![]() |
Win32.Induc -- using You as malware generator |
Post Reply
|
| Author | |
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Topic: Win32.Induc -- using You as malware generatorPosted: 22 August 2009 at 10:25am |
|
I suspected that for a long time, does the compiled exe increase with the virus?
How many kb? |
|
|
Concentrate on your strengths.
|
|
![]() |
|
ntunldr
Senior Member
Joined: 05 July 2009 Online Status: Offline Posts: 229 |
Post Options
Quote Reply
Posted: 20 August 2009 at 6:29pm |
|
where is SystemPro?
![]() "source" code ripped from "infected" sysconst.dcu is below well actually this is not a virus in pure type of virus definition. the root of infection probably miranda 0.8 plugin
Edited by ntunldr - 20 August 2009 at 6:30pm |
|
![]() |
|
USForce
Senior Member
Joined: 26 October 2007 Location: United States Online Status: Offline Posts: 150 |
Post Options
Quote Reply
Posted: 20 August 2009 at 4:58pm |
|
This is not the first virus that attack compilers and source codes instead of compiled executables
Edited by USForce - 20 August 2009 at 5:00pm |
|
![]() |
|
ntunldr
Senior Member
Joined: 05 July 2009 Online Status: Offline Posts: 229 |
Post Options
Quote Reply
Posted: 20 August 2009 at 2:17pm |
|
very cool but buggy, code suffers with bug that help to find it. I found executables compiled 4-5 month ago infected with that sh*t.
update: seems to be have no effect with Delphi > 7. Edited by ntunldr - 20 August 2009 at 2:22pm |
|
![]() |
|
nullptr
Senior Member
Joined: 06 April 2008 Location: Australia Online Status: Offline Posts: 553 |
Post Options
Quote Reply
Posted: 20 August 2009 at 2:12pm |
|
At least Win32.Induc is kind enough to save the original Sysconst.dcu as SysConst.bak.
|
|
![]() |
|
ntunldr
Senior Member
Joined: 05 July 2009 Online Status: Offline Posts: 229 |
Post Options
Quote Reply
Posted: 20 August 2009 at 1:57pm |
|
zeroday uppon your souls ^_^
It's infecting executables written on Delphi (from 4 version up to 7) and doing this through delphi compiler. So you have Delphi installed and compiles your application. Your application become infected "by design". This affects some popular ICQ programs, file managers. you may even don't know that your totally infected ^_^ it's very small and its very hard to locate in binary. Induc injects itself to sysconst.pas and recompiles it, using the fact that most delphi VCL programs always have sysconst included. infected signature from compiled binary 75 73 65 73 20 77 69 6E 64 6F 77 73 3B 20 76 61 72 20 73 63 3A 61 72 72 61 79 5B 31 2E 2E 32 34 5D 20 6F 66 20 73 74 72 69 6E 67 3D 28 00 you can also play with Delphi IDE registry key: HKLM\Borland\Delphi\x.x @RootDir where x.x - is IDE version, RootDir is registry value name. Using invalid reg entry of RootDir will lead to abnormal termination of program infected by Induc and to nothing with not infected applications. Watch yourself compiling viruses ![]() edit: corrected info about affected delphi versions Edited by ntunldr - 20 August 2009 at 2:43pm |
|
![]() |
|
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |