LOP.Com - can anyone rid me of this pesky varmint?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by slicknick, Dec 1, 2004.

  1. slicknick

    slicknick Private E-2

    Help please - New member

    I have a rogue bar that positions itself at the bottom of my screen and also inserts a search bar at the top of the screen.

    It stops me reading other windows bars in programmes such as Excel etc.

    The only thing I know about it is when I click properties it shows:
    http://lop.com/passthrough/newpass2.html

    Is there anyway of getting rid of this for good?

    Your help would be greatly appreciated.

    PS. I have ad-aware, spybot S&D, CWE shredder installed and yet it still comes back!

    Many thanks.

    Slicknick
     
  2. Kodo

    Kodo SNATCHSQUATCH

    Please follow all the steps in this Sticky thread <READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >


    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. slicknick

    slicknick Private E-2

    Thanks for the reply. I have undertaken every step outlined in the "DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan and Virus Removal" reply.

    The only step I had any problem with was in the section headed: Keeping your computer safe and secure:

    I was unable to locate and therefore remove the following items : The \%systemroot%\Java folder.

    It does not appear to be in my C:\Windows folder.

    Finally, having rebooted and gone back into Internet Explorer the LOP search bars are back!!!

    I would be grateful for any help you could give me still with this.

    Thanks for your help so far

    Slicknick
     
  4. Skaterscafe.com

    Skaterscafe.com Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a thread that has not been active for almost twomonths. I'm not sure if the user even cares anymore.

    Be careful what you remove with MS Antispyware. It has lot's of issues with false detections. It even removes things that you purposely put into your Restricted Zones to block malware. There have also been several cases where MS Antispyware broke Microsoft's own built in firewall in Win XP SP2.
     
  6. Skaterscafe.com

    Skaterscafe.com Private E-2

    Yea, I know it was 2 months old, I didn't see an answer and didn't think 2 months was all that long to bring back a topic that still goes unanswered.

    Well, that didn't work after all. I opened MS IE again and there it was. I have ran Norton, MSAS, Spybot and nothing seems to remove this )@*&@^ thing.
     
    Last edited by a moderator: Feb 17, 2005
  7. PhilliePhan

    PhilliePhan Guest

    You don't happen to use Messenger Plus! 3, do you? It installs LOP.

    Please post a fresh HijackThis Log. Be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!
    Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been tied up with work lately and cannot visit this forum too often these days, but somebody will try to take a look when they get a chance.

    PP :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It only went unanswered only because the user never came back so we could not find out what the real problems were and fix them.

    You should have started your own thread.

    And please in cases like this where you think you have solved a similar problem, wait to make sure your "solution" works before posting it!

    PP,

    I saw no evidence that the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal thread has been run by Skaterscafe!
     
    Last edited: Feb 20, 2005
  9. slicknick

    slicknick Private E-2

    Hi, Please accept my apologies if I inadvertently caused this thread to go a bit 'pear shaped'!

    I waited a little while for a reply but gave up in the end.

    Unfortunatley, I still have the LOP.COM toolbar at the bottom of my screen and my computer now runs like a tractor!

    I have tried:
    Ad-aware, Hijack this, Spybot search and destroy, A2Squared, BHO Demon, CrapwareCleaner, EZAntivirus - plus others all to no avail. I get an Altnet and Grockster warning when I scan my computer but the software I ahve cannot eliminate either. I think my computer got these when my two sons downloaded Blubster and Kazaa without my knowledge!

    If anyone out there could still help me I would be extremely grateful.

    Many thanks

    Slicknick
     
  10. PhilliePhan

    PhilliePhan Guest

    Hi Nick,

    How many User Accounts on your machine?

    Please attach a HJT log as per the instructions in Post #7 for all user accounts and somebody will take a look as time permits.

    PP :)
     
  11. slicknick

    slicknick Private E-2

    Hi PP,

    Thanks for the prompt reply.

    There are four user accounts in total on my machine.

    Please find attached a Hijackthis log for someone to take a look at when convenient.

    Many thanks

    Nick
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install Spyware Doctor and then allow BHO Demon to disable it? Uninstall Spyware Doctor if you do not want it. It appears to only be the demo version anyway which is not of much use.

    You had two instances of C:\Program Files\Internet Explorer\iexplore.exe
    running when you used HJT. ALL browsers must be shutdown before you use HJT.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {4C09941E-C1BE-92FD-CDB5-36DB47821763} - (no file)
    O4 - HKLM\..\Run: [Vgasettings01coal] C:\Documents and Settings\All Users\Application Data\USER SLOW VGA SETTINGS\Extralive.exe

    The below are up to you to decide:
    Do you really want Sony to be in control of what your Home & search pages reset to?
    O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com/
    Nothing belongs in the Trusted Zone unless they are absolutely necessary. I have not seen a case yet where they were?
    O15 - Trusted Zone: *.sony-europe.com
    O15 - Trusted Zone: *.sonystyle-europe.com
    O15 - Trusted Zone: *.vaio-link.com

    Read this and observe where Limewire is listed: http://www.spywareinfo.com/articles/p2p/
    You have Limewire installed:
    O4 - Global Startup: LimeWire 4.2.6.lnk = D:\ProgramFiles\LimeWire\LimeWire 4.2.6\LimeWire.exe

    After completing my fixes and deciding what you want to do about the other items, reboot and post a new HJT log.
     
    Last edited: Feb 20, 2005
  13. slicknick

    slicknick Private E-2

    Hi PP,

    Many thanks for looking at this for me.

    I have removed Spyware Doctor using Unistall4good.

    I have also removed everything else you suggested including the Limewire connection (I was assured by my son that this came on the software for his iPOD but I'm not so sure!)

    The good news is the LOP.com toolbar has now disappeared - do you think it will re-emergence again - perhaps through some hidden file at startup?

    Please find attached a further HJT log.

    Many thanks again.

    Kind regards

    Nick (UK)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was me, chaslang, who answered you last time. PP had given steps earlier and was not around so I picked up where he left off.

    You have one more left over from Spyware Doctor to fix with HijackThis (make sure no browsers are running when you click fix):

    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)

    Limewire may have come with iPod, I don't know. Many people do choose to keep programs like this and use them. Any P2P program represents some level of danger and some (as indicated in the link I gave you) add some additional garabage to your system.

    You log is clean other than the above line. To help you avoid future problems, you should now perform the steps in the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds