Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Lop Virus after reinstall of OS

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 04-Sep-2008, 07:05 PM
Colloghi's Avatar
Colloghi Colloghi is offline
Registered Member
Posts: 97
Points: 118 Colloghi has over 100 pointsColloghi has over 100 points
Power: 6
None
Join Date: 09 Mar 2006
Location: Barnsley, South Yorks
Age: 29
Certifications: TEFL, A+ 601,
WIP: A+ 602 module
Lop Virus after reinstall of OS

I seem to be having a problem with a computer for a friend. They seem to be getting something called a Lop virus, which seems to change the users page they are viewing, and also leaves traces with the address lop@usersname.com. The virus seems to refuse to go away, even after reinstall.......but im not so sure and feel this may be something to do wiuth whatever the users is viewing or downloading after each install.


The pc is a dell and comes with the Dell windows xp recovery Cds for that system, and ive reinstalled the system twice with this disk. The first time, i was askled to save some files, but to otherwise do a complete reinstall of the system. I done as asked, and reinstalled the system and retrieved the data which needed retrieving and checked the system....it all seemed fine, no viruses as far as my scans showed.

However the virus came back the same, the user this time said they were happy for everything to formatted and the OS recovered. Ive now done this, formatted the system and recovered the OS with the dell disks. Ran AVG, Hijackthis, Adaware, norton, all fine no scans.



Today the user states the same virus is back, although she has assured me that nothing has been downloaded as far as she is aware.

I know others do use this same PC, like her younger son.................is it something being downloaded? or is there a chance the Lop virus is staying in the recovery partition if there is one?


Sorry for the long post

 
Reply With Quote
  #2  
Old 04-Sep-2008, 09:26 PM
zebulebu's Avatar
zebulebu zebulebu is offline
Premium Member
Posts: 2,039
Points: 6109 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 86
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 35
Certifications: A few
WIP: NCDA, VCP
Lop is a nasty bit of adware from C-Media that is often installed with programs like MessengerPlus - the default installation of which comes with Lop as a 'sponsor' program - lots of people install without realising it is filth as the actual MessengerPlus program is pretty useful (I run it meself).

Check the PC out again for anything that has been installed - look for things like ropey-looking toolbars (a dead giveaway). Either they are downloading something that installs it as part of a bundle, or they are going to a particular website that drive-by installs it each time the PC is rebuilt. If they run pop-up blocking software it should help, tell them to use Firefox instead of IE and, most importantly, give them my stock answer in cases like this:

stop looking at pr0n on the Internet

 
Reply With Quote
  #3  
Old 04-Sep-2008, 10:00 PM
postman's Avatar
postman postman is offline
Valued Member
Posts: 172
Points: 167 postman has over 100 pointspostman has over 100 points
Power: 3
None
Join Date: 08 Jun 2008
Location: Northern Ireland
WIP: A+
Quote:
stop looking at pr0n on the Internet
But that's the best part of the internet

 
Reply With Quote
  #4  
Old 05-Sep-2008, 12:32 AM
hbroomhall hbroomhall is offline
Premium Member
Posts: 6,342
Points: 2130 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 90
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
Number one rule here:

After restoring the OS *patch it* using something like Autopatcher (i.e. not on line) and bring the SPs up to date, also not on line.

The install AVG etc and other apps.

Old restore disks can leave a machine vulnerable, and attempting to patch it online can mean a race between nasties and the patches.

Also check the machine before you do this - if there is any P2P apps on it then read the riot act to the owner.

Harry.

 
Reply With Quote
  #5  
Old 14-Sep-2008, 01:38 AM
Colloghi's Avatar
Colloghi Colloghi is offline
Registered Member
Posts: 97
Points: 118 Colloghi has over 100 pointsColloghi has over 100 points
Power: 6
None
Join Date: 09 Mar 2006
Location: Barnsley, South Yorks
Age: 29
Certifications: TEFL, A+ 601,
WIP: A+ 602 module
Thanks for the replies back on this.

just another quick query, could the application Skype? be a means by which the lop is appearing, as I know the users does use that fairly often.

 
Reply With Quote
  #6  
Old 14-Sep-2008, 02:21 AM
zebulebu's Avatar
zebulebu zebulebu is offline
Premium Member
Posts: 2,039
Points: 6109 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 86
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 35
Certifications: A few
WIP: NCDA, VCP
Not unless they are downloading Skype from a malicious source. Like other software, Skype can be provisioned from non-legitimate sources, so its possible (though highly unlikely) that they are getting it that way.

Have you taken my earlier advice? Check Add/Remove programs for Messenger Plus. It is by far the most common attack vector for lop infections in my experience.

 
Reply With Quote
  #7  
Old 06-Oct-2008, 10:43 AM
Norton-Forum-assist Norton-Forum-assist is offline
New Member
Posts: 1
Points: 0 Norton-Forum-assist has no points
Power: 1
None
Join Date: 20 Jun 2008
HI Colloghi,

My name is Peter and I am working for an external European Symantec-Support-Team.
We are sorry to hear about your problem. I have informed the Symantec Support about your issue and they provided us with the following solution:

-Please see: http://www.symantec.com/security_res...421-99&tabid=1

Please try it and let me know if it helped.

Best Regards,
Pete

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
MSN Virus Help zimbo Security & Viruses 15 25-Jan-2008 11:34 AM
News on rootkit virus greenbrucelee Software 6 17-Jan-2008 03:26 PM
Virus could hit WLANs tripwire45 News 1 04-Jan-2008 04:40 PM
New Virus greenbrucelee Software 36 03-Jan-2008 05:56 AM
Virus question greenbrucelee Software 14 23-Dec-2007 08:33 PM


All times are GMT +1. The time now is 03:49 PM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages