Gnutella Forums  

Go Back   Gnutella Forums > Gnutella News and Gnutelliums Forums > General Gnutella / Gnutella Network Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Gnutella / Gnutella Network Discussion For general discussion about Gnutella and the Gnutella network.
For discussion about a specific Gnutella client program, please post in one of the client forums above.


View Poll Results: Which is the best Gnutella client?
Bearshare 8 9.20%
Limewire 23 26.44%
Xolox 20 22.99%
Gnotella 11 12.64%
Gnucleus 12 13.79%
Phex 9 10.34%
Swapnut 0 0%
Mactella 0 0%
Napshare 0 0%
other! 4 4.60%
Voters: 87. You may not vote on this poll

 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #35 (permalink)  
Old January 4th, 2002
Unregistered
Guest
 
Posts: n/a
Angry Limewire installs Trojan!!!

Those *******s of Limewire install a Trojan in your computer!!!
Information below taken from Symantec:

Ver

W32.DlDer.Trojan
Discovered on: December 27, 2001
Last Updated on: January 2, 2002 at 12:46:44 PM PST


Printer-friendly version Tell a Friend

W32.DlDer.Trojan is a Trojan which has two components that work together: Dlder.exe (40,960 bytes) and Explorer.exe (31,232 bytes), which is downloaded by Dlder.exe.

NOTE: Definitions dated before December 29, 2001, detect this as Backdoor.Trojan.


Also Known As: Trojan.Win32.DlDer

Type: Trojan Horse

Virus Definitions: December 29, 2001

Threat Assessment:


Wild:
Low Damage:
Low Distribution:
Low



Technical description:

This Trojan is known to be installed (as part of the normal installation) by two "freeware" file-sharing programs:

Grokster, which is a file sharing system.
Limeware, which is the LimeWire Gnutella Client.

During the installation process of these programs, you are asked if you want to install the (spyware) program "Clicktilluwin." Regardless of whether you click Yes or No, the Trojan code is installed.

This Trojan has two components:
Explorer.exe, which is the main Trojan.
Dlder.exe, which is the downloader for Explorer.exe.

The Trojan creates the hidden folder \Explorer in the \Windows folder, and then downloads Explorer.exe to that folder. The Trojan also copies Dlder.exe to the \Windows folder.

NOTE: Do not confuse the Trojan, which is copied as \Windows\Explorer\Explorer.exe, with the real Windows Explorer file, which is also named Explorer.exe. The genuine file is, by default, in stored in the \Windows folder, not the \Windows\Explorer\ folder. The Trojan creates the \Explorer folder under the Windows folder, and places the Trojan there.

The Trojan also adds one of the following values:

dlder C:\windows\explorer\Explorer.exe

dlder C:\windows\dlder.exe

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run

so that it runs each time that you start Windows.

The Trojan appears to be sending some information (such User-ID and IP address) to the following URL:

http:/ /www.2001-007.com


Removal instructions:

To remove this Trojan, delete files that are detected as W32.DlDer.Trojan, and remove the value that it added to the registry.

To remove the Trojan:

1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.DlDer.Trojan.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.

1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run

4. In the right pane, delete any of the following values that exist:

dlder C:\windows\explorer\Explorer.exe

dlder C:\windows\dlder.exe

5. Navigate to and delete the following subkey:

HKEY_LOCAL_MACHINE\Software\Games\Clicktilluwin

6. Click Registry, and then click Exit.
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Gnutella client name... errorlevel General Gnutella / Gnutella Network Discussion 3 August 2nd, 2002 12:18 PM
How many Gnutella client are there? dimagor General Gnutella / Gnutella Network Discussion 8 May 18th, 2002 05:01 AM
Gnutella itself--not a client Unregistered General Gnutella / Gnutella Network Discussion 3 May 15th, 2002 08:21 AM
DOS Gnutella Client!!! CyberBug84 General Gnutella / Gnutella Network Discussion 10 July 18th, 2001 08:33 AM
The Best Gnutella Client Unregistered General Gnutella / Gnutella Network Discussion 0 July 9th, 2001 06:36 PM


All times are GMT -7. The time now is 09:20 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright Đ 2020 Gnutella Forums.
All Rights Reserved.