Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 18th, 2009, 04:35 PM
prasid prasid is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 16
Big Grin Now All Delphi Project (EXE) is new threat!!

Hey!
Today I update my NOD32 AV with sig: 4346
After that when I create a exe in delphi then I got superb message!!
NOD32 give me a rest from coding!
http://ploader.net/files/926e43d77af...b9a9c04afb.gif

Anyy solution?

Last edited by prasid : August 18th, 2009 at 04:46 PM.
  #2  
Old August 18th, 2009, 05:18 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,897
Default Re: Now All Delphi Project (EXE) is new threat!!

Hello,

The Win32/Induc.A virus has an interesting characteristic: If it finds Delphi 4-7 on a computer, it adds its code to any new projects created on the computer.

I am guessing that at some point your computer was infected by the virus, which is why you are seeing a report from NOD32 when you try to build an .EXE file.

ESET's virus lab can confirm this if you would like to send them a copy of the file for analysis. Instructions for doing so can be found in ESET Knowledgebase Article # 141, "How to submit virus or potential false positive samples to ESET's labs."

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #3  
Old August 18th, 2009, 05:24 PM
prasid prasid is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 16
Default Re: Now All Delphi Project (EXE) is new threat!!

I already deposit via http://www.eset.eu/support/form
Previously I submit same type issue in this way. Need help immediate otherwise need to uninstall...
  #4  
Old August 18th, 2009, 08:18 PM
Rmuffler's Avatar
Rmuffler Rmuffler is offline
Former Eset Moderator
 
Join Date: Jun 2008
Location: San Diego, CA USA
Posts: 995
Default Re: Now All Delphi Project (EXE) is new threat!!

Hello prasid,

I have sent you a PM asking for your case number.

Thank you,
Richard
  #5  
Old August 19th, 2009, 02:48 AM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Now All Delphi Project (EXE) is new threat!!

Quote:
Originally Posted by prasid
I already deposit via http://www.eset.eu/support/form
Previously I submit same type issue in this way. Need help immediate otherwise need to uninstall...

You should perform a full system scan, remove the virus from source files and then recompile the application so that it no longer contains the virus.
  #6  
Old August 19th, 2009, 03:25 AM
prasid prasid is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 16
Default Re: Now All Delphi Project (EXE) is new threat!!

I already do it!!! Nothing found on my system. I fully deep scan my all drives. Nothing found!!
Where is virus? I can't compile my essential project. Plz help me.
  #7  
Old August 19th, 2009, 08:42 AM
prasid prasid is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 16
Default Re: Now All Delphi Project (EXE) is new threat!!

Can you tell me wht the activity of win32/Induc.A threat?
Problem Solved:
Quote:
The main culprit is sysconst.dcu! I replace sysconst.bak to sysconst.dcu.
Which is basically reside on C:\Program Files\Borland\Delphi7\Lib
W32/Induc-A searches computers for installations of Delphi, then attempts to modify SysConst.pas and hence infect SysConst.dcu. The original SysConst.dcu can be restored from the backup made by the virus in SysConst.bak.

Thanks to ESET!!! Still I love v2.7

Last edited by prasid : August 19th, 2009 at 08:59 AM.
  #8  
Old August 19th, 2009, 10:54 AM
danieln's Avatar
danieln danieln is offline
Eset Staff
 
Join Date: Jan 2009
Posts: 112
Default Re: Now All Delphi Project (EXE) is new threat!!

http://www.eset.eu/encyclopaedia/win32-induc-a-virus
http://www.eset.sk/virus/win32-induc-a-virus
  #9  
Old August 20th, 2009, 06:17 AM
stackz stackz is offline
Frequent Poster
 
Join Date: Dec 2007
Posts: 537
Default Re: Now All Delphi Project (EXE) is new threat!!

Quote:
W32/Induc-A searches computers for installations of Delphi, then attempts to modify SysConst.pas and hence infect SysConst.dcu. The original SysConst.dcu can be restored from the backup made by the virus in SysConst.bak.

This is certainly one of the kindest and most caring infections I've seen.
  #10  
Old August 20th, 2009, 07:18 AM
Bensec's Avatar
Bensec Bensec is offline
Regular Poster
 
Join Date: Aug 2008
Location: China Changsha
Posts: 177
Default Re: Now All Delphi Project (EXE) is new threat!!

This is a terrible joke for Delphi developers.
I hope Lazarus will not be affected.
__________________
Cheers.
Ben
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:40 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums