Overview |
Summary: |
lop is a family of programs that set your start page and IE's search features to use the site lop.com ('Live Online Portal') or one of its clone sites. Known lop sites include: aavc.com acjp.com ebav.com ebaw.com ebch.com ebch.com ebdv.com ebdw.com ebgo.com ebjp.com ebkb.com ebkn.com ebky.com eblv.com wbkb.com ebmu.com ebvr.com ecmh.com ecmp.com ecpm.com ecwz.com ecyb.com edhq.com edty.com eduy.com eeev.com farse.com ibmx.com icwb.com icwo.com icwp.com iddh.com idhh.com ifiz.com iguu.com samz.com saoe.com sbee.com sbjr.com sbnl.com sbnt.com sbvr.com scbm.com sckr.com scrk.com sdry.com seld.com sfux.com sheat.com sipo.com smds.com srib.com srox.com srsf.com ssaw.com ssby.com surj.com tbvg.com tdak.com tdmy.com tefs.com tfil.com tjar.com tjaw.com tjgo.com tjem.com torc.com wabu.com wabq.com wfix.com wflu.com Lop also adds shortcuts to advertisers. Finally it adds a task to run on startup which sets your homepage and search back to lop if you change them. |
Alias: |
TrojanDownloader.Win32.Swizzor.ae, Adware/Adtomi [Panda], Adware/Apropos [Panda], Adware/Lop [Panda], Adware/nCase [Panda], Adware/NetPals [Panda], Adware/WinActive [Panda], Adware-180Solutions [McAfee], C2 Media, after the company that makes it., Dialer.AL [Panda], Lop, LopAdvert [McAfee], MP3Search [McAfee], MpAdvert [McAfee], Spyware/Infameow [Panda], Trj/Downloader.HC [Panda], Trj/Downloader.HW [Panda], Trj/Downloader.HX [Panda], Trj/Zerolin.A [Panda], Trojan.Win32.SecondThought.h [Kaspersky], TrojanClicker.Win32.Rotarran (for Lop.Com.WinactiveJ), TrojanDownloader.Win32.Small.bp, TrojanDownloader.Win32.Small.bp [Kaspersky], TrojanDownloader.Win32.Swizzor.au [Kaspersky], TrojanDownloader.Win32.Swizzor.ba [Kaspersky], TrojanDownloader.Win32.Swizzor.bm [Kaspersky], TrojanDownloader.Win32.Swizzor.bn [Kaspersky], TrojanDownloader.Win32.Swizzor.br [Kaspersky], TrojanDownloader.Win32.Swizzor.i [Kaspersky], TrojanDownloader.Win32.Swizzor.q [Kaspersky], TrojanDropper.Win32.Small.fl [Kaspersky], VBS.ObjectDataHTA [Computer Associates], VBS.Suzer [Computer Associates], VBS/Inor.gen [Panda], VBS/Suzer.A!Dropper [Computer Associates], Win32/Polbya.A!Trojan [Computer Associates] |
See Also: |
Lop |
Category: |
Spyware: Any product that employs a user's Internet connection in the background without their knowledge, and gathers/transmits info on the user or their behavior. Many spyware products will collect referrer info (information from your web browser which reveals what URL you linked from), your IP address (a number that is used by computers on the network to identify your computer), system information (such as time of visit, type of browser used, the operating system and platform, and CPU speed.) Spyware products sometimes wrap other commercial products, and are introduced to machines when those commercial products are installed. See also Adware.
Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product. Browser Helper Object: (BHO). A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules. A BHO can detect events, create windows to display additional information on a viewed page, monitor messages and actions. Microsoft calls it "a spy we send to infiltrate the browser's land." BHOs are not stopped by personal firewalls, because they are seen by the firewall as your browser itself. Some exploits of this technology search all pages you view in IE and replace banner advertisements with other ads. Some monitor and report on your actions. Some change your home page. Dialer: Software that dials a phone number. Some dialers connect to local Internet Service Providers and are beneficial as configured. Others connect to toll numbers without user awareness or permission. Downloader: A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site. Dropper: In viruses and trojans, the dropper is the part of the program that installs the hostile code onto the system. Hijacker: Any software that resets your browser's settings to point to other sites. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower. Search Hijacker: Any software that resets your browser's settings to point to other sites when you perform a search. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower. Search results when such a hijacker is running will sometimes differ from non-hijacked results. Toolbar: A group of buttons which perform common tasks. A toolbar for Internet Explorer is nomally located below the menu bar at the top of the form. Toolbars may be created by Browser Helper Objects. Trojan: Any program with a hidden intent. Trojans are one of the leading causes of breaking into machines. If you pull down a program from a chat room, new group, or even from unsolicited e-mail, then the program is likely trojaned with some subversive purpose. The word Trojan can be used as a verb: To trojan a program is to add subversive functionality to an existing program. For example, a trojaned login program might be programmed to accept a certain password for any user's account that the hacker can use to log back into the system at any time. Rootkits often contain a suite of such trojaned programs. |
Variants: |
Lop.com.WinActiveLop.com.WinActiveJLop.com/ActiveLop.com/AYBLop.com/DialerLop.com/IMZLop.com/LoaderLop.com/RNDLop.com/ToolbarLop.com/TrinityOmegaSearchSome variants
install both the Toolbar software and the AYB software.
There are some other drive-by-downloads based around
similar code. lop/Trinity only adds the shortcuts and
does the homepage/search hijacking. lop/Dialer is a
plain porn dialler; lop/Dialer2 is a porn dialer which
also includes the startup task but not the links or
the toolbar. |
Similar Pests: |
Spyware · Adware · Browser Helper Object · Dialer · Downloader · Dropper · Hijacker · Search Hijacker · Toolbar · Trojan |
Origins |
Group: |
C2 Media Ltd |
Vendor: |
WRN.net
markets the affiliate program to webmasters. |
By This Group: |
Lop · |
Programming Language: |
Compressed with UPX. |
Date of Origin: |
Variants from June, 2002 to March, 2005 |
Distribution |
Distribution: |
Installed by ActiveX or simple EXE file download from
many sites, often through redirecting pop-up ads. The
executable file is likely to have a name like:
mp3.exe
FreeMP3.exe
freemp3z.exe
FreeMP3Music.exe
free_sex_viewer.exe
free_deals.exe
Software_Plugin.exe
download_file.exe
The_Ultimate_Browser_Enhancer.exe
free_plugin.exe |
Prevalence: |
Lop.com: 75.1%OmegaSearch: 1.2%
More Info |
Clot Factor: |
Lop.com: 7
The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone. |
Growth: |
Lop.com: Insufficient data to report growthOmegaSearch: Insufficient data to report growth |
Operation |
Advertising: |
Yes. Some shortcut icons are added to the desktop. Many more are added to the Favorites menu. More are on an IE toolbar called 'Accessories'. The process run on startup also occasionally pops up advertisements. |
Storage Required: |
Lop.com: at least 15009 KBLop.com.WinActive: at least 4609 KBLop.com.WinActiveJ: at least 49 KBOmegaSearch: at least 1161 KB |
Browser Performance: |
Likely to slow performance of Internet Explorer. |
Risks |
Privacy Issues: |
No. |
Security Issues: |
None known. |
Stability Issues: |
Running the software may cause many 'dial-up connection' requests to appear if you are not connected. Windows seems to hang temporarily for a few minutes when this happens. |
Detection and Removal |
Automatic Removal: |
PestPatrol detects this.
PestPatrol removes this.
|
Manual Removal: |
There is an uninstall feature, which can usually be
found on the round icon in the system tray. Click the
right button on it and choose 'Menu'. On the resulting
window, click 'Help', then 'Uninstall'. Some variants
also add a 'LOP uninstall' entry to the Control Panel's
Add/Remove Programs control which does the same. However
this feature does not clear up all the mess lop leaves
behind. See below for cleanup info.
Open the Application Data folder. This can be found
inside the Windows folder on Windows 95/98/Me; on Windows
2000 and XP it is inside your user folder in 'Documents
and Settings', but it's hidden, so go to Tools->Folder
Options->View and turn on 'Show hidden files and
folders' to see it. In Windows NT 4.0 it is in the user
folder inside 'WinNT\Profiles'.
The filenames of lop files varies for each different
lop affiliate distributing the software, but normally
there should not be any files inside Application Data
(only folders), so it's usually easy to pick out the
culprits. Known filenames for the toolbar DLL (lop/Toolbar)
or ayb: protocol DLL (lop/AYB) include:
eelykofrllfrpr.dll
ealymfrprwch.dll
yeecrsoustoull.dll
heeachmstll.dll
ziebaeeoaeepr.dll
prxzoustustgr.dll
llfggrdr.exe
plg_ie[any digit].dll
quizbt[any digit].dll
blztstull[letter 'a', 'c', 'j', 'p', 's', 't' or 'y'].dll
blztstull['pr', 'tr' or 'oo'].dll
Known filenames for the system tray task and hijacker
file include:
oofrkxpe.exe
lopsearc.exe
shoucrck.exe
meemnckyqbr.exe
eaymulyl.exe
ulyuiexeechp.exe
byb_save.exe
peebqusz.exe
trstdris.exe
Other files you may find with some versions include
icon libraries (known filenames tchejea.lib and iCndE.lib)
and loads of GIFs. These can all be deleted too. You
might also have some of the following files in the Windows
folder:
desktop.htm
dnserror.htm
jexpoofro.htm
i_dnserr.gif
s_dnserr.gif
r_dnserr.gif
b_dnserr.gif
tiejexpoo.gif
xiejexpoo.gif
oiejexpoo.gif
uiejexpoo.gif
Open the registry (Start->Run->regedit) and find
the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you have not used the uninstall feature there should
still be an entry with a value like 'C:\WINDOWS\APPLIC~1\(task
name).exe -QuieT'; delete it. The name of this entry
changes in different variants; known names are:
eeullz
ymste
abtu
zvoah
lssxsh
pprwly
You should also delete the following entries if you
have them and they are not just blank:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Telephony\DomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Domain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{...check
all interfaces...}\Domain
Also you can remove the lop settings key if you can
find it; it is inside HKEY_LOCAL_MACHINE\Software and
has, again, a varying name; known examples are:
ckotetlllyllshz
kseateasteestoe
ssaxstxoaieoagrh
TrinityAYB (lop/Trinity variant)
Next, if you have not used the uninstall feature, open
a DOS command prompt window (from Start->Programs->Accessories)
and enter the following commands:
cd "%WinDir%\System"
regsvr32 /u [name of DLL]
substituting the full filename of the DLL, whatever
its name is, in Application Data. Tip: You can drag
the DLL file from Explorer onto the DOS command prompt
window to put the name in so you don't have to type
it all out.
Finally, reboot Windows and you should be able to delete
all the files mentioned above, along with the shortcuts
added to the desktop and the favorites menu. You can
also reset your homepage (from Internet Options->General)
and search settings (Internet Options->Programs->Reset
Web Settings); if you use Netscape/Mozilla you will
need to reset the home page too (Edit->Preferences->Navigator).
You may also wish to check your computer for dialers,
as the lop.com site has been known to include dialer
installers. |
|
Stop Running Processes:
Kill these running processes with Task Manager:
|
|
Remove AutoRun Reference:
Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\blehantimapimeta, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cam-6415[1], delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\defyactive, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ford site, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\frckshll, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\idle heart free wipe, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\iso real, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\list 4, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\loud math help cash, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\meta mail, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\mfcd boob film frag, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\move delete, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\parttickwaitjugs, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\proxycity, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\setup wipe, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\start idle, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\two bags, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\twquh, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ubipwdk, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\uqzborauqedw, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\winactive, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\window balm, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ws2f35t, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\wstpsh, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ybmk, delete it and reboot the machine immediately.
|
|
Unregister DLLs:
Unregister these DLLs with Regsvr32, then reboot:
|
|
Clean Registry:
Remove these registry items (if present) with RegEdit:
|
|
Remove Files:
Remove these files (if present) with Windows Explorer:
|
|
Remove Directories:
Remove these directories (if present) with Windows Explorer:
|
|
Restore Settings:
After following the instructions above, you will still need to restore your original settings and prevent this from happening again. Here''s how.
|
Research |
File Analyses: |
|
More Info: |
Nastylop
is a site set up to fight Lop.
AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo! |
Research By: |
Andrew CloverPestPatrol's Pest Research Center |
Last Revised: |
April 03, 2005 |