What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Messenger Plus! for Live Messenger » WLM Plus! Help » Information related to Lop Infection

Information related to Lop Infection
Author: Message:
Midou
New Member
*


Posts: 3
Joined: Nov 2005
O.P. Information related to Lop Infection
I am not sure if my computer has been infected with the most heinious of all spyware/adware/malware programs known as lop. I have installed MSg plus and i am uncertain of what version i installed. Anyways the following is a log file using "Registry Viewer" (www.sysinternals.com). The "Glue Once Blue" reffers to Glue Once Blue.exe which was found in C/Documents and settings/My Name/Application Data/Phone Meet With HijackThis I started the registry viewer up and opened the exe (Hoping that it didnt kill the crap out of my computter)

    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Glue once blue.exe    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat    SUCCESS    0x0   
    Glue once blue.:3816    CloseKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat    SUCCESS    0x0   
    Glue once blue.:3816    CloseKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Session Manager    SUCCESS    Access: 0x1     
Glue once blue.:3816    QueryValue    HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKLM\System\CurrentControlSet\Control\Session Manager    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat    SUCCESS    0x0   
    Glue once blue.:3816    QueryValue    HKLM\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled    SUCCESS    0x0   
Glue once blue.:3816    CloseKey    HKLM\System\CurrentControlSet\Control\Terminal Server    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon    SUCCESS    Access: 0x20019     
Glue once blue.:3816    QueryValue    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LeakTrack    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM    SUCCESS    Access: 0x2000000     
Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\SafeBoot\Option    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers    SUCCESS    Access: 0x1     
Glue once blue.:3816    QueryValue    HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled    SUCCESS    0x1   
    Glue once blue.:3816    CloseKey    HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers    SUCCESS       
    Glue once blue.:3816    OpenKey    HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Error Message Instrument\    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32\Glue once blue    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility\Glue once blue    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows    SUCCESS    Access: 0x20019     
    Glue once blue.:3816    QueryValue    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKLM\SYSTEM\Setup    SUCCESS    Access: 0x1     
    Glue once blue.:3816    QueryValue    HKLM\SYSTEM\Setup\SystemSetupInProgress    SUCCESS    0x0   
    Glue once blue.:3816    CloseKey    HKLM\SYSTEM\Setup    SUCCESS       
    Glue once blue.:3816    OpenKey    HKCU    SUCCESS    Access: 0x2000000     
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Nls\MUILanguages    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKCU\Control Panel\Desktop    SUCCESS    Access: 0x80000000     
    Glue once blue.:3816    QueryValue    HKCU\Control Panel\Desktop\MultiUILanguageId    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKCU\Control Panel\Desktop    SUCCESS       
    Glue once blue.:3816    CloseKey    HKCU    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Nls\MUILanguages    NOT         
    Glue once blue.:3816    OpenKey    HKCU    SUCCESS    Access: 0x2000000     
    Glue once blue.:3816    OpenKey    HKLM\System\CurrentControlSet\Control\Nls\MUILanguages    NOT FOUND       
    Glue once blue.:3816    OpenKey    HKCU\Control Panel\Desktop    SUCCESS    Access: 0x80000000     
    Glue once blue.:3816    QueryValue    HKCU\Control Panel\Desktop\MultiUILanguageId    NOT FOUND       
    Glue once blue.:3816    CloseKey    HKCU\Control Panel\Desktop    SUCCESS       
    Glue once blue.:3816    CloseKey    HKCU    SUCCESS       
    Glue once blue.:3816    OpenKey    HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots    NOT FOUND   

It did not stop there however this is actually a short version of the first actions it did inside the registry.

Now for the question.

Am I infected with a form of Lop as a result of Msg Plus, Or is this another virus unrelated to Msg Plus. If I am infected with Lop I have already read the sticky and plan to use that for removal but I have another question. In removing Msg Plus Outright from my computer will i lose my Display Pics or Is there a way to save them (I am sure there must be a collection of them in a folder somewhere which is where MSN gets them from)

Thank You in advance to anyone who responds.   
11-09-2005 03:23 AM
Profile E-Mail PM Find Quote Report
prashker
Veteran Member
*****


Posts: 5109
Reputation: 104
– / Male / –
Joined: Mar 2005
Status: Away
RE: Information related to Lop Infection
You will not lose your Display Pictures. Just follow what you read to remove the Optional Sponsor
11-09-2005 03:39 AM
Profile PM Find Quote Report
MeEtc
Patchou's look-alike
*****

Avatar
In the Shadow Gallery once again

Posts: 2200
Reputation: 60
38 / Male / Flag
Joined: Nov 2004
Status: Away
RE: Information related to Lop Infection
see This Thread for info on the sponser, and how to remove it safely

This post was edited on 11-09-2005 at 03:42 AM by MeEtc.
[Image: signature/]     [Image: sharing.png]
I cannot hear you. There is a banana in my ear.
11-09-2005 03:42 AM
Profile PM Web Find Quote Report
prashker
Veteran Member
*****


Posts: 5109
Reputation: 104
– / Male / –
Joined: Mar 2005
Status: Away
RE: Information related to Lop Infection
quote:
Originally posted by MeEtc
see This Thread for info on the sponser, and how to remove it safely
quote:
Originally posted by Midou
I have already read the sticky and plan to use that for removal
11-09-2005 03:48 AM
Profile PM Find Quote Report
Midou
New Member
*


Posts: 3
Joined: Nov 2005
O.P. RE: Information related to Lop Infection
Thank you to all who responded...again as for Patchou aka ( C.P. gasp I found out your real name >:D) I think he owes those of us that he tricked per se.. a public apology, if not I might just have to go to Sainte-Dorothee and ask him personally for an apology.

