Am Freitag, den 21.08.2009, 11:08 +1000 schrieb Bruce Tulloch: > Some more information on this... > > Its propgation mode is that it changes sysconst.dcu, and any app compiled and > subsequently run on a machine which has delphi installed has its sysconst.dcu > infected. Fixing is easy, as your original sysconst.dcu is renamed > sysconst.bak, > so you just switch it back and make the directory non-writable. > > Details at: > > http://www.symantec.com/security_response/writeup.jsp?docid=2009-081816-3934-99 > > Cheers, Bruce. > > PS: of course it does not affect Lazarus :-) > > waldo kitty wrote: > > Martin wrote: > >> Just something I found: > >> > >> http://www.h-online.com/security/Virus-infects-development-environment--/news/114031
In all those decriptions I miss the information on how the manipulated sysconst.dcu has entered the system. There has to be some transporting mechanism still undetected. Does anybody know how the infection works? -- Marc Santhoff <[email protected]> -- _______________________________________________ Lazarus mailing list [email protected] http://lists.lazarus.freepascal.org/mailman/listinfo/lazarus
