Kazaa and DLDER.exe [Archive] - SpeedGuide.net Broadband Community

View Full Version : Kazaa and DLDER.exe


Needlefreak
02-24-02, 11:35 AM
dlder.exe - An advertising trojan that is installed by Grokster (1.33), Bearshare (2.4.0b7), LimeWire (2.02), Net2Phone (unspecified versions) and KaZaA (unspecified versions). The spyware itself comes from ClickTillUWin.com. Taking the torch from even the worst advertising spyware to date, this one creates a fake Explorer executable and process to hide its activities. More information here. Some antivirus manufacturers have listed this as a virus or trojan horse: TROJ_DLDER.A.

http://cexx.org/adware.htm

I found this on my system the otherday ...Current versions of Tauscan and The Cleaner did not pick it up...This is not a slam on the products but if youve been using them to scan as I have please do a file search for DLDER.exe and Clicktilluwin...I also maks a fake Explorer folder with a Explorer.exe inside..If you are getting repeated attempts from Explorer.exe to access the internet you may have this...Zone alarm stopped all outgoing info...So far seems to be no harm done..

Do you guys and gals think I should have are bank accounts changed??

Brent P

blebs
02-24-02, 10:30 PM
No, I don't think you need to go to that extreme.
Have you got rid of the trojan? If not, let me know and I'll send you the removal program for it. I saved the thing figuring others will need it. :)

Set
02-24-02, 11:28 PM
bleb could i get a copy of that please

blebs
02-24-02, 11:53 PM
Originally posted by settrippen
bleb could i get a copy of that please
On it's way in email. :)

Needlefreak
02-25-02, 01:10 AM
Blebs:
Ive deleted this..

DLDER.exe and it's presence in the registry..
Explorer folder and the fake Explorer.exe
Erased all Kazaa and Clicktilluwin.

One thing I forgot to do was remove the fake Explorer.exe from the Zonealarms programs that are allowed to access internet..So for some time now now the Fake Explorer.Exe has been allowed to access....Thats got me worried bigtime..

Send that removal program this way also please....Thanks ....

Brent P

blebs
02-25-02, 07:25 AM
On it's way in email Needlefreak. :)