Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-20-2009, 22:07
Antelox Antelox is offline
Friend
 
Join Date: Mar 2009
Posts: 24
Rept. Given: 16
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
Antelox Reputation: 3
Virus Win32:Induc

Hi all,

here there is a simple description of Win32: Induc virus that infects Delphi Development Environments.

LoOk:

http://antelox.wordpress.com/2009/08/20/virus-win32induc/

Bye.
Reply With Quote
  #2  
Old 08-20-2009, 23:53
dj-siba's Avatar
dj-siba dj-siba is offline
Musician Member
 
Join Date: Jun 2003
Location: Outside the dot
Posts: 324
Rept. Given: 34
Rept. Rcvd 43 Times in 21 Posts
Thanks Given: 57
Thanks Rcvd at 160 Times in 43 Posts
dj-siba Reputation: 42
More info
Code:
http://blog.eurekalog.com/?p=244
http://www.kaspersky.com/news?id=207575885
http://www.at4re.com/f/showthread.php?t=6549
here a small tool from my friend STRELiTZIA
SlugMRT small tool to detect W32/Induc-A virus in non packed program
http://rapidshare.com/files/269477686/SlugMRT.rar
Reply With Quote
  #3  
Old 08-21-2009, 03:00
Antelox Antelox is offline
Friend
 
Join Date: Mar 2009
Posts: 24
Rept. Given: 16
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
Antelox Reputation: 3
Very Nice dj-siba, thx much br0!!!

Does he have this mw??? It so please send me a PM

Thx in advance!!!

Bye.
Reply With Quote
  #4  
Old 08-21-2009, 03:29
dj-siba's Avatar
dj-siba dj-siba is offline
Musician Member
 
Join Date: Jun 2003
Location: Outside the dot
Posts: 324
Rept. Given: 34
Rept. Rcvd 43 Times in 21 Posts
Thanks Given: 57
Thanks Rcvd at 160 Times in 43 Posts
dj-siba Reputation: 42
see here analyze of virus with source code
http://www.at4re.com/f/showthread.php?t=6549
you can use google to translate from Arabic
Reply With Quote
  #5  
Old 08-21-2009, 05:06
Antelox Antelox is offline
Friend
 
Join Date: Mar 2009
Posts: 24
Rept. Given: 16
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
Antelox Reputation: 3
I say an infected exe so that I can analyze it.

Btw thx much for the hints

Bye.
Reply With Quote
  #6  
Old 08-21-2009, 18:54
dj-siba's Avatar
dj-siba dj-siba is offline
Musician Member
 
Join Date: Jun 2003
Location: Outside the dot
Posts: 324
Rept. Given: 34
Rept. Rcvd 43 Times in 21 Posts
Thanks Given: 57
Thanks Rcvd at 160 Times in 43 Posts
dj-siba Reputation: 42
ok here an infected keygen
http://download-crack-serial.com/software-crack.php?id=125613
Reply With Quote
  #7  
Old 08-21-2009, 22:52
Antelox Antelox is offline
Friend
 
Join Date: Mar 2009
Posts: 24
Rept. Given: 16
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
Antelox Reputation: 3
Oh thx br0,

Can i upload it to OffensiveComputing as a Win32/induc sample???

Bye.
Reply With Quote
  #8  
Old 08-22-2009, 05:18
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
Why spread this filth at all? Every time somebody uploads this kind of source you can bet for certain it will fall into many hands that will abuse it and do harm to others. If you are so keen to upload it why not limit it to requests from people you know and trust?. Be responsible please.

Git
Reply With Quote
  #9  
Old 08-27-2009, 02:37
BoRoV's Avatar
BoRoV BoRoV is offline
Lo*eXeTools*rd
 
Join Date: Aug 2009
Posts: 56
Rept. Given: 3
Rept. Rcvd 91 Times in 24 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
BoRoV Reputation: 91
My tools for fight with this virus
http://a0.sderni.ru/319127-Anti.Win32.Induc.v0.13.7z
Reply With Quote
  #10  
Old 09-17-2009, 21:53
STRELiTZIA
 
Posts: n/a
Hi,
Good work
but I have a brief comment...

Your Tool Patch only one byte without removing the entirment code of virus that will always concedere as infected by the Antivirus...
Reply With Quote
  #11  
Old 09-18-2009, 14:15
BoRoV's Avatar
BoRoV BoRoV is offline
Lo*eXeTools*rd
 
Join Date: Aug 2009
Posts: 56
Rept. Given: 3
Rept. Rcvd 91 Times in 24 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
BoRoV Reputation: 91
yes, I know about this problem, going to correct it, but time is not present
Reply With Quote
  #12  
Old 09-29-2009, 07:06
SLV SLV is offline
Friend
 
Join Date: May 2005
Posts: 62
Rept. Given: 3
Rept. Rcvd 4 Times in 3 Posts
Thanks Given: 5
Thanks Rcvd at 2 Times in 2 Posts
SLV Reputation: 4
One more cause why not to use stupid delphi
Reply With Quote
  #13  
Old 09-29-2009, 14:39
BoRoV's Avatar
BoRoV BoRoV is offline
Lo*eXeTools*rd
 
Join Date: Aug 2009
Posts: 56
Rept. Given: 3
Rept. Rcvd 91 Times in 24 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
BoRoV Reputation: 91
already it was heard from you
Reply With Quote
  #14  
Old 10-04-2009, 17:05
LaptoniC LaptoniC is offline
Family
 
Join Date: Jan 2002
Posts: 31
Rept. Given: 1
Rept. Rcvd 38 Times in 4 Posts
Thanks Given: 1
Thanks Rcvd at 7 Times in 5 Posts
LaptoniC Reputation: 38
Kaspersky always flags CORE keygens by tam infected with this virus for quite long time. I don't know whether it is false positive but I think they should take care of it.
Reply With Quote
  #15  
Old 10-05-2009, 03:07
.:hack3r2k:.'s Avatar
.:hack3r2k:. .:hack3r2k:. is offline
Friend
 
Join Date: Mar 2002
Location: Inside the c0de ...
Posts: 66
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 3 Posts
.:hack3r2k:. Reputation: 0
Cool

Since this "cvirus" was actually harmless it passed untected for long period of time so at current time for sure there are out there many Delphi applications containing it.

Br
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Definition of Virus wilson bibe General Discussion 4 07-08-2013 18:04
Virus and cracking peleon General Discussion 0 05-12-2004 16:25


All times are GMT +8. The time now is 21:26.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )