Lop.com


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Risks ·
· Detection and Removal ·
· Research ·



Overview

Summary:

lop is a family of programs that set your start page and IE's search features to use the site lop.com ('Live Online Portal') or one of its clone sites.

Known lop sites include: aavc.com acjp.com ebav.com ebaw.com ebch.com ebch.com ebdv.com ebdw.com ebgo.com ebjp.com ebkb.com ebkn.com ebky.com eblv.com wbkb.com ebmu.com ebvr.com ecmh.com ecmp.com ecpm.com ecwz.com ecyb.com edhq.com edty.com eduy.com eeev.com farse.com ibmx.com icwb.com icwo.com icwp.com iddh.com idhh.com ifiz.com iguu.com samz.com saoe.com sbee.com sbjr.com sbnl.com sbnt.com sbvr.com scbm.com sckr.com scrk.com sdry.com seld.com sfux.com sheat.com sipo.com smds.com srib.com srox.com srsf.com ssaw.com ssby.com surj.com tbvg.com tdak.com tdmy.com tefs.com tfil.com tjar.com tjaw.com tjgo.com tjem.com torc.com wabu.com wabq.com wfix.com wflu.com

Lop also adds shortcuts to advertisers. Finally it adds a task to run on startup which sets your homepage and search back to lop if you change them.

Alias:

TrojanDownloader.Win32.Swizzor.ae, Adware/Adtomi [Panda], Adware/Apropos [Panda], Adware/Lop [Panda], Adware/nCase [Panda], Adware/NetPals [Panda], Adware/WinActive [Panda], Adware-180Solutions [McAfee], C2 Media, after the company that makes it., Dialer.AL [Panda], Lop, LopAdvert [McAfee], MP3Search [McAfee], MpAdvert [McAfee], Spyware/Infameow [Panda], Trj/Downloader.HC [Panda], Trj/Downloader.HW [Panda], Trj/Downloader.HX [Panda], Trj/Zerolin.A [Panda], Trojan.Win32.SecondThought.h [Kaspersky], TrojanClicker.Win32.Rotarran (for Lop.Com.WinactiveJ), TrojanDownloader.Win32.Small.bp, TrojanDownloader.Win32.Small.bp [Kaspersky], TrojanDownloader.Win32.Swizzor.au [Kaspersky], TrojanDownloader.Win32.Swizzor.ba [Kaspersky], TrojanDownloader.Win32.Swizzor.bm [Kaspersky], TrojanDownloader.Win32.Swizzor.bn [Kaspersky], TrojanDownloader.Win32.Swizzor.br [Kaspersky], TrojanDownloader.Win32.Swizzor.i [Kaspersky], TrojanDownloader.Win32.Swizzor.q [Kaspersky], TrojanDropper.Win32.Small.fl [Kaspersky], VBS.ObjectDataHTA [Computer Associates], VBS.Suzer [Computer Associates], VBS/Inor.gen [Panda], VBS/Suzer.A!Dropper [Computer Associates], Win32/Polbya.A!Trojan [Computer Associates]

See Also:

Lop

Category:

Spyware: Any product that employs a user's Internet connection in the background without their knowledge, and gathers/transmits info on the user or their behavior. Many spyware products will collect referrer info (information from your web browser which reveals what URL you linked from), your IP address (a number that is used by computers on the network to identify your computer), system information (such as time of visit, type of browser used, the operating system and platform, and CPU speed.) Spyware products sometimes wrap other commercial products, and are introduced to machines when those commercial products are installed. See also Adware.

Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product.

Browser Helper Object: (BHO). A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules. A BHO can detect events, create windows to display additional information on a viewed page, monitor messages and actions. Microsoft calls it "a spy we send to infiltrate the browser's land." BHOs are not stopped by personal firewalls, because they are seen by the firewall as your browser itself. Some exploits of this technology search all pages you view in IE and replace banner advertisements with other ads. Some monitor and report on your actions. Some change your home page.

Dialer: Software that dials a phone number. Some dialers connect to local Internet Service Providers and are beneficial as configured. Others connect to toll numbers without user awareness or permission.

Downloader: A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site.

Dropper: In viruses and trojans, the dropper is the part of the program that installs the hostile code onto the system.

Hijacker: Any software that resets your browser's settings to point to other sites. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower.

Search Hijacker: Any software that resets your browser's settings to point to other sites when you perform a search. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower. Search results when such a hijacker is running will sometimes differ from non-hijacked results.

Toolbar: A group of buttons which perform common tasks. A toolbar for Internet Explorer is nomally located below the menu bar at the top of the form. Toolbars may be created by Browser Helper Objects.

Trojan: Any program with a hidden intent. Trojans are one of the leading causes of breaking into machines. If you pull down a program from a chat room, new group, or even from unsolicited e-mail, then the program is likely trojaned with some subversive purpose. The word Trojan can be used as a verb: To trojan a program is to add subversive functionality to an existing program. For example, a trojaned login program might be programmed to accept a certain password for any user's account that the hacker can use to log back into the system at any time. Rootkits often contain a suite of such trojaned programs.

Variants:

  • Lop.com.WinActive
  • Lop.com.WinActiveJ
  • Lop.com/Active
  • Lop.com/AYB
  • Lop.com/Dialer
  • Lop.com/IMZ
  • Lop.com/Loader
  • Lop.com/RND
  • Lop.com/Toolbar
  • Lop.com/Trinity
  • OmegaSearch
  • Some variants install both the Toolbar software and the AYB software.

    There are some other drive-by-downloads based around similar code. lop/Trinity only adds the shortcuts and does the homepage/search hijacking. lop/Dialer is a plain porn dialler; lop/Dialer2 is a porn dialer which also includes the startup task but not the links or the toolbar.

  • Similar Pests:

    Spyware · Adware · Browser Helper Object · Dialer · Downloader · Dropper · Hijacker · Search Hijacker · Toolbar · Trojan

    Origins

    Group:

    C2 Media Ltd

    Vendor:

    WRN.net markets the affiliate program to webmasters.

    By This Group:

    Lop ·

    Programming Language:

    Compressed with UPX.

    Date of Origin:

    Variants from June, 2002 to March, 2005

    Distribution

    Distribution:

    Installed by ActiveX or simple EXE file download from many sites, often through redirecting pop-up ads. The executable file is likely to have a name like:

    mp3.exe
    FreeMP3.exe
    freemp3z.exe
    FreeMP3Music.exe
    free_sex_viewer.exe
    free_deals.exe
    Software_Plugin.exe
    download_file.exe
    The_Ultimate_Browser_Enhancer.exe
    free_plugin.exe

    Prevalence:

  • Lop.com: 75.1%
  • OmegaSearch: 1.2%
  • More Info

    Clot Factor:

  • Lop.com: 7
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Growth:

  • Lop.com: Insufficient data to report growth
  • OmegaSearch: Insufficient data to report growth
  • Operation

    Advertising:

    Yes. Some shortcut icons are added to the desktop. Many more are added to the Favorites menu. More are on an IE toolbar called 'Accessories'. The process run on startup also occasionally pops up advertisements.

    Storage Required:

  • Lop.com: at least 15009 KB
  • Lop.com.WinActive: at least 4609 KB
  • Lop.com.WinActiveJ: at least 49 KB
  • OmegaSearch: at least 1161 KB
  • Browser Performance:

    Likely to slow performance of Internet Explorer.

    Risks

    Privacy Issues:

    No.

    Security Issues:

    None known.

    Stability Issues:

    Running the software may cause many 'dial-up connection' requests to appear if you are not connected. Windows seems to hang temporarily for a few minutes when this happens.

    Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    There is an uninstall feature, which can usually be found on the round icon in the system tray. Click the right button on it and choose 'Menu'. On the resulting window, click 'Help', then 'Uninstall'. Some variants also add a 'LOP uninstall' entry to the Control Panel's Add/Remove Programs control which does the same. However this feature does not clear up all the mess lop leaves behind. See below for cleanup info.

    Open the Application Data folder. This can be found inside the Windows folder on Windows 95/98/Me; on Windows 2000 and XP it is inside your user folder in 'Documents and Settings', but it's hidden, so go to Tools->Folder Options->View and turn on 'Show hidden files and folders' to see it. In Windows NT 4.0 it is in the user folder inside 'WinNT\Profiles'.

