LOP Toolbar

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Frogo, Oct 25, 2004.

  1. Frogo

    Frogo Private E-2

    Hi guys,

    Im having a problem with this LOP toolbar (when I right click it and click properties it says http://lop.com/passthrough/newpass2.html), ever since I installed MSN Messenger Plus 3, and didnt look properly when installing that. *fwaps head* :( . I uninstalled it the day after, but obviously some stuff has been left behind. Anyway, I've followed the Anti-Spyware guide, going into Safe mode etc. and downloaded and ran Spy Sweeper but the tool bar is still here. I've looked into some stuff on LOP and delete manualing it says to go to Application Data, in there I've found a folder named "InsideMp3PlatformBore", in here are 3 .exe files, "Corn find.exe" , "dumb type.exe", & "extra junk.exe " Now, I've ran Hijackthis and some stuff has shown up , such as the "extra junk.exe. I really need your help, this toolbar is getting really annoying, I used to be able to cope with it, as I could just close it by clicking the "X" box on it, but now it isnt following orders.

    Really appreciate it.
    Phil
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought uninstalling MSN Messenger Plus 3, took care of LOP but I guess not.

    If you have run all the items in the READ ME FIRST thread, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT Version 1.98.2
     
  3. Frogo

    Frogo Private E-2

    Here you go Chaslang, appreciate the help :) .


    Take care,
    Phil
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember that you MUST shutdown ALL browsers BEFORE running HijackThis. You still had IE running.
    C:\Program Files\Internet Explorer\iexplore.exe

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nwfwzdadoxliejdkhueszxk.us/ivG8O8nL3r_jS6IA5_XWPajsCWPAn/VSYfYnJ1TLDe5ZNue9GmfZaWBoKkmrS0Zh.html

    Unless you know what this www.eircom.ie page is, fix the next line too.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eircom.ie/cgi-bin/bvsm/bveircom/mainPage.jsp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://lightertricks.com
    O2 - BHO: (no name) - {6EDD3811-D891-1232-73D7-D9ED2D191BF9} - C:\DOCUME~1\ADMINI~1\APPLIC~1\STOREH~1\freeroad.exe
    O4 - HKLM\..\Run: [platform bore type wma] C:\Documents and Settings\All Users\Application Data\InsideMp3PlatformBore\extra junk.exe
    O4 - HKCU\..\Run: [Inside Site] C:\DOCUME~1\ADMINI~1\APPLIC~1\ENCFOU~1\DATAARMY.exe


    And unless you are absolutely sure you need the below two items, I would fix them too. This is typically recommended everywhere.
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab


    Boot into safe mode and use Windows Explorer to delete:
    C:\DOCUME~1\ADMINI~1\APPLIC~1\STOREH~1\freeroad.exe
    C:\Documents and Settings\All Users\Application Data\InsideMp3PlatformBore\extra junk.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\ENCFOU~1\DATAARMY.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. Frogo

    Frogo Private E-2

    Hi Chaslang,


    Ok, I encountered some stuff when doing what you asked. I went into Safe Mode, and I was able to delete both "C:\DOCUME~1\ADMINI~1\APPLIC~1\STOREH~1\freeroad.exe" and "C:\Documents and Settings\All Users\Application Data\InsideMp3PlatformBore\extra junk.exe", however, when I tryed to delete or even right-click "C:\DOCUME~1\ADMINI~1\APPLIC~1\ENCFOU~1\DATAARMY.exe", I got the error

    "explorer.exe has generated errors and will be closed by Windows. You will need to restart the program"

    Also, in the folder, "EncFourMode", where the DATAARMY.exe was found, there were also 4 other .exe files.
    -dashhole software trans.exe
    -defy cash prgram.exe
    -dkkysdao.exe
    -vroqunzs.exe

    I didn't try to delete those, but they look very suspicious, and also, the 2 other .exe files found in the same folder as extra junk.exe, "corn find.exe" & "dumb type.exe" still remain. However, the LOP toolbar seems to have disappeared, but these other files are just worrying me.

    Any idea to what I should do?
    Take care,
    Phil
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Phil,

    We need to get all of those files deleted. All the files in the directories below (you will have to determine the full name to the path since they are shortened in your HJT log):
    C:\DOCUME~1\ADMINI~1\APPLIC~1\STOREH~1
    C:\Documents and Settings\All Users\Application Data\InsideMp3PlatformBore
    C:\DOCUME~1\ADMINI~1\APPLIC~1\ENCFOU~1

    If you have a problem deleting the directories/files, you will need to hit CTRL-ALT-DEL to bring up Task Manager and select Processes. Then look for any of these processes to be running and end them. Then try deleting the files and directories.

    Also, post a new HJT log attachment.
     
  7. Frogo

    Frogo Private E-2

    Chaslang,

    I booted in Safe Mode, and deleted those 3 folders you mentioned, and had no errors etc. Here is the new HJT log.

    Thanks again for everything,
    Take care,
    Phil
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Phil,

    You're welcome.
    Your log is clean! So I assume you have no more problems now?
     
  9. Frogo

    Frogo Private E-2

    Yup, you assumed right :D . Thanks for everything!

    Really really appreciate it!
    Take care,
    Phil
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. Frogo

    Frogo Private E-2

    Chaslang,

    I've followed all the steps in that link, and I am just in the midst of getting rid of Java, but I do not know where to find the 2 Registry Subkeys, I thought that Hijackthis would show them, but it doesen't. Can you direct me to where I can delete those subkeys?

    Take care,
    Phil
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you are talking about these:
    The registry subkey HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Java VM
    The registry subkey HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ InternetExplorer \ AdvancedOptions \ JAVA_VM

    Use regedit to locate and delete them.
     
  13. Frogo

    Frogo Private E-2

    Oh right, thanks! Installing the new Java as I type.

    Take care,
    Phil
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Happy and safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds