Main Menu
Home
Bookmark
Contact Us



 
Trojan.Win32.Dlder. Viruses Information

Name: Trojan.Win32.Dlder.
Category: Viruses
Description: Details
Trojan.Win32.Dlder.a

This text was written by Alexey Podrezov, F-Secure Corp.
This two-component spyware-Trojan was discovered at the end of December 2001. Once the Trojan is installed on a user's system, it constantly upgrades its main component that connects to the 2001-007.com Web site and reports a user's ID, the Web browser being used and all URLs and all its child windows open. The Trojan violates a user's privacy and opens a security hole in the system by downloading and activating executable files.
This spyware-Trojan is installed with LimeWire, Kazaa and some other software packages along with other spyware. The Trojan is installed even if a user selects not to install any additional components from these packages.
The main Trojan component is an Explorer.exe file that is located in a Windows folder in Explorer subfolder (do not mistake it with the original Windows Explorer.exe). This component is constantly upgraded by the second Trojan component that has the name 'DlDer.exe' and is located in a Windows folder.
The DlDer.exe file, when it is started, downloads an Explorer.exe file from a Web site, and puts it in a WindowsExplorer folder. Then the Trojan creates a start-up key for the Explorer.exe file. Upon the next system restart, the Explorer.exe file is activated, and it creates a start-up key for the DlDer.exe file, and starts to connect to the aforementioned 2001-007.com Web site, reporting a user's ID, Web browser and all URLs visited by a user.
We recommend deleting both Trojan components from an infected system. If these components can't be deleted (locked files), they should be deleted from a pure DOS (in the case of a Windows 9x system), or renamed with different extensions (EXA for example) with immediate system restart (in case of Windows NT/2000/XP system).



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Coca.57
Macro.Word.Mihole
SomeKit.AOS.85
Worm.Linux.Chees
Stahlpla.75
Ache.33
Backdoor.Katien.
Nuke.Awake.600.
Anti-AV.83
Coca.50


 


© 2006-2008 spyware32.com - Privacy Policy