    The filenames of lop files varies for each different lop affiliate distributing the software, but normally there should not be any files inside Application Data (only folders), so it's usually easy to pick out the culprits. Known filenames for the toolbar DLL (lop/Toolbar) or ayb: protocol DLL (lop/AYB) include:

    eelykofrllfrpr.dll
    ealymfrprwch.dll
    yeecrsoustoull.dll
    heeachmstll.dll
    ziebaeeoaeepr.dll
    prxzoustustgr.dll
    llfggrdr.exe
    plg_ie[any digit].dll
    quizbt[any digit].dll
    blztstull[letter 'a', 'c', 'j', 'p', 's', 't' or 'y'].dll
    blztstull['pr', 'tr' or 'oo'].dll
    Known filenames for the system tray task and hijacker file include:

    oofrkxpe.exe
    lopsearc.exe
    shoucrck.exe
    meemnckyqbr.exe
    eaymulyl.exe
    ulyuiexeechp.exe
    byb_save.exe
    peebqusz.exe
    trstdris.exe
    Other files you may find with some versions include icon libraries (known filenames tchejea.lib and iCndE.lib) and loads of GIFs. These can all be deleted too. You might also have some of the following files in the Windows folder:

    desktop.htm
    dnserror.htm
    jexpoofro.htm
    i_dnserr.gif
    s_dnserr.gif
    r_dnserr.gif
    b_dnserr.gif
    tiejexpoo.gif
    xiejexpoo.gif
    oiejexpoo.gif
    uiejexpoo.gif
    Open the registry (Start->Run->regedit) and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. If you have not used the uninstall feature there should still be an entry with a value like 'C:\WINDOWS\APPLIC~1\(task name).exe -QuieT'; delete it. The name of this entry changes in different variants; known names are:

    eeullz
    ymste
    abtu
    zvoah
    lssxsh
    pprwly
    You should also delete the following entries if you have them and they are not just blank:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Telephony\DomainName
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Domain
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Domain
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{...check all interfaces...}\Domain
    Also you can remove the lop settings key if you can find it; it is inside HKEY_LOCAL_MACHINE\Software and has, again, a varying name; known examples are:

    ckotetlllyllshz
    kseateasteestoe
    ssaxstxoaieoagrh
    TrinityAYB (lop/Trinity variant)
    Next, if you have not used the uninstall feature, open a DOS command prompt window (from Start->Programs->Accessories) and enter the following commands:

    cd "%WinDir%\System"
    regsvr32 /u [name of DLL]
    substituting the full filename of the DLL, whatever its name is, in Application Data. Tip: You can drag the DLL file from Explorer onto the DOS command prompt window to put the name in so you don't have to type it all out.

    Finally, reboot Windows and you should be able to delete all the files mentioned above, along with the shortcuts added to the desktop and the favorites menu. You can also reset your homepage (from Internet Options->General) and search settings (Internet Options->Programs->Reset Web Settings); if you use Netscape/Mozilla you will need to reset the home page too (Edit->Preferences->Navigator).

    You may also wish to check your computer for dialers, as the lop.com site has been known to include dialer installers.

    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove AutoRun Reference:

    Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\blehantimapimeta, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cam-6415[1], delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\defyactive, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ford site, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\frckshll, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\idle heart free wipe, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\iso real, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\list 4, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\loud math help cash, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\meta mail, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\mfcd boob film frag, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\move delete, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\parttickwaitjugs, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\proxycity, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\setup wipe, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\start idle, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\two bags, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\twquh, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ubipwdk, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\uqzborauqedw, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\winactive, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\window balm, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ws2f35t, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\wstpsh, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ybmk, delete it and reboot the machine immediately.



    Unregister DLLs:

    Unregister these DLLs with Regsvr32, then reboot:

    Clean Registry:

    Remove these registry items (if present) with RegEdit:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Remove Directories:

    Remove these directories (if present) with Windows Explorer:

    Restore Settings:

    After following the instructions above, you will still need to restore your original settings and prevent this from happening again. Here''s how.

    Research

    File Analyses:

    More Info:

  • Nastylop is a site set up to fight Lop.
  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • Andrew Clover
  • PestPatrol's Pest Research Center
  • Last Revised:

    April 03, 2005