lop.com toolbar removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by firstphantom, May 5, 2005.

  1. firstphantom

    firstphantom Private E-2

    Hi,
    thanks for your time...

    I have spent 2 days cleaning a 16 year old's computer. I have run in safe mode as well as under her id every malware, trojan, and spyware tool out there. I eliminated 35 processes and the machine runs much faster but i have a few items I cant resolve.

    1. when running Symantec Security Check it tells me to get rid of:
    c:\windows\system32\dncqcoo.exe, dknqn.dll, iprln.exe, sipbpgg.dll and

    c:\docs and setting\all users\start menu\programs\startup\rkdc.exe

    Even though I set machine to show file extensions, and hidden files and system files, I still cannot find these 4 files.


    2.When I run CCleaner I see under the Start programs tab the following:

    Key=HKLM:Run, Program = KavSvc, File=c:\windows\system32\iprlrn.exe

    Should I delete this?

    And under the Startup Programs are the following:

    Fonesync, IE HOST R3, Indexing Function, Learn2Player (Uninstall Only), SBMOS, Search OS, TP HTTP, and Win-dh.

    Do I remove any of these?



    3.At the bottom of the desktop when I open IE I get a toolbar but only under her id. When I right click it and click properties it shows:

    Address=http://lop.com/passthrough/newpass.html

    This toolbar does not appear under the other 2 ID's on the machine.

    I have run hijackthis 1.99.1 and can post the output if that will help.

    Thanks in advance for any help you can offer,
    gary...
     
  2. firstphantom

    firstphantom Private E-2

    I see 30 people have looked over my post so far and no one has been able to offer any suggestions. Is there some other information I should be posting to give more information that may allow someone to help? Please let me know if there is anything else I can do.

    As I said, the most important thing for me to do is remove the lop.com toolbar.

    thanks,
    gary...
     
  3. firstphantom

    firstphantom Private E-2

    While waiting I was able to fix number one on my own. I found that even though I cant see the 4 files in explorer, I can see and delete them in DOS.

    I still need help with the other 2 though if anyonecan help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Number 1 and number 2 are related to the same problem. So all that may have happen is they changed names. You need to run thru our full cleanup procedure which ends in posting a HijackThis log if still having a problem.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    Now after doing the above follow the steps below so we can fixed the root of your problem with KavSvc:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just have to wait your turn in the queue! Not everyone reading your message has the ability to understand the problem or to fix it. Those of us who do are very busy. At the current time I have in the vincinity of 100 running threads. Just have patience. We do not work here! This is a free service with people volunteering their time when they can do so.
    When you added your additional message, you only delayed getting a response. This happens because you make your thread newer and you make it have greater then 0 responses. First we work our current running threads that need attention and then we work from oldest to newest and also one threads with no responses first. For this reason, anyone who does a "bump" on their thread will only further delay getting help.
     
  6. firstphantom

    firstphantom Private E-2

    Hi Chaslang,

    This was my first time posting to this group and that was why I re-posted to ask if there was anything I did out of the norm. Thanks for taking the time to address my problem.

    I attached the hijackthis file as well as the QooLogic file. There is a 2 file max, so I will print the output of the RKFiles Tool at the end here.

    Thanks again,
    gary...

    What follows is the RKFiles output:

    C:\Documents and Settings\Administrator

    That was the only line present in c:\log.txt
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the RKfiles tool again. There should be more info than that. Did you run it after booting into safe mode? Make sure you wait until it completes. Yes you are right there is a two attachment limit. You could just you a second message to post the third attachment.

    Is that HJT log from normal boot mode or safe mode? They must be from normal boot mode unless otherwise requested.

    You did not install HijackThis as request. You are running it from:
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis1.99.1.zip\HijackThis.exe

    This means you are running it directly from the ZIP file. You must follow the directions given. Running it this way will not allow HJT to make backups of items we fix with it.

    I see no signs of KavSvc, File=c:\windows\system32\iprlrn.exe
    running on your system. The reason I had you run Qoologic and RKfiles was to help us fix that problem, but I do not see it.
     
    Last edited: May 6, 2005
  8. firstphantom

    firstphantom Private E-2

    Hi Chaslang,

    Sorry for not extracting to the proper directory right away. I did it right this time.

    I ran hijackthis under the offending id (there are 2 other id's without problems), and I ran RKfiles under the admin account in safe mode. I did not run it under the offending account because they dont have admin rights so I their account doesnt show in safe mode.

    After running RKfiles, I found a win.txt and a windows.txt along with the log.txt with the same date and time. I dont know if you need the output of those, but the output only has 4 lines.

    win.txt contains:
    C:\WINDOWS\SYSTEM32\garyoldadlinstallwin32.garyoldexe.garyoldtcf: UPX!
    C:\WINDOWS\SYSTEM32\sgaryoldew.egaryoldxe: UPX!
    C:\WINDOWS\SYSTEM32\DFRG.MSC: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213

    The first 2 lines above show files I had renamed after running other cleanup software rather than deleting the files.


    windows.txt contains:
    C:\WINDOWS\axpfins.exe: UPX!
    C:\WINDOWS\io2uns.exe: UPX!
    C:\WINDOWS\sideb.exe: UPX!
    C:\WINDOWS\tsc.exe: UPX!
    C:\WINDOWS\vsapi32.dll: UPX!t4


    Thanks again,
    Gary...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I only need the final log from RKfiles. The others are already included in it. I think you need to go back now and run the Qoologic file in the proper account because it did not show the problems last time either. In order to fix all problems we will have to clean all user accounts eventually.

    Also you must remember to exit ALL browsers before running HijackThis. You had two of them open:
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    If you did not have them open, make sure you tell that. Some malware problems can run IE behind your back and I need to know if that is happening.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tiepvdovbu.info/vLnGnhQXR5wqcKWT3Y3igePEYl19ty7469YomO6iFsR8diF3uvIsowCekfsqBn1y.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=?ÃA????
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O4 - HKCU\..\Run: [Book jump] C:\DOCUME~1\Jennifer\APPLIC~1\DEAFBI~1\playplatform.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\DOCUME~1\Jennifer\APPLIC~1\DEAFBI~1\playplatform.exe
    C:\WINDOWS\SYSTEM32\garyoldadlinstallwin32.garyoldexe.garyoldtcf
    C:\WINDOWS\SYSTEM32\sgaryoldew.egaryoldxe
    C:\WINDOWS\axpfins.exe
    C:\WINDOWS\io2uns.exe
    C:\WINDOWS\sideb.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file. If you cannot find or delete any of these, you must remember to tell me which ones.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. firstphantom

    firstphantom Private E-2

    Hi Chaslang,

    I ran all the steps as you recommended and lo and behold, the lop toolbar is gone. I have attached the latest hijackthis log.

    p.s. i see from your profile you are a baseball fan. being from NJ I assume you are a Yankees fan. I hope you dont hold it against me for being a mets fan. <G>

    Thanks again for all you have done,
    gary...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below in your log:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.vgkewdwtthmwbfels.com/vLnGnhQXR5wqcKWT3Y3igePEYl19ty7469YomO6iFsSKmjZQ68WvygCekfsqBn1y.htm

    This is a typical sign of a hidden infection. Sometimes a LOP infection. Did you Reset Web Settings as requested? I did not see www.majorgeeks.com show up as your home page.

    I think the first thing we need to do is follow the steps in the below thread to get better protection on your PC. You are in serious need of an antivirus application and a "real" firewall. The firewall in Win XP SP2 does not provide sufficient protection.

    How to Protect yourself from malware!

    After getting these steps completed post a new HJT log. Make sure you fix the R1 line again and Reset Web Settings again too. Use majorgeeks as your home page at least temporarily until we get this fixed.

    Yes, I'm Yankee fan but I do not hate the Mets.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds