TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_DLDER.A
Overview

Malware type: Trojan

Aliases: Backdoor.Win32.WinShell.50 (Kaspersky), BackDoor-TC.gen (McAfee), Backdoor.Winshell (Symantec), HEUR/Malware (Avira), Troj/Winshell-A (Sophos), Backdoor:Win32/Winshell.G (Microsoft)

In the wild: No

Destructive: No

Language: English

Platform: Windows

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

Low

Description: 

This Trojan arrives disguised as adware and is known to have been contained in older versions of popular file-sharing utilities, like Grokster 1.3.3, LimeWire 2.0.2, and a version of Kazaa. This malware sends out user information to a certain Web site, including IP address, default Web browser, and visited sites.

During setup of the specified versions of these file-sharing utilities, users are prompted for the installation of this Trojan. However, even if a user selects NOT to install the diguised Trojan, installation continues in the background.

This Trojan connects to a certain Web site and downloads and another component, which sends the stolen information. By regularly downloading the component via the same site, this Trojan updates its component regularly.

Note: At this time of writing, downloadable versions of Grokster, LimeWire, and Kazaa do NOT contain this Trojan.

For additional information about this threat, see:
Solution
Technical Details

Description created: Dec. 27, 2001 5:18:22 PM GMT -0800
Description updated: Dec. 2, 2002 11:28:48 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.