PDA

View Full Version : Trojaned build of DC++ in the wild


View Full Version : Trojaned build of DC++ in the wild


wonderboy2005
January 26th, 2005, 07:38 PM
Trojaned build of DC++ in the wild

Anti-virus company Kapersky Lab has announced that a trojaned version of popular P2P software DC++ has been found in the wild. Several download services, including Download.com have been offering a version which installs malware onto the system.

The trojaned version installs TrojanDownloader.Win32.Istbar.er, Trojan.Win32.Krepper.ag and Trojan.Win32.Agent.ba - all of which are related to installation of AdWare.

The version offered by AfterDawn.com (http://www.afterdawn.com/software/p2p_software/p2p_applications/dcplusplus.cfm) is clean. You can identify the infected version from the proper one from their MD5 sum.

MD5 for clean version: 9041a4c53a30bb45fcd6a81669241045
MD5 for trojaned version: 02ffde276505191525e84cf084cb85e9

According to Kapersky only the installation package of tha latest version, v0.668, is affected. If you have installed that version it is recommended that you check your system using, for example, Ad-Aware (http://dawnload.net/desktop_software/desktop_security/ad-aware.cfm).

After checking your system download the clean version from the following URL:

http://www.afterdawn.com/software/p2p_software/p2p_applications/dcplusplus.cfm

Download.com has removed the listing for DC++.

Source: Kapersky Lab (http://www.viruslist.com/en/weblog?weblogid=158236628)

I (wonderboy) got it from http://www.afterdawn.com/

infringer
January 26th, 2005, 08:28 PM
Yuckkie not cool this is bound and determined to happen I am supprised that there isnt more backdoors reported to these programs... I know that spending all that time developing software and forming a network would definately be a justification that most folks would use for having a backdoor that would provide better bandwith for the programmer making the program...

Some folks just want there cake and eat it too.

-infringer-

xan
January 27th, 2005, 03:45 PM
I know that spending all that time developing software and forming a network would definately be a justification that most folks would use for having a backdoor that would provide better bandwith for the programmer making the program...
That is, in no way, a valid justification for including any kind of remote access in a publicly distributed application.

Let's not forget that DC++ is open source, and easily compiles out of the box. Anyone can (and does constantly) read the source, and there is nothing in it that could remotely qualify as a backdoor. So, please don't confuse unauthorized binary distributors with software developers.

Official response: http://dcplusplus.sourceforge.net/forum/viewtopic.php?t=14815

Mels_Smileys45
January 27th, 2005, 04:18 PM
This will make DC++ the number one download.

moneoa
January 27th, 2005, 04:27 PM
This will make DC++ the number one download.
Hey what works for eXeem....... :devil

infringer
January 27th, 2005, 04:28 PM
I was specifying that this type of thing should not go on I'm all for open source though it dont do me worlds of good there is someone out there who would beable to spot backdoors quite simply...

-infringer-