search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Monday November 23, 2009 8:39 AM AEST
Skip Navigation LinksPC Authority > News > Virus targets Delphi code compiler
Virus targets Delphi code compiler
NEWS

Virus targets Delphi code compiler

by Shaun Nichols  on Aug 24, 2009
A new virus attack is targeting the Delphi code compiler and garnering the attention of security experts..

A new virus attack is targeting the Delphi code compiler and garnering the attention of security experts.

The virus infects a component within the Delphi library folder and disguises itself as a legitimate file.

Rather than attempt to simply install other malicious files onto the host machine, however, the virus uses the compiler itself as a means of spreading. When the host machine compiles programs, the virus inserts lines of malicious code, turning the compiled code into a virus delivery system.

Researchers from Sans, McAfee, BitDefender and F-Secure have all reported and analyzed the virus. So far, the virus has displayed no malicious intents other than replicating itself and no further malware attacks or file downloads have been reported.

Still, the virus is gaining attention from experts to its unusual delivery style, which has managed to infect some high-profile applications. German computer magazine ComputerBild warned readers after discovering that one of the files on a recent issue's free CD insert was found to be infected with the virus.

The infection also appears to be spreading in more nefarious circles, according to Sans researcher Rick Wanner.

"A funny side effect is that in the few days since this virus has been detected in the wild, a number of trojans have been discovered to be affected with the virus," wrote Wanner.

"Obviously they were compiled with an infected Delphi compiler."

Security firm BitDefender said that developers can check for the infection by searching for a file in the Delphi library folder names "SysConst.bak" and then renaming the infected file as "SysConst.dcu" to prevent compiled applications from becoming infected.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Box battle: Telstra takes on TiVo and Foxtel with T-Box trial in Melbourne
It's not quite Foxtel IQ and it's isn't TiVo either. The T-Box lets Telstra users watch movies and TV from the Bigpond site, as well as record and watch digital TV
 
5 More Free Linux Apps You Can't Do Without
More digital Swiss Army knife software, including Linux utilities and tools that are so useful you won't know how you ever did without them
 
Microsoft delivers Office 2010 public beta
Vendor details editions for Office 2010 along with application virtualisation for testing.
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple