Wednesday, September 21, 2011

Soapbox: TBackDoor

Correspondent from New York


Delphi Lovers contacting Induc virus after unsafe downloading
Delphi Lovers often take part in massive file-sharing love of Delphi components. It seems that they could catch a nasty virus on their computer which unwittingly is compiled to their Apps. The Anti-Virus vendor with their ESET antiretroviral therapy & suite detected a virus/malware that is spreading like wild-fire in the Delphi community.


Viral Load
The virus works propagates similar to HIV, via unsafe downloading of illegal software, such as Themida-protected Delphi XE2 keygen, ASPROTECT-Protected files which hide an illegal payload, modified MSI files (such as modified AQTime and FinalBuilder installs), modified Innosetup packages (such as modified TMS setup, double-packaged (CompanyName) setup, modified ShellPlus installer and so on) or nakedly via a ZIP file with unsuspecting infected *.res file which contains the payload (i.e., compile the sources and build EXE, the virus activates when the final cell-membrane is generated).


Diagnosis and Treatment
Many Delphi developers are unaware they have this virus and few Delphi developers take the trouble to get tested. Testing for this virus consists of screening Pascal files to detect this virus. Treatment of this virus consists of highly active anti-retrovial therapy (HAART) consisting of three or more virus scanners (e.g., Norton, BitDefender, Panda) and constantly needing to scan their computers for malware, viruses and malicious software.


Latent Reservoirs
Despite the ability for anti-virus suites to detect such infections, these viruses are able to spread rapidly via file-sharing networks and unsafe downloading.

1 comments:

Michael Bunny said...

I would not use such cracked downloads - everything comes back one day and in-honesty does not pay.