• On TV.com: TOP 10 Shows CANCELED Too Soon
August 18, 2009 5:06 PM PDT

New virus infects programs built with Delphi

by Elinor Mills
  • Font size
  • Print
  • 12 comments
Share

Researchers said on Tuesday that they are seeing something unusual in the malware world--a virus that targets a development environment.

The virus, dubbed Win32.Induc, was written to infect applications built with Delphi, according to Nick Bilogorskiy, manager of antivirus researcher at Sonicwall. Delphi is used to write Windows programs, including database applications.

When an infected program is run on a machine running Delphi, the virus infects any software that gets compiled on that machine. The virus spreads the executable file of itself as well as the source code. It looks for a compiler on the infected system and re-compiles the source code, inserting its code into any programs compiled on the system.

"This malware just spreads; it doesn't delete files or do anything malicious," he said. "But if you create software and you have this code in it, the software will be blocked by antivirus (technology)."

Developers whose systems are infected will pass the infection on to the programs they are creating, Bilogorskiy said.

Already, two free tools that are included in certain magazine CDs and are among the top 100 downloads on some portals--Any TV Free 2.41 and Tidy Favorites 4.1--have been infected, he said. "As many as 30 percent of developers who use Delphi have this," he added.

Sonicwall and a number of antivirus vendors have updated their software to block the virus.

Sophos has more details on its SophosLabs blog.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from InSecurity Complex
Defense Dept. pulls software over privacy issues
Microsoft to plug critical IE hole targeted by exploit code
Avast update falsely flags good apps as malware
EFF sues feds for info on social-network surveillance
Fake CDC vaccine e-mail leads to malware
Building circuits, code, community at Noisebridge hacker space
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
Add a Comment (Log in or register) (12 Comments)
  • prev
  • 1
  • next
by SIGHUP August 18, 2009 5:25 PM PDT
All version?
Reply to this comment
by monkeyfun14 August 18, 2009 5:28 PM PDT
Okay so it does nothing? You know tbh the developers goal was probably to get the file blocked by AV's so the programs it infects won't run
That's the damage.
Reply to this comment
by tektaktyks August 18, 2009 5:57 PM PDT
please,we all know that apple is writing those so they can claim they have better os...
Reply to this comment
by baconstang August 18, 2009 9:16 PM PDT
Dude, you are clinical.
by Dalkorian August 19, 2009 11:06 AM PDT
LOL! Thanks tektaktyks, that was really funny!
by benjwah August 18, 2009 9:02 PM PDT
I thought Delphi died out years ago.
Reply to this comment
by j0nnysmith August 19, 2009 2:33 AM PDT
Me to but it s a good program I learn it in High school nice in any case the av I have don t let it make a mass Bitdefender 2010 because I upgraded it so it a all good when it s all safe people;) I m curios to run one more time Delphi now;))
by BruceMcGee August 21, 2009 12:29 PM PDT
Not so much. It's still pretty widely used.
by Ted Miller August 19, 2009 9:12 AM PDT
From CNet there are to good programs that Sophos picked on that where indeed false positives. Both from the same vender. One is "Wise Disk Cleaner" and the other is "Wise Registry Cleaner". I believe that both of these programs are fine, and had "so, so" reviews by CNet (3.5 Stars).

First, I would like to say that I think Sophos is a very good anti virus, but they like many others become what you can call analware, because the two programs that I mentioned where not the only false positives that I recieved from them. There where indeed many others, as I am a major collector of software. I really think that many of these antvirus utilities should work a littlle harder to correctly identify what is and what is not a virus. Especially those that take your money for their services.
Reply to this comment
by RichardCohen_Sophos August 19, 2009 10:01 AM PDT
Ted, if you think there's an FP then please send us a sample via https://secure.sophos.com/support/samples. However I've just done a quick check and we do have copies of both of those products that *are* infected with W32/Induc-A - if you run them on a system with Delphi installed, then you *will* get infected.

http://www.sophos.com/blogs/gc/g/2009/08/19/w32induca-spread-delphi-software-houses/ talks about this some more - if you find W32/Induc-A in a file from a 3rd party, you should speak to the developers to help them stop spreading the virus.
by StuartClennett August 21, 2009 12:09 PM PDT
The article neglects to mention that it only affects Delphi up to version 7. We are now on Delphi 2009 (v12) with 2010 (v13) just around the corner. So my guess is the majority of infections will be with those that haven't been able to afford the upgrade, hence shareware and freeware writers.

And for the uninformed that think the *only* development environment is Visual Studio, check out this link:

http://delphi.wikia.com/wiki/Good_Quality_Applications_Built_With_Delphi

Peace.

Stu
Reply to this comment
by Former Big Iron Guy August 23, 2009 7:25 PM PDT
Unfortunately, there are a heck of a lot of legacy Delphi applications still in production in versions 7 and prior. I see this most often in small Delphi shops where the compiler system was used to build corporate applications that could not be purchased anywhere, off-the-shelf. The compilers live in the developer environment and may even have source repositories. The repositories as well as the developer workstations are often run at administrator levels, which is a normal development requirement, but leave the workstation open to being infected.
Hopefully, corporate strength security will prevent problems in such shops, but don't hold your breath.

Been there, had it done to me.
(12 Comments)
  • prev
  • 1
  • next
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About InSecurity Complex

Elinor Mills became fascinated with hacker culture when she was sent to Las Vegas to cover DefCon in 1995. Since then, script kiddies have given way to cyber criminals targeting bank passwords, and privacy risks are everywhere, from Google to Facebook and the iPhone. InSecurity Complex keeps tabs on the flaws, the foibles, and the fixes.

Add this feed to your online news reader

InSecurity Complex topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right