Bearshare, LimeWire, Kazaa, Grokster, Net2Phone, BonziBuddy users: TROJAN VIRUS WARNING!

gsaldivar

Diamond Member
Apr 30, 2001
8,691
1
81
I'm posting this to try to alert some people out there to a new trojan virus which is installed *with* the following software:
- Bearshare 2.4.0 Beta 7
- LimeWire 2.02
- Kazaa (unspecified versions)
- Grokster 1.33
- Net2Phone (unspecified versions)
- BonziBUDDY (unspecified versions)


Here is what is known so far:

These software packages are bundled with an infected adware installer called "ClickTillUWin", which carries the "backdoor.trojan" or "W32.DlDer.Trojan".

This virus is a relatively new one, and as of today (12/30/01) the following virus scanners will NOT detect this virus:
- McAfee

Here are the virus scanners which WILL detect this virus:
- Norton Antivirus (latest virus definitions ONLY!)
- TrendMicro online


Here is a description of the trojan:
This trojan is a Visual C++ compiled program. Upon execution it drops a file named DLDER.EXE under the %windows% directory. After modifying the registry, the trojan connects to the site www.2001-007.com and and provides the user's IP address and default browser. It then sends an incrementing integer that possibly indicates the number of infected computers.

Upon installation of these file-sharing programs, TROJ_DLDER.A is also installed on the computer without the user?s knowledge. Aside from the file DLDER.EXE in the %windows% folder, a hidden folder named "explorer" is also created in the %windows% folder. The hidden folder contains a file named EXPLORER.EXE. (more)


I hope I don't get flamed for posting a virus warning here, but I thought it would be a good idea given the number of affected software packages involved here.

Please check out these links for more discussion of this virus:

Anandtech Discussion
Anandtech Discussion #2
Anandtech Discussion #3
BearShare.net Discussion
LimeWire Discussion (scroll to bottom)
DSLReports Discussion
DSLReports Discussion #2
 

Dreadogg

Golden Member
Mar 1, 2001
1,780
0
76
ring ring ring we have a winner click2youwin it was bundled with net2phone for me I downloaded it chrismaseve and remember seeing it . Thank you so much I've been pulling my hair out tring to figure this out .
 

Ark

Senior member
Oct 9, 1999
872
0
0
Norton Antivirus users: you must have Dec. 29 definition,
Dec 27 definition does not work.
 

MuK107

Senior member
Dec 30, 2001
270
0
0
i have macafee is there anyway to detect the viris with it. do they know about it?
 

Dreadogg

Golden Member
Mar 1, 2001
1,780
0
76


<< i have macafee is there anyway to detect the viris with it. do they know about it? >>


the links that he left in the first post will show you the way to look in your regestry and find it yourself if you have it! I'm sure mcaffee will be adding it to thier definitions sooner or later ! well I'm still interested to see if more people have been infected with this little rascale !
 

Dasterdly

Member
Oct 27, 1999
140
0
0
It means you have to manually clean it or repartition/reformat/re-install. Most antivirus sites have information pages about whatever virus you have with instructions on what you should do.
 

sabrownfl

Member
Jul 6, 2000
113
0
0
I just installed Limewire 1.7c version. Am I safe? I don' t find any of the referenced files on my 'puter so I am hoping I am clean.

I just wanted to know if Limewire contains spyware. Did they add it to the newest versions? I get no ads, but the damn install program put a link to that f****** BonziBuddy on my desktop which was promptly deleted!

sabrownfl