[iwar] [fc:Popular.file-share.utilities.contain.Trojans]

From: Fred Cohen (fc@all.net)
Date: 2002-01-04 18:17:17


Return-Path: <sentto-279987-4199-1010197023-fc=all.net@returns.groups.yahoo.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 [204.181.12.215] by localhost with POP3 (fetchmail-5.7.4) for fc@localhost (single-drop); Fri, 04 Jan 2002 18:24:08 -0800 (PST)
Received: (qmail 30300 invoked by uid 510); 5 Jan 2002 02:21:52 -0000
Received: from n5.groups.yahoo.com (216.115.96.55) by all.net with SMTP; 5 Jan 2002 02:21:52 -0000
X-eGroups-Return: sentto-279987-4199-1010197023-fc=all.net@returns.groups.yahoo.com
Received: from [216.115.97.165] by n5.groups.yahoo.com with NNFMP; 05 Jan 2002 02:17:02 -0000
X-Sender: fc@red.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_1_3); 5 Jan 2002 02:17:02 -0000
Received: (qmail 91578 invoked from network); 5 Jan 2002 02:17:02 -0000
Received: from unknown (216.115.97.171) by m11.grp.snv.yahoo.com with QMQP; 5 Jan 2002 02:17:02 -0000
Received: from unknown (HELO red.all.net) (12.232.125.69) by mta3.grp.snv.yahoo.com with SMTP; 5 Jan 2002 02:17:01 -0000
Received: (from fc@localhost) by red.all.net (8.11.2/8.11.2) id g052HHh30079 for iwar@onelist.com; Fri, 4 Jan 2002 18:17:17 -0800
Message-Id: <200201050217.g052HHh30079@red.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL3]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Fri, 4 Jan 2002 18:17:17 -0800 (PST)
Subject: [iwar] [fc:Popular.file-share.utilities.contain.Trojans]
Reply-To: iwar@yahoogroups.com
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit

Popular file-share utilities contain Trojans

By Thomas C Greene, The Register, 1/3/2002
<a href="http://www.theregister.co.uk/content/4/23532.html">http://www.theregister.co.uk/content/4/23532.html>

Popular file-sharing software from Grokster and the Limewire Gnutella
Client contain the W32.DlDer Trojan, Symantec revealed last week. 
According to several Reg readers, the KaZaA utility also contains the
same infection. 
The Trojan here is a spyware application masquerading as a lottery game
called ClickTilUWin. When installing the Grokster or Limewire software,
and some versions of KaZaA, the user is given an option to enable the
ClickTilUWin feature. Regardless of whether one accepts or declines, the
Trojan is installed. 
Grokster has offered an explanation of this embarrassing oversight on
its Web site: 
"Some of you may be wondering why this Trojan was in our installer at
all," the company speculates wisely. 
"We sometimes bundle advertiser applications with our installer in order
to help pay for our costs here at Grokster. We are normally given an
installer from the advertiser which we run during the installation of
Grokster. We have no access to the source code of these third-party
installers and so we rely on what our advertisers say these programs do.
To the best of our knowledge, this particular advertiser simply placed a
link to a free online lottery on the desktop. We were never informed
that it installed or was a Trojan." 
The company has released a utility which it says will remove the Trojan,
and promises to have a clean version of its software available in a
matter of days. 
Those who prefer to see to their own Trojan removal need only search for
a hidden directory under their \Windows directory called \Explorer.
Simply delete the \Windows\Explorer directory, along with the companion
file Dlder.exe in the \Windows directory. 
The Trojan is not destructive, but does phone home to the ClickTilUWin
Web site with user data which, presumably, is used for marketing
purposes, or is perhaps forwarded to RIAA headquarters to assemble a
database of copyright scofflaws. 
We don't know which; but we do know better than to install software we
know nothing about. ®

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Tiny Wireless Camera under $80!
Order Now! FREE VCR Commander!
Click Here - Only 1 Day Left!
http://us.click.yahoo.com/WoOlbB/7.PDAA/ySSFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2002-12-31 02:15:02 PST