<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Check your Delphi’s installation – it may be infected</title>
	<atom:link href="http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/</link>
	<description>A blog about the EurekaLog tool</description>
	<lastBuildDate>Thu, 04 Mar 2010 13:53:07 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Delphi DCU Virus &#8211; SysConst.pas Library Source Injection. Athena Virus?</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-8512</link>
		<dc:creator>Delphi DCU Virus &#8211; SysConst.pas Library Source Injection. Athena Virus?</dc:creator>
		<pubDate>Thu, 04 Mar 2010 13:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-8512</guid>
		<description>[...] the claim it seems &#8211; Bit Defender.Allegedly this piece of malware does the following:It checks registry to see if there are any Delphi installed (it checks only for Delphi 4-7).For each found instance of Delphi: It makes a copy of SysConst.pas file and inject itself into it.It [...]</description>
		<content:encoded><![CDATA[<p>[...] the claim it seems &#8211; Bit Defender.Allegedly this piece of malware does the following:It checks registry to see if there are any Delphi installed (it checks only for Delphi 4-7).For each found instance of Delphi: It makes a copy of SysConst.pas file and inject itself into it.It [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Delphi DCU Virus &#8211; SysConst.pas Library Source Injection. Athena Virus?- The Recursive ISV</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2553</link>
		<dc:creator>Delphi DCU Virus &#8211; SysConst.pas Library Source Injection. Athena Virus?- The Recursive ISV</dc:creator>
		<pubDate>Sun, 06 Sep 2009 10:46:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2553</guid>
		<description>[...] It checks registry to see if there are any Delphi installed (it checks only for Delphi 4-7). [...]</description>
		<content:encoded><![CDATA[<p>[...] It checks registry to see if there are any Delphi installed (it checks only for Delphi 4-7). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2406</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Sun, 30 Aug 2009 18:43:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2406</guid>
		<description>&lt;a href=&quot;http://www.viruslist.com/en/weblog?weblogid=208187832&quot; rel=&quot;nofollow&quot;&gt;Overview and explanations from Kaspersky Lab&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p><a href="http://www.viruslist.com/en/weblog?weblogid=208187832" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.viruslist.com/en/weblog?weblogid=208187832&amp;referer=');">Overview and explanations from Kaspersky Lab</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2276</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Tue, 25 Aug 2009 05:40:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2276</guid>
		<description>I have 2 confirmation on January of 2009 (both on Russian, sorry). So it was over 7 month (mininum).
BTW, cured applications may not work, as CRC-checks will broke after changes by anti-virus.</description>
		<content:encoded><![CDATA[<p>I have 2 confirmation on January of 2009 (both on Russian, sorry). So it was over 7 month (mininum).<br />
BTW, cured applications may not work, as CRC-checks will broke after changes by anti-virus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DDS</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2270</link>
		<dc:creator>DDS</dc:creator>
		<pubDate>Mon, 24 Aug 2009 23:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2270</guid>
		<description>This virus has been in the wild for at least 3 months (I found it in EXEs compiled in May),
Some antiviruses (such as Kaspersky) can remove this virus from infected EXEs. Or you can just re-compile them from sources after disinfecting Delphi.
Also, to disinfect your Delphi, delete SysConst.dcu and then rename SysConst.bak (backup file created by the virus) to SysConst.dcu. That should fix it. No need to reinstall.
Also, make sure to disinfect/recompile any infected applications or your Delphi will get infected again.</description>
		<content:encoded><![CDATA[<p>This virus has been in the wild for at least 3 months (I found it in EXEs compiled in May),<br />
Some antiviruses (such as Kaspersky) can remove this virus from infected EXEs. Or you can just re-compile them from sources after disinfecting Delphi.<br />
Also, to disinfect your Delphi, delete SysConst.dcu and then rename SysConst.bak (backup file created by the virus) to SysConst.dcu. That should fix it. No need to reinstall.<br />
Also, make sure to disinfect/recompile any infected applications or your Delphi will get infected again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2217</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Sat, 22 Aug 2009 08:14:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2217</guid>
		<description>Yes, anti-viruses start detecting this &lt;b&gt;particular&lt;/b&gt; malware little by little. But no one protect you from any other modification of this or other malware of such kind.</description>
		<content:encoded><![CDATA[<p>Yes, anti-viruses start detecting this <b>particular</b> malware little by little. But no one protect you from any other modification of this or other malware of such kind.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rober</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2196</link>
		<dc:creator>Rober</dc:creator>
		<pubDate>Fri, 21 Aug 2009 19:43:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2196</guid>
		<description>Sophos now say they detect both infected executables and infected SysConst.dcu files, so it should be easy to tell if you Delphi installation is affected.

http://www.sophos.com/security/analyses/viruses-and-spyware/w32induca.html
http://www.sophos.com/blogs/sophoslabs/v/post/6195</description>
		<content:encoded><![CDATA[<p>Sophos now say they detect both infected executables and infected SysConst.dcu files, so it should be easy to tell if you Delphi installation is affected.</p>
<p><a href="http://www.sophos.com/security/analyses/viruses-and-spyware/w32induca.html" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.sophos.com/security/analyses/viruses-and-spyware/w32induca.html?referer=');">http://www.sophos.com/security/analyses/viruses-and-spyware/w32induca.html</a><br />
<a href="http://www.sophos.com/blogs/sophoslabs/v/post/6195" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.sophos.com/blogs/sophoslabs/v/post/6195?referer=');">http://www.sophos.com/blogs/sophoslabs/v/post/6195</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Delphi vira alvo de virus &#171; blog do issinho</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2124</link>
		<dc:creator>Delphi vira alvo de virus &#171; blog do issinho</dc:creator>
		<pubDate>Wed, 19 Aug 2009 17:05:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2124</guid>
		<description>[...] Fonte: Viruslist.com, Info online, Eurekalog [...]</description>
		<content:encoded><![CDATA[<p>[...] Fonte: Viruslist.com, Info online, Eurekalog [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carlos H. Cantu Blog &#187; Blog Archive &#187; Virus ataca desenvolvedores Delphi!</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2120</link>
		<dc:creator>Carlos H. Cantu Blog &#187; Blog Archive &#187; Virus ataca desenvolvedores Delphi!</dc:creator>
		<pubDate>Wed, 19 Aug 2009 15:04:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2120</guid>
		<description>[...] Informações detalhadas, inclusive de como remover o &#8220;virus&#8221; podem ser lidas aqui. [...]</description>
		<content:encoded><![CDATA[<p>[...] Informações detalhadas, inclusive de como remover o &#8220;virus&#8221; podem ser lidas aqui. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2114</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Wed, 19 Aug 2009 12:16:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2114</guid>
		<description>&lt;a href=&quot;http://www.virustotal.com/en/analisis/efe51fb1fc6660e76e9f16b0f5f36bd243d86e2a9695767b71255cce3291f397-1250675839&quot; rel=&quot;nofollow&quot;&gt;Here is the current result of scanning by different anti-viruses&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p><a href="http://www.virustotal.com/en/analisis/efe51fb1fc6660e76e9f16b0f5f36bd243d86e2a9695767b71255cce3291f397-1250675839" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.virustotal.com/en/analisis/efe51fb1fc6660e76e9f16b0f5f36bd243d86e2a9695767b71255cce3291f397-1250675839?referer=');">Here is the current result of scanning by different anti-viruses</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virus infecta .dcu de Delphi 4, 5, 6 e 7 &#124; Cesar Romero</title>
		<link>http://blog.eurekalog.com/check-your-delphis-installation-it-may-be-infected/comment-page-1/#comment-2087</link>
		<dc:creator>Virus infecta .dcu de Delphi 4, 5, 6 e 7 &#124; Cesar Romero</dc:creator>
		<pubDate>Tue, 18 Aug 2009 18:45:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eurekalog.com/?p=244#comment-2087</guid>
		<description>[...] http://blog.eurekalog.com/?p=244   Bookmark and Share:  sociallist_03b1ecae_url = &#039;http://www.cesarromero.com.br/virus-infecta-dcu-de-delphi-4-5-6-e-7/&#039;; sociallist_03b1ecae_title = &#039;Virus infecta .dcu de Delphi 4, 5, 6 e 7&#039;; sociallist_03b1ecae_text = &#039;&#039;; sociallist_03b1ecae_tags = &#039;&#039;; [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.eurekalog.com/?p=244" rel="nofollow">http://blog.eurekalog.com/?p=244</a>   Bookmark and Share:  sociallist_03b1ecae_url = &#8216;http://www.cesarromero.com.br/virus-infecta-dcu-de-delphi-4-5-6-e-7/&#8217;; sociallist_03b1ecae_title = &#8216;Virus infecta .dcu de Delphi 4, 5, 6 e 7&#8242;; sociallist_03b1ecae_text = &#8221;; sociallist_03b1ecae_tags = &#8221;; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
