Tech Support banner

Status
Not open for further replies.
1 - 5 of 5 Posts

·
Registered
Joined
·
2 Posts
Discussion Starter · #1 ·
Need some other moderators except SUBs

According to Subs

The lop uninstaller located at Lop Help Section is a security threat.

He (Subs) has lock the thread in another forum and remove my links to the lop uninstaller Click Here Some1 please clarify with him.

In another topic loosin sleep, jgvernonco have pointed out to download the file from Lop Help Section.

So if that link/file is indeed a virus or a security threat why dun some1 remove the link in the thread above.
 

·
Registered
Joined
·
6,574 Posts
Hi benlye.

As I do understand your concern, it's not a common practice at TSF by the security analysts to use tools to remove infections, created by the people who created the infection.

Can you really trust a Lop uninstaller, by the people that stealthly installed lop on the computer in the first place?? Do you really believe ALL the infection will be removed??

Obviously the opinions amongst the security staff differ slightly, but the majority of us will not use a tool created by the author of the infection.
 

·
Registered
Joined
·
2 Posts
Discussion Starter · #3 · (Edited)
You said it is not a common pratice.. then why jgvernonco also pointed out to download and use tha application.


Also how sure are you that all the viruses out in the internet is not written by Anti-virus companies to make money. It might be true and it might not...
 

·
TSF Security Team, Emeritus
Joined
·
6,962 Posts
benlye:

I'm not quite sure I grasp what your asking here. Every Analyst will have a different opinion and way of doing things when they read and run the fix on a hijackthis log. Now I can't speak to the fact on what the other forum does or does not do regarding infections such as LOP. The knowledge I have obtained is through training and doing more logs and research then I dare to put into numbers at all.

I can't account for JG using the LOP removal tool as that was his choice.......but one basic thing to keep in mind......

NEVER..trust a Malware company to remove it's own Malware. Does the tool work?? You bet..but NOT always. Some versions of LOP will fail to be removed completely. That's why we take it out manually. Awhile back...MyPCTools said there tool removed Aurora too. Paper Ghost proved what a crock that was and we still take it out manually as well. So the LOP removal tool does remove LOP most of time...but Sub's is correct and the tool is a security risk.

If you read through what LOP sometimes installs...
http://www.doxdesk.com/parasite/lop.html you should be reluctant to trust in the tool as you can bet it doesn't address this other malware it installed. Now I'm not trying to belittle you in any way...but depending on the LOP removal tool to remove it's own infection seams like a "Quick Fix" method in removing it.

So in conclusion...I personally don't and won't use their own removal tool and we don't teach the use of it in the academy. If you know the history of LOP and C2Media then you would know NOT to trust them or their removal tool to remove this nasty malware from any system.

Several experts have designed great LOP batch files..that will find every entry LOP makes in the system. Once located it's files can removed quickly along with whatever other spyware/adware it may have installed.
 

·
Registered
Joined
·
6,574 Posts
benlye,

I have NOD32 Antivirus installed. When I clicked to download the uninstall tool, I was faced with a NOD32 virus warning.

Upon further investigation from sUBs the following Virus Scanners found the following results:



If this does not satsify your curiosity, I don't knwo what will. In which case - feel free to use the LOP uninstaller - but DO NOT offer such neglegent advice to any member on this forum.

I'd much rather you take our advice and evidence, follow our recommendations, and THANK sUBs for his expert opinion. Afterall, he did have your best interests at heart, and rightly so.

Good day.
 
1 - 5 of 5 Posts
Status
Not open for further replies.
Top