Am Freitag, den 21.08.2009, 11:08 +1000 schrieb Bruce Tulloch:
> Some more information on this...
> 
> Its propgation mode is that it changes sysconst.dcu, and any app compiled and
> subsequently run on a machine which has delphi installed has its sysconst.dcu 
> infected. Fixing is easy, as your original sysconst.dcu is renamed 
> sysconst.bak, 
> so you just switch it back and make the directory non-writable.
> 
> Details at:
> 
> http://www.symantec.com/security_response/writeup.jsp?docid=2009-081816-3934-99
> 
> Cheers, Bruce.
> 
> PS: of course it does not affect Lazarus :-)
> 
> waldo kitty wrote:
> > Martin wrote:
> >> Just something I found:
> >>
> >> http://www.h-online.com/security/Virus-infects-development-environment--/news/114031

In all those decriptions I miss the information on how the manipulated
sysconst.dcu has entered the system. There has to be some transporting
mechanism still undetected.

Does anybody know how the infection works?

-- 
Marc Santhoff <[email protected]>


--
_______________________________________________
Lazarus mailing list
[email protected]
http://lists.lazarus.freepascal.org/mailman/listinfo/lazarus

Reply via email to