Malware City/Blog/

Aug
24
Filed Under:
WEEKLY REVIEW

BitDefender weekly review – Is the Delphi virus harmfull?

24 August 2009
The answer is simple: no. No matter how intuitive (and rather successful) it's spreading method is, this virus does no harm to any of the systems it comes in contact with, besides the actual file infection necessary for proliferation.

Win32.Induc.A

The virus spreads by infecting Delphi development environments (versions 4 through 7). When an infected executable is run, the virus checks the registry for specific Delphi entries and if found, it exacts the version and installation path of the compiler, if the version is supported.

Next it will copy %delphi_install_path%\Source\Rtl\Sys\SysConst.pas to %delphi_install_path%\Lib\SysConst.pas and adds its malicious code to the implementation section of it. The file is compiled which results in an infected SysConst.dcu (Delphi compiled unit). The original SysConst.dcu is copied into SysConst.bak beforehand. The source file (Sysconst.pas) is deleted after compilation.

As SysConst.dcu is included in every compiled file, all of the resulting executables will contain the virus code.

Win32.Induc.A takes no action if the computer doesn't contain any Delphi installation.

 

Trojan.FakeAv.QF

Another rogue security product plagues users this week. Intuitively called Total Security (a play on BitDefender's Total Security products line) the fake antivirus tries to trick users into installing it.

When first run, the malware copies itself to c:\Documents and Settings\All Users\Application Data\[Rnd8]\[Rnd8].exe and executes a batch script to delete the original file.

It makes changes to the registry to ensure it is being executed at every system startup.

Then it start a fake scan of the system, presenting the same hard-coded "infections" to the user regardless of the computers' state.

In order to "clean" the system, the user is forced to pay for the software. The e-threat is randomly closing processes and marks them as infected.

Total Security fake av

 

Information in this article is available courtesy of BitDefender virus researchers: Dana Stanut and Horea Coroiu




Comments:

rent villas said on May-2-2011 03:51

Its a pelasure to read your blog. Thanks for sharing and keep up your nice work.

http://reversephonelookupfree.net/ said on May-26-2011 20:56

I love the dear information you offer in your articles. I can bookmark your weblog and have my friends take a look at up right here generally. I am fairly sure they’ll be told a lot of new stuff right here than any one else!

wedding photography in Lincoln said on May-29-2011 05:05

It's always nice when you can not only be informed, but also entertained! I'm sure you had fun writing this article.I have boon looking everywhere to find the information bout this you know.

free ipad giveaway said on Jun-1-2011 13:15

awesome way to finish an article

Keyword Research Tools said on Oct-3-2011 01:00

This really am a very useful information. It help us identify harmful software that can damage our PC . It's a very impressive review.

no fax payday loans said on Nov-7-2011 01:29


Hi. Great concept. Another informative post. This is a very nice blog that I will definitively come back to several more times this year!

The 5 most advances seo tips said on Nov-9-2011 08:35

Thank you for this informative and helpful article.

The 5 most advances seo tips said on Nov-9-2011 08:35

Thank you for this informative and helpful article.

Comment on this

Name:

Email:

Website:

Your email adress will not be published.