs are out there and available for fools like me to buy.:eek:


    Reminds me of an incident I experienced about 30 years ago. One of my first clients was purchasing a remote piece of property to build a steel mill. As we were driving through the brush on the property, where a brush fire was raging maybe 200 feet from us, and I at least (not my client) was showing signs of nervousness....he handed me a rather thick document and said - "Here, take a look at this." After looking at a document that was very technical in nature having to do with iron ore boilers, I handed it back to him and said " I'm not sure why you're giving this to me, I don't understand one bit of it" He replied - "Well, that's how much I know about what you do."

    Keep up your good works!

    Thanks so much.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't feel too bad. Thousands of people have fallen for these advertisements and professionally looking websites (in some cases). See this list which is lagging behind (it has not been updated for over a year):

    http://www.spywarewarrior.com/rogue_anti-spyware.htm


    :D:D


    You're welcome. And remember to check here first the next time you have malware problem. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds