Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > LimeWire+WireShare (Cross-platform) > Open Discussion topics
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

Open Discussion topics Discuss the time of day, whatever you want to. This is the hangout area. If you have LimeWire problems, post them here too.


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old January 4th, 2002
Unregistered
Guest
 
Posts: n/a
Angry Very important: Limewire installs Trojan!!!

Those *******s of Limewire install a Trojan in your computer!!!
Information below taken from Symantec:

Ver

W32.DlDer.Trojan
Discovered on: December 27, 2001
Last Updated on: January 2, 2002 at 12:46:44 PM PST


Printer-friendly version Tell a Friend

W32.DlDer.Trojan is a Trojan which has two components that work together: Dlder.exe (40,960 bytes) and Explorer.exe (31,232 bytes), which is downloaded by Dlder.exe.

NOTE: Definitions dated before December 29, 2001, detect this as Backdoor.Trojan.


Also Known As: Trojan.Win32.DlDer

Type: Trojan Horse

Virus Definitions: December 29, 2001

Threat Assessment:


Wild:
Low Damage:
Low Distribution:
Low



Technical description:

This Trojan is known to be installed (as part of the normal installation) by two "freeware" file-sharing programs:

Grokster, which is a file sharing system.
Limeware, which is the LimeWire Gnutella Client.

During the installation process of these programs, you are asked if you want to install the (spyware) program "Clicktilluwin." Regardless of whether you click Yes or No, the Trojan code is installed.

This Trojan has two components:
Explorer.exe, which is the main Trojan.
Dlder.exe, which is the downloader for Explorer.exe.

The Trojan creates the hidden folder \Explorer in the \Windows folder, and then downloads Explorer.exe to that folder. The Trojan also copies Dlder.exe to the \Windows folder.

NOTE: Do not confuse the Trojan, which is copied as \Windows\Explorer\Explorer.exe, with the real Windows Explorer file, which is also named Explorer.exe. The genuine file is, by default, in stored in the \Windows folder, not the \Windows\Explorer\ folder. The Trojan creates the \Explorer folder under the Windows folder, and places the Trojan there.

The Trojan also adds one of the following values:

dlder C:\windows\explorer\Explorer.exe

dlder C:\windows\dlder.exe

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run

so that it runs each time that you start Windows.

The Trojan appears to be sending some information (such User-ID and IP address) to the following URL:

http:/ /www.2001-007.com


Removal instructions:

To remove this Trojan, delete files that are detected as W32.DlDer.Trojan, and remove the value that it added to the registry.

To remove the Trojan:

1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.DlDer.Trojan.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.

1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run

4. In the right pane, delete any of the following values that exist:

dlder C:\windows\explorer\Explorer.exe

dlder C:\windows\dlder.exe

5. Navigate to and delete the following subkey:

HKEY_LOCAL_MACHINE\Software\Games\Clicktilluwin

6. Click Registry, and then click Exit.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
LimeWire Installs Correctly, But Does Not Run HelpMePleaseMan Windows 4 August 27th, 2006 08:51 AM
Limewire installs, but does not run agreendevil Getting Started Using LimeWire + WireShare 0 August 3rd, 2006 02:31 PM
limewire installs in a different language barfish Windows 6 June 4th, 2006 10:03 AM
Limewire 2.3.4 Installs SPYWARE Unregistered General Windows Support 3 May 2nd, 2002 05:07 PM


All times are GMT -7. The time now is 10:05 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.