W32/Induc-A virus infects Delphi sysconst.dcu

Discuss and announce Total Commander plugins, addons and other useful tools here, both their usage and their development.

Moderators: Stefan2, white, sheep, Hacker

User avatar
JohnFredC
Power Member
Power Member
Posts: 886
Joined: 2003-03-14, 13:37 UTC
Location: Sarasota Florida

W32/Induc-A virus infects Delphi sysconst.dcu

Post by *JohnFredC » 2009-08-19, 02:44 UTC

I accidently ran across this article today and just for the h*** of it scanned my Delphi 5 folder.

Lo and behold, there it was. Instant panic mode, but luckily none of my compiled executables had been infected yet, so nothing bad has left my shop.

Virus scanned all my volumes and found it in two products: 3DImageCommander and IconCommander.

Heads up everyone. A good reason to do a complete virus scan more frequently. My Delphi must have been infected before the virus hit the Avast! database.
Licensed, Mouse-Centric, moving (slowly) toward Touch-centric

User avatar
ZeLen1y
Junior Member
Junior Member
Posts: 35
Joined: 2009-06-27, 09:05 UTC

Post by *ZeLen1y » 2009-08-19, 04:58 UTC

Plugins infected in my tc folder :roll:
· ICLRead 1.4.wcx
· ICLView 5.5.2009.wlx

User avatar
fenix_productions
Power Member
Power Member
Posts: 1953
Joined: 2005-08-07, 13:23 UTC
Location: Poland
Contact:

Post by *fenix_productions » 2009-08-19, 08:07 UTC

2ZeLen1y
I think it's a false alarm in your case. These plugins do not seem to be written in Delphi.

I've checked with few tools and each one of them reports UPX so this is rather old "stupid antivirus software" case.
"When we created the poke, we thought it would be cool to have a feature without any specific purpose." Facebook...

#128099

User avatar
ZeLen1y
Junior Member
Junior Member
Posts: 35
Joined: 2009-06-27, 09:05 UTC

Post by *ZeLen1y » 2009-08-19, 09:55 UTC


User avatar
karlchen
Power Member
Power Member
Posts: 4553
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen » 2009-08-19, 10:40 UTC

Hi, folks.

With respect to the download files wcx_ICLRead_1.4.1.zip and wlx_ICLView_5.5.2009.zip:
+ Kaspersky Online File Scan considers them both clean (today 12:30 METDST)
+ Our Symantec AV 10.1.5, definitions: 17.08.2009 considers them both clean.

Either of two assumptions will be true very likely:
  • Kaspersky and our Symantec AV are both wrong and they files are infected.
  • Kaspersky and Symantec are right, the files are clean. All those considering them infected have implemented their detection patterns for W32/Induc too carelessly.
Time will tell which of the two assumptions is right and which one is wrong.

Kind regards,
Karl

User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 37374
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Post by *ghisler(Author) » 2009-08-19, 10:52 UTC

Thanks for the warning, I will inform the developer of these plugins, and the webmaster of wincmd.ru.

Btw, Total Commander itself isn't in danger - it's written in Delphi 2, which isn't affected by the virus. I didn't have any infected plugins installed either, only older versions.
Author of Total Commander
http://www.ghisler.com

User avatar
DrShark
Power Member
Power Member
Posts: 1265
Joined: 2006-11-03, 22:26 UTC
Location: Kyiv, 68/262

Post by *DrShark » 2009-08-19, 15:39 UTC

CopyToTabs and Tc_But_Exe TC addons and Mover.wcx are infected too. These files can be successfully treated by Kaspersky with latest virus bases.
Android 4.3.1 no root, kernel 08.09.2016; Vista Home Premium SP2 rus 32 bit
TC #149847 Personal licence

Cuz we're all in this together, We're here to make it right

User avatar
karlchen
Power Member
Power Member
Posts: 4553
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen » 2009-08-19, 15:48 UTC

DrShark wrote:CopyToTabs and Tc_But_Exe TC addons and Mover.wcx are infected too.
Tested and confirmed! :shock:

Karl

User avatar
Boofo
Power Member
Power Member
Posts: 1431
Joined: 2003-02-11, 00:29 UTC
Location: Des Moines, IA (USA)
Contact:

Post by *Boofo » 2009-08-19, 16:03 UTC

2ZeLen1y
I run Symantec and have gotten no such errors.
chmod a+x /bin/laden -- Allows anyone the permission to execute /bin/laden

How do I un-overwrite all my data?

User of Total Commander
#60471 Single user license

User avatar
Horst.Epp
Power Member
Power Member
Posts: 3338
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Post by *Horst.Epp » 2009-08-19, 17:06 UTC

Boofo wrote:2ZeLen1y
I run Symantec and have gotten no such errors.
Kapersky ist not alone.
Avira Antivir finds it and also Sophos.
So don't wait until your Symantex finds it to.

User avatar
DrShark
Power Member
Power Member
Posts: 1265
Joined: 2006-11-03, 22:26 UTC
Location: Kyiv, 68/262

Post by *DrShark » 2009-08-19, 17:25 UTC

Uploaded files treated by Kaspersky:
http://www.multiupload.com/24CLO0IRS4
(mover.wcx from link above; CopyToTabs 4.2.6.5 and 5.0; TC_But_Exe)
http://www.multiupload.com/92ZK0UJY67
(CopyToTabs 5.5)
But its still recommend to wait for official updates from plugin & addon authors.
Android 4.3.1 no root, kernel 08.09.2016; Vista Home Premium SP2 rus 32 bit
TC #149847 Personal licence

Cuz we're all in this together, We're here to make it right

User avatar
fenix_productions
Power Member
Power Member
Posts: 1953
Joined: 2005-08-07, 13:23 UTC
Location: Poland
Contact:

Post by *fenix_productions » 2009-08-19, 19:09 UTC

ZeLen1y wrote:2fenix_productions
You think that Nod, DrWeb, Kaspersky or Symantec are "stupid antivirus software" ? :shock:
Yes. I consider each antivirus as stupid if it says that something is infected just because it is UPXed. I saw many threads on many boards about "infected" UPX. Even Wikipedia has some information about it.

It is also stupid the way I saw for few applications (i.e. Kaspersky):
- something is considered as dangerous,
- notice authors about false alert to get updated database,
- few updates later reported entry is removed and the same executable is "bad" once again.

There are no other words to name it.
"When we created the poke, we thought it would be cool to have a feature without any specific purpose." Facebook...

#128099

User avatar
karlchen
Power Member
Power Member
Posts: 4553
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen » 2009-08-19, 20:46 UTC

Enumerating the mistakes which AV producers have made and will make - there is no perfect AV product around - will not help preventing W32/Induc from spreading in the wild.

The point is that Delphi developers (Delphi v4 and higher) may be unknowingly distributing an infected Delphi unit inside everything they compile and link. (cf. Sophos on W32/Induc-A, Virus infects development environment)

No need to panic, but a good reason
+ to update the AV definition files and do a full system scan
+ to upload any download to Virustotal first in the near future
+ keep in mind that there is not the one-and-only AV product which will always be right


Kind regards,
Karl
--
<edit>
only changed some formatting details to emphasize the important details
</edit>
Last edited by karlchen on 2009-08-20, 08:53 UTC, edited 1 time in total.

User avatar
Boofo
Power Member
Power Member
Posts: 1431
Joined: 2003-02-11, 00:29 UTC
Location: Des Moines, IA (USA)
Contact:

Post by *Boofo » 2009-08-19, 22:26 UTC

DrShark wrote:Uploaded files treated by Kaspersky:
http://www.multiupload.com/24CLO0IRS4
(mover.wcx from link above; CopyToTabs 4.2.6.5 and 5.0; TC_But_Exe)
http://www.multiupload.com/92ZK0UJY67
(CopyToTabs 5.5)
But its still recommend to wait for official updates from plugin & addon authors.
I'm not getting either one of those links to load. All I get is a white page.
chmod a+x /bin/laden -- Allows anyone the permission to execute /bin/laden

How do I un-overwrite all my data?

User of Total Commander
#60471 Single user license

ouzoWTF
Junior Member
Junior Member
Posts: 93
Joined: 2009-04-20, 21:03 UTC

Post by *ouzoWTF » 2009-08-20, 00:14 UTC

DrShark wrote:CopyToTabs and Tc_But_Exe TC addons and Mover.wcx are infected too.
Not confirmed with latest avira personal.
Single User Licence #201763

Post Reply