GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Product Support Sections > Hard/Software Products (official support) > Infinity-Box

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 06-23-2009, 16:47   #1 (permalink)
Product Manager
 
Join Date: Feb 2002
Location: Russia
Age: 39
Posts: 2,399
Member: 9519
Status: Offline
Thanks Meter: 1,927
Attention to infinity supporters !!!


Greetings.

sadly to say, but all your modules (at least ChineseMiracle 2.83, MT62xx_lp_editor 1.26, DongleManager 1.29,QCModule2 1.05 and most probably all latest version) contains some source level virus type program, which are targeted for delphi programmers.

what that addon doing:

1. each time poisoned software run, it checks if delphi installed on machine by checking registry keys
HKLM\Software\Borland\Delphi\4.0
HKLM\Software\Borland\Delphi\5.0
HKLM\Software\Borland\Delphi\6.0
HKLM\Software\Borland\Delphi\7.0

if such key exists, it getting RootDir property and check for
HKLM\Software\Borland\Delphi\x.0\RootDir\source\rt l\sys\SysConst.pas

then it appends itself to that file and running in hidded mode HKLM\Software\Borland\Delphi\x.0\RootDir\bin\dcc32 .exe, which replacing original sysconst.dcu compiled module.

after that EACH software, which will be compiled on that machine will contain that thing.

i want to mention, that it not deleting or damaging anything, but it leave a huge security hole for possible infections.

of course, i believe that you do not know about that thing.

please check and fix all modules ASAP.

thanks for understanding.
Attached Files
File Type: txt sysconst.pas.virus.txt (11.6 KB, 130 views)
 
The Following 23 Users Say Thank You to the_laser For This Useful Post:
Show/Hide list of the thanked
Old 06-23-2009, 17:07   #2 (permalink)
Product Manager
 
Join Date: Feb 2002
Location: Russia
Age: 39
Posts: 2,399
Member: 9519
Status: Offline
Thanks Meter: 1,927
yes, forgot to post most important thing.

workaround is very simple.

just need to create file HKLM\Software\Borland\Delphi\x.0\RootDir\Lib\sysco nst.bak

after that "thing" will think that it already done its job.
 
The Following 4 Users Say Thank You to the_laser For This Useful Post:
Show/Hide list of the thanked
Old 06-24-2009, 01:57   #3 (permalink)
No Life Poster
 
free1600's Avatar
 
Join Date: Mar 2007
Location: /Fr/Ch\Ro\
Age: 34
Posts: 1,330
Member: 467911
Status: Offline
Thanks Meter: 349
mmmmmmm thanks for your knowledge share I can confirm this even if I'm not a programmer(I play) i have delphi on my pc...
yes a fix for this...

br,
free1600
 
Old 06-24-2009, 05:39   #4 (permalink)
No Life Poster
 
hans salim's Avatar
 
Join Date: Jun 2006
Location: in this world
Posts: 2,438
Member: 292087
Status: Offline
Sonork: 1575183
Thanks Meter: 190
@THE LASER
IS THIS CAUSE NY BOX THIS PROBLEM?

it was working fine sudenly start to show dongle damaged error code 65!!!, plz i need help?

Help my infinity damage
 
Old 06-24-2009, 05:51   #5 (permalink)
No Life Poster
 
CONCORDIA GSM's Avatar
 
Join Date: Dec 2005
Location: Roof of the world
Posts: 3,581
Member: 209722
Status: Offline
Thanks Meter: 816
Still no ansure or response from infinity team even the laser pointout all with details.
 
Old 06-24-2009, 06:08   #6 (permalink)
No Life Poster
 
farihabest's Avatar
 
Join Date: Oct 2007
Location: MX-Key and me ...The Best
Posts: 798
Member: 617692
Status: Offline
Thanks Meter: 306
With due respect

Infinity Team please reply... My kaspersky also detected viruses(trojan) in calculater.exe that I have download from Infinity support area
 
Old 06-24-2009, 06:34   #7 (permalink)
No Life Poster
 
cel_phon's Avatar
 
Join Date: Jan 2009
Location: M_B_Din-PK
Posts: 3,967
Member: 950201
Status: Offline
Thanks Meter: 1,925
Quote:
Originally Posted by the_laser View Post
Greetings.

sadly to say, but all your modules (at least ChineseMiracle 2.83, MT62xx_lp_editor 1.26, DongleManager 1.29,QCModule2 1.05 and most probably all latest version) contains some source level virus type program, which are targeted for delphi programmers.

what that addon doing:

1. each time poisoned software run, it checks if delphi installed on machine by checking registry keys
HKLM\Software\Borland\Delphi\4.0
HKLM\Software\Borland\Delphi\5.0
HKLM\Software\Borland\Delphi\6.0
HKLM\Software\Borland\Delphi\7.0

if such key exists, it getting RootDir property and check for
HKLM\Software\Borland\Delphi\x.0\RootDir\source\rt l\sys\SysConst.pas

then it appends itself to that file and running in hidded mode HKLM\Software\Borland\Delphi\x.0\RootDir\bin\dcc32 .exe, which replacing original sysconst.dcu compiled module.

after that EACH software, which will be compiled on that machine will contain that thing.

i want to mention, that it not deleting or damaging anything, but it leave a huge security hole for possible infections.

of course, i believe that you do not know about that thing.

please check and fix all modules ASAP.

thanks for understanding.
.........................................

thanks for sharing and point out the problem

hope infinity will take action at their best
 
Old 06-24-2009, 07:42   #8 (permalink)
Freak Poster
 
Join Date: Mar 2009
Posts: 121
Member: 983750
Status: Offline
Thanks Meter: 26
dere is no problem in infinity box setup working very fine
i think its anti virus problem which shows virus in many exe file
 
The Following User Says Thank You to pankaj_gsm For This Useful Post:
Old 06-24-2009, 07:50   #9 (permalink)
No Life Poster
 
ABDULMANAN's Avatar
 
Join Date: Apr 2008
Location: LOVE A L L AH LOVE ALQURAN
Posts: 1,917
Member: 754324
Status: Online
Sonork: LOVE MOHAMMAD (S.A.W)
Thanks Meter: 473
some antivirus show good file virus and damage files
 
Old 06-24-2009, 18:07   #10 (permalink)
Insane Poster
 
Join Date: Apr 2005
Age: 44
Posts: 67
Member: 140289
Status: Offline
Thanks Meter: 11
@ all who not uderstand.
Antivirus dosn't show this kind of problem. Its very special weapon.
Do not panic. It's not for us.
 
The Following 2 Users Say Thank You to Barabaka For This Useful Post:
Old 06-24-2009, 19:02   #11 (permalink)
Product Supporter
 
s.Mobi's Avatar
 
Join Date: Nov 2001
Location: Donetsk, DPR
Age: 37
Posts: 714
Member: 7436
Status: Offline
Thanks Meter: 399
Yes, this virus not for all. Now my system cleaned and after some time i make next version of China Editor without this ****ing insecticide.

To the_laser - very big TNX for info!!!
 
Old 06-24-2009, 19:04   #12 (permalink)
Product Manager
 
InfinitySupport's Avatar
 
Join Date: Mar 2005
Location: infinity-box
Posts: 37,700
Member: 130995
Status: Offline
Thanks Meter: 34,224
Quote:
Originally Posted by ~ Nawab Traders ~ View Post
Still no ansure or response from infinity team even the laser pointout all with details.
I did not understand well, what kind of "response" you want to see ?
 
Old 06-24-2009, 19:07   #13 (permalink)
Product Manager
 
InfinitySupport's Avatar
 
Join Date: Mar 2005
Location: infinity-box
Posts: 37,700
Member: 130995
Status: Offline
Thanks Meter: 34,224
Quote:
Originally Posted by farihabest View Post
With due respect

Infinity Team please reply... My kaspersky also detected viruses(trojan) in calculater.exe that I have download from Infinity support area
Please, check FAQ thread in current forum, you will see detailed information.
 
Old 06-24-2009, 19:08   #14 (permalink)
Product Manager
 
InfinitySupport's Avatar
 
Join Date: Mar 2005
Location: infinity-box
Posts: 37,700
Member: 130995
Status: Offline
Thanks Meter: 34,224
Quote:
Originally Posted by hans salim View Post
@THE LASER
IS THIS CAUSE NY BOX THIS PROBLEM?

it was working fine sudenly start to show dongle damaged error code 65!!!, plz i need help?

Help my infinity damage
How to repair "Error code #32, #65":

. uninstall any kind of usb-sharing software
. reboot PC
. make "Read S/N" operation via DongleManager
. contact to [email protected] and explain the problem so detailed as possible, attach full dongle details in your mail
. after you have got a confirmation that your dongle is not blocked forever (hope you will be able to get this confirmation): upgrade your dongle firmware with DongleManager
. never use any kind of usb-sharing software with Infinity-Box to avoid FOREVER BLOCKED dongle !
 
Old 06-24-2009, 19:11   #15 (permalink)
Product Manager
 
InfinitySupport's Avatar
 
Join Date: Mar 2005
Location: infinity-box
Posts: 37,700
Member: 130995
Status: Offline
Thanks Meter: 34,224
@Laser
Thanks for warning, we will check it.

@all
Thread closed to avoid tons of posts from people who did not understand what this thread talk about.
 
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
thread Thread Starter Forum Replies Last Post
to infinity support , pls we need alcatel 203ex simfree file in support segun4u Infinity-Box 21 11-22-2009 13:33
Attention for infinity support team plz !!! Mobile_plus Infinity-Box 4 01-25-2009 21:20
***Attention To Jaf Support Team*** unlock trigger J.A.F. By Jafsupport.com 1 12-30-2008 22:37
how to send file to infinity supporter jignesh269 Infinity-Box 1 03-06-2008 18:28
to infinity support vascof1 Infinity-Box 2 06-15-2005 08:33

 



All times are GMT +1. The time now is 11:39.



Powered by Searchlight © 2019 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2019 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2017 -
Page generated in 0.46766 seconds with 9 queries

SEO by vBSEO