Page 1 of 2 12 LastLast
Results 1 to 10 of 16

Thread: Check your Delphi’s installation – it may be infected

  1. #1

    Check your Delphi’s installation – it may be infected

    The topic says it all, I just saw this post and my heart stop beating for a moment. He says d4-7 and I run d2009 but still. I checked just to make sure. This is nuts man.

    http://blog.eurekalog.com/?p=244

    and

    http://jamiei.com/blog/2009/08/malwa...geting-delphi/

    Sigh!
    Jarrod Davis
    Technical Director @ Piradyne Games

  2. #2
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2

    Re: Check your Delphi’s installation – it may be infected

    Nice shout Jarrod.

    Needless to say, I'm forwarding this to everyone I can think of that uses one of the affected versions.
    :: AthenaOfDelphi :: My Blog :: My Software ::

  3. #3
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2

    Re: Check your Delphi’s installation – it may be infected

    Something else to add... an idea thats been suggested by one of the guys here is to actually go through your installations and set SysConst.pas to be read-only and keep a backup copies of the SysConst (pas and dcu) files... just in case.
    :: AthenaOfDelphi :: My Blog :: My Software ::

  4. #4

    Re: Check your Delphi’s installation – it may be infected

    Is this the only possible files or need other files also be secured?
    Also are delphi version above 7 affected or not?
    http://3das.noeska.com - create adventure games without programming

  5. #5

    Re: Check your Delphi’s installation – it may be infected

    Checked SysConst.dcu in both Delphi versions 6 and 7 and the string “CreateFile(pchar(d+$bak$),0,0,0,3,0,0);” could not be found so I'm safe.

    Hope so!!

    Thanks for the headsUp!!!
    Wake up from the dream and live your life to the full

  6. #6

    Re: Check your Delphi’s installation – it may be infected

    Only the compiled sysconst.dcu is infected, the source code remains unchanged.

    Delphi 2007 and 2009 aren't affected by this.
    If you develop an idiot proof system, the nature develops better idiots.

  7. #7
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2

    Re: Check your Delphi’s installation – it may be infected

    Quote Originally Posted by vgo
    Only the compiled sysconst.dcu is infected, the source code remains unchanged.

    Delphi 2007 and 2009 aren't affected by this.
    From one of the articles:-

    For each founded instance of Delphi:

    1. It makes a copy of SysConst.pas file and inject itself into it.
    2. It compiles new SysConst.pas and places new infected dcu-file into Lib folder.
    The source code is deleted after SysConst is recompiled meaning you can't recover it without extracting it from a backup or the original install files.
    :: AthenaOfDelphi :: My Blog :: My Software ::

  8. #8

    Re: Check your Delphi’s installation – it may be infected

    Quote Originally Posted by Wizard
    Checked SysConst.dcu in both Delphi versions 6 and 7 and the string “CreateFile(pchar(d+$bak$),0,0,0,3,0,0);” could not be found so I'm safe.

    Hope so!!

    Thanks for the headsUp!!!
    Ditto for me too, so it appears I'm safe at work and home...phew!
    cheers,
    Paul

  9. #9

    Re: Check your Delphi’s installation – it may be infected

    I found this on the avast forum:

    http://forum.avast.com/index.php?top...2787#msg402787

    Sigh... i wonder how many Delphi apps made with those versions are infected and on our machines?
    Jarrod Davis
    Technical Director @ Piradyne Games

  10. #10

    Re: Check your Delphi’s installation – it may be infected


    ps: i just checked, i'm not infected
    From brazil (:

    Pascal pownz!

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •