Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 29th, 2002, 10:44 PM
Digiti Digiti is offline
Infrequent Poster
 
Join Date: Feb 2002
Posts: 39
Default lop.com exploit?

Does anyone know how the lop.com intrusion takes over your browser and toolbar etc.? I have been hearing that a visit to that url. has dire consequences. In fact, a scan with AD-AWARE showed reg. key for lop.com on my system as well. Thanks.
  #2  
Old March 30th, 2002, 12:16 AM
SmackDown
 
Posts: n/a
Default Re: lop.com exploit?

I just went there and found nothing, I ran Ad-aware, and it also found nothing.
  #3  
Old March 30th, 2002, 09:42 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,138
Default Re: lop.com exploit?

I went there, too - nothing. Even clicked on the 'Extreme Adult' link - nada.

Of course, IE-SPYAD automatically put the whole place into the IE 'Restricted' zone to start with! ( <G> ) Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #4  
Old March 31st, 2002, 08:44 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,226
Default Re: lop.com exploit?

Quote:
I went there, too - nothing. Even clicked on the 'Extreme Adult' link - nada.
Does your mother know where you go at night?

Quote:
Of course, IE-SPYAD automatically put the whole place into the IE 'Restricted' zone to start with! ( <G> ) Pete
I know nothing about this program. *Would you care to elucidate?
__________________
My Novel
  #5  
Old March 31st, 2002, 10:19 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,138
Default Re: lop.com exploit?

I'll tell you about it, too! ( <g> )

Short excerpt from this page: http://www.staff.uiuc.edu/~ehowes/resource.htm :

"IE-SPYAD is a Registry file (IE-ADS.REG) that adds a long list of known ad/spy servers and domains to the "Restricted Zone" of Internet Explorer. Once IE-ADS.REG is "merged" into your Registry, most ad/spy servers will not be able to resort to the usual "tricks" (e.g., cookies, scripts, popups, et al) that they use in order to track and monitor your behavior while you surf the Net.

Please note that IE-ADS.REG will NOT block banner ads in Internet Explorer (though it will stop script-based popups). This list of known ad/spy servers and domains merely blocks the cookies typically attached to banner ads. It also prevents the use of ActiveX, Java, and scripting -- active content technologies that can be used to compromise your privacy and security -- by the servers and domains specified in IE-ADS.REG.

This "Restricted Zone" list is based on info from the latest HOSTS file of Stephen Martin (http://www.smartin-designs.com/ )."

And (very important) : " After you merge IE-ADS.REG into the Registry, make sure that your settings for the "Restricted Zone" in Internet Explorer are configured for maximum paranoia (i.e., set everything to "Disable" or "Prompt")."

Only works for IE, but it does work with IE6.0 Pete

__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #6  
Old March 31st, 2002, 10:28 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,138
Default Re: lop.com exploit?

Also, M Healan's post in this thread: http://www.lavasoft.de/cgi-bin/forums/ikonboard.cgi?act=ST;f=5;t=173;hl=lop.com gives removal instructions, tips if you've been 'infected' by lop.com. *Pete

*See dcinotti's post to that thread, as well.
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #7  
Old March 31st, 2002, 01:48 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re: lop.com exploit?

I also found this in several newsgroup threads:

"Here's why that *** thing stuck around after I'd already killed the Run key that called it:

It also copies a Web page to your Wallpaper folder, which calles the Flash movie that runs that friggin' bar, and changes your current Background to this Web page. You don't think to check because it preserves whatever wallpaper you were currently using.

So, to rip it out by hand, not only do you need to zap the Run key above (and I wish I'd kept better notes when I was doing this so I could post exactly what the key was...at the time I just wanted this OUT...maybe someone can find it and point it out to the class), but you ALSO need to change your wallpaper back to whatever you were using (you'll note it's currently set to "desktop" with an IE icon next to it in Desktop Properties > Desktop, and delete the desktop.htm and desktop.swf files that are in your C:\Windows\Web\Wallpaper folder. It'll go away once you change the wallpaper back, but I recomment destroying all traces of it and rebooting to make sure it's gone."


Cheers,
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #8  
Old March 31st, 2002, 02:55 PM
Digiti Digiti is offline
Infrequent Poster
 
Join Date: Feb 2002
Posts: 39
Default Re: lop.com exploit?

Just to let you know, I first heard about lop.com from a techtv broadcast with Chris Pirillo called "Call for Help".It has been showing up in threads on several security forums as well. Evidently it is getting very dangerous out there on the web.
  #9  
Old March 31st, 2002, 03:12 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re: lop.com exploit?

Well, *I wouldn't exactly call it *'dangerous' , *but it still is a scourge.

Take a look at these newsgroup threads... :-/
__________________
Tony < > CLSID List - A Collection of Autostart Locations
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:02 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums