All the latest UK technology news, reviews and analysis

Virus targets Delphi code compiler

by Shaun Nichols

21 Aug 2009

Comments: 2

  • Tweet this
Computer virus
A new virus uses the Delphi code compiler to spread

Security experts have warned of a new virus attack targeting the Delphi code compiler. The virus infects a component within the Delphi library folder, and disguises itself as a legitimate file.

Rather than attempt to simply install other malicious files onto the host machine, however, the virus uses the compiler itself as a means of spreading. When the host machine compiles programs, the virus inserts lines of malicious code, turning the compiled code into a virus delivery system.

Researchers from security firms Sans, McAfee, BitDefender and F-Secure have all reported and analysed the virus, which has so far shown no malicious intent other than replicating itself. No further malware attacks or file downloads have been reported.

But the virus is gaining attention because of its unusual delivery style, which has managed to infect some high-profile applications. German computer magazine ComputerBild warned readers after discovering that one of the files on a recent CD insert was infected with the virus.

The infection also appears to be spreading in more nefarious circles, according to Sans researcher Rick Wanner.

"A funny side-effect is that, in the few days since this virus has been detected in the wild, a number of Trojans have been discovered to be affected with the virus," he said in a blog post. "Obviously they were compiled with an infected Delphi compiler."

BitDefender said that developers can check for the infection by searching for a file in the Delphi library folder named 'SysConst.bak', and then renaming the infected file as 'SysConst.dcu' to prevent compiled applications becoming infected.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

2%

14%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Senior Technical Consultant (Microsoft)- ATS

Opportunity to join a rapidly expanding Microsoft Consultancy...

Technical Architect -UC/Video Conferencing/VAAS

Technical Architect - UC/Video Conferencing/VAAS Inspire...

SQL Developer - MS SQL .NET

A busy organisation in Glasgow is looking for a skilled...

Test Analyst, Python, Automation, London

Test, Python, Shell, Automation, Manual My client...

To send to more than one email address, simply separate each address with a comma.