Chinese Internet Security Response Team (GMT +0800)

Induc Virus

[Post on : August 20, 2009 09:13 | Category : Virus | by : smallmo] Reship : Original

I saw many anti-virus vendors reported Win32/Induc together today.

According to Symantec's description:
Quotation
This threat attempts to infect Delphi files during the compilation process. It does this by placing an infection routine in the following file:
[DELPHI INSTALLATION FOLDER]\source\rtl\sys\SysConsts.dcu


The vendors reports:

1. Symantec: W32.Induc.A

2. McAfee: Induc Virus Abuses Delphi Compiler

3. Kaspersky: Induc, the innovative file infector

4. ESET: The Retro-Virus

5. Sophos: W32/Induc-A virus being spread by Delphi software houses

6. Kingsoft Duba: Delphi民工的梦魇!