W32/Induc-A searches computers for installations of Delphi, then attempts to temporarily modify SysConst.pas, and compiles this to infect SysConst.dcu. The original SysConst.dcu can be restored from the backup made by the virus in SysConst.bak.So apparently we're talking about Delphi authors who've picked up viruses in the wild with their development machine (surfing porn sites, opening infected e-mail attachments, or running sketchy utilities, I presume), then later on compiled and released software programs on that same machine. I guess there's a lot to be said for keeping development machines disconnected from the network.
Please be aware - this virus isn’t just a threat if you are a software developer who uses Delphi. It’s possible that you are running programs which are written in Delphi on your computers, and they could be affected. Sophos has received thousands of reports of programs infected by W32/Induc-A.So are
Sophos detected more than 3,000 programs infected with the code, including some banking Trojans, suggesting that even cybercriminals have had their computers compromised by the program.So you can strike anything anybody's said about backdoors. My bad.
The W32/Induc-A virus inserts itself into the source code of any Delphi program it finds on an infected computer, and then compiles itself into a finished executable.So the analysts have access to the source of the virus.
It must have gotten this thread as I have tried to comment about a dozen times and MeFi just fails to respond. ;) Not that anyone will ever see this if it continues, but it amuses me to keep trying. I just add a little more each time. I am just talking to myself it seems. I hope it does not get too embarrassing if the thread finally accepts my comment.So, it was probably clean-up, but perhaps too much. We had gobs of comments posted multiple times. Yet, why erase the comments about the problem? That has always been part of the fun of MeFi. JRun, run....
It's still amusing, but starting to get annoying.
I notice no one else is commenting here either. odd.
Maybe if I try a different browser...
posted by caddis at 6:31 PM on August 20 [+] [!]
...
Weee. Now that was fun. All the comments came in at once. It must be the compiler. ;)
posted by caddis at 6:38 PM on August 20 [+] [!]
« Older Joseph Brodsky: In Praise of Boredom -- from his ... | Thank you Miles, but your apot... Newer »
This thread has been archived and is closed to new comments
posted by Lutoslawski at 12:35 PM on August 20