P.S. this wasnt all bad, the good thing that came about through this 2 year battle with what I now know as lop (but had no idea before) is that I have become more computer litterate, especially when dealing with Spyware/Adware/Malware.
11-09-2005 04:09 AM
Profile E-Mail PM Find Quote Report
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
RE: Information related to Lop Infection
Ok firstly his name is no secret. Cyril is his actual name Patchou is his alias and his companies name.

Cyril owes no one an appology. As you see the sponsor is clearly outlined in the installer.

3.0
[Image: mp30092_sponsor.png]

3.25
[Image: mp3_sponsor.png]

3.60
[Image: mp360_sponsor1.gif]


I am getting really annoyed with people who blame all their problems on Plus!. As you see from the 3 different screenshots of 3 different Plus! versions the sponsor is outlined and even more so in the latest version. Now if you installed the sponsor by accident come on now its your own fault right? You don't agree to two license agreements without wondering. But then again some do...

Simply reinstall Messenger Plus! with the sponsor so it will reconfigure it properly, then choose to uninstall it using the Add/Remove programs and select Sponsor Only. If the changes aren't reversed and still suffering from Lop.com try the Lop.com uninstaller that launches the removal of any installed Lop.com products. Located here.
11-09-2005 04:36 AM
Profile E-Mail PM Find Quote Report
Midou
New Member
*


Posts: 3
Joined: Nov 2005
O.P. RE: RE: Information related to Lop Infection

As you see from the 3 different screenshots of 3 different Plus! versions the sponsor is outlined and even more so in the latest version. Now if you installed the sponsor by accident come on now its your own fault right? You don't agree to two license agreements without wondering. But then again some do...

If the changes aren't reversed and still suffering from Lop.com try the Lop.com uninstaller that launches the removal of any installed Lop.com products. Located here.



Aww your tired of people getting mad at patchou, you know what Im tired of, this Cult that is following him around blindly, Do you people even know what C2Media and lop are considered among web circles? there considered the most heinious Spyware/Adware/Malware "Corporation" around. "By using this software, Including any 3rd party software made avaliable in conjuction with this software". Wait a minuite! that means even if you select No thanks I dont want the Program bundled with it you get it anyways. and you see it is BS like that is what has me so angry. By  having a selection to say NO I dont want the sponsor program and bundling it anyways is called Misleading. Also, Get an unistall program from Lop.com, are you effing kidding me, do you think im stupid or something. ANY uninstalling program that comes from ANY Company that is a Know Spyware/Adware/Malware vendore should not be trusted. Oh sure it will uninstall Lop and it will install some other variant of its program or programs. Of course you will fight till the end of time over patchou's innocence, Because you are a beta tester, and I bet you get a nice cut of Patchou's estimated 50k-100k paycheck every MONTH
11-09-2005 08:53 PM
Profile E-Mail PM Find Quote Report
Rodney
Junior Member
**


Posts: 75
Reputation: 3
34 / Male / Flag
Joined: Dec 2004
RE: Information related to Lop Infection
If you select "No" during installing you will NOT get ANY spyware or adware on your pc. At least not through Msg Plus!, maybe you got it somewhere else, but don't start blaming Plus! for everything that goes wrong on your computer.
11-09-2005 09:29 PM
Profile PM Find Quote Report
Caboose
Full Member
***

Avatar

Posts: 400
Reputation: 14
35 / Male / –
Joined: Oct 2004
RE: Information related to Lop Infection
Midou:

You're a persistent one, aren't you? Do you think Messenger Plus! would have a "cult" if it was a piece of shit? I think not. We're here because we know that it's a fine piece of work.

Don't like the sponsor? Neither do I. But you might want to try that "reading" thing that people do. You know, the thing that stops you from looking like a tool? Yeah, that's the one. Do that and choose the option to not install the sponsor. Like Rodney said...

quote:
If you select "No" during installing you will NOT get ANY spyware or adware on your pc.
Now then. Beta testers getting a cut of Patchou's "paycheck"? I'm pretty sure they do it for free. Stop babbling conspiracy theories.

I'm also pretty sure Patchou doesn't get $50,000 - $100,000 a MONTH. I understand you're mad, but why make yourself look like an ass by spewing random nonsense?

In conclusion... well, I really shouldn't say. I'm probably in shit for this post already, so I'd rather just be quiet now. If you don't like Messenger Plus!, then don't use it. There will always be a strong following no matter what you do.


To the other respectable members/mods/admins reading this, I'm sorry for this post, but it needs to be done to put these kinds of people in their place.
11-09-2005 09:59 PM
Profile E-Mail PM Web Find Quote Report
Patchou
Messenger Plus! Creator
*****

Avatar

Posts: 8607
Reputation: 201
43 / Male / Flag
Joined: Apr 2002
RE: Information related to Lop Infection
You're being ridiculous. Uninstall programs are there to be used. I don't know for other programs you've used before but the unisntall programs distributed by myself and my C2Media (lop) do not install anything when run, they just delete stuff.

As for C2Media being known as bad guys, this is mainly because of rumours that continue to circulate nowadays on forums where people like yourself say this kind of thing without any reason, refering other people of the same kind to support their arguments. If you want to know what really is malware and spyware I suggest you install a Windows XP without service pack, plug it on the net and wait about 10 minutes (just make sure you unplug your phone cord from your modem if you don't want extra charges on your phone biull in addition to a ruined test system).

C2Media is an avertisement company which distributes adware, nothing else and Messenger Plus! gives you a clear choice during installation wether or not you want to install those ads. And one last thing: no-one in the community is paid to help others or beta tests the products and as for your estimated pay check: lol.

This post was edited on 11-09-2005 at 11:25 PM by Patchou.
[Image: signature2.gif]
11-09-2005 11:23 PM
Profile PM Web Find Quote Report
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On