GSM-Forum

Go Back   GSM-Forum > Product Support Sections > Hard/Software-Products (official support) > Infinity-Box


Closed Thread
 
Thread Tools Display Modes
Old 06-23-2009, 17:47   #1
the_laser
No Life Poster
 
Join Date: Feb 2002
Location: Russia
Age: 30
Posts: 997
Member: 9519
Status: Offline
Thanks: 2
Thanked 403 Times in 90 Posts
Attention to infinity supporters !!!

Greetings.

sadly to say, but all your modules (at least ChineseMiracle 2.83, MT62xx_lp_editor 1.26, DongleManager 1.29,QCModule2 1.05 and most probably all latest version) contains some source level virus type program, which are targeted for delphi programmers.

what that addon doing:

1. each time poisoned software run, it checks if delphi installed on machine by checking registry keys
HKLM\Software\Borland\Delphi\4.0
HKLM\Software\Borland\Delphi\5.0
HKLM\Software\Borland\Delphi\6.0
HKLM\Software\Borland\Delphi\7.0

if such key exists, it getting RootDir property and check for
HKLM\Software\Borland\Delphi\x.0\RootDir\source\rt l\sys\SysConst.pas

then it appends itself to that file and running in hidded mode HKLM\Software\Borland\Delphi\x.0\RootDir\bin\dcc32 .exe, which replacing original sysconst.dcu compiled module.

after that EACH software, which will be compiled on that machine will contain that thing.

i want to mention, that it not deleting or damaging anything, but it leave a huge security hole for possible infections.

of course, i believe that you do not know about that thing.

please check and fix all modules ASAP.

thanks for understanding.
Attached Files
File Type: txt sysconst.pas.virus.txt (11.6 KB, 98 views)
 
The Following 22 Users Say Thank You to the_laser For This Useful Post:
Old 06-23-2009, 18:07   #2
the_laser
No Life Poster
 
Join Date: Feb 2002
Location: Russia
Age: 30
Posts: 997
Member: 9519
Status: Offline
Thanks: 2
Thanked 403 Times in 90 Posts
yes, forgot to post most important thing.

workaround is very simple.

just need to create file HKLM\Software\Borland\Delphi\x.0\RootDir\Lib\sysco nst.bak

after that "thing" will think that it already done its job.
 
The Following 4 Users Say Thank You to the_laser For This Useful Post:
Old 06-24-2009, 02:57   #3
free1600
No Life Poster
 
free1600's Avatar
 
Join Date: Mar 2007
Location: /Fr/Ch\Ro\
Age: 25
Posts: 808
Member: 467911
Status: Offline
Thanks: 607
Thanked 174 Times in 124 Posts
mmmmmmm thanks for your knowledge share I can confirm this even if I'm not a programmer(I play) i have delphi on my pc...
yes a fix for this...

br,
free1600
 
Old 06-24-2009, 06:39   #4
hans salim
No Life Poster
 
hans salim's Avatar
 
Join Date: Jun 2006
Location: in this world
Posts: 1,422
Member: 292087
Status: Offline
Sonork: 1575183
Thanks: 68
Thanked 72 Times in 50 Posts
@THE LASER
IS THIS CAUSE NY BOX THIS PROBLEM?

it was working fine sudenly start to show dongle damaged error code 65!!!, plz i need help?

http://forum.gsmhosting.com/vbb/show...96&postcount=1
 
Old 06-24-2009, 06:51   #5
~ Nawab Traders ~
No Life Poster
 
~ Nawab Traders ~'s Avatar
 
Join Date: Dec 2005
Location: City Of Education
Posts: 2,051
Member: 209722
Status: Offline
Sonork: 1575287
Thanks: 4,294,967,295
Thanked 340 Times in 255 Posts
Still no ansure or response from infinity team even the laser pointout all with details.
 
Old 06-24-2009, 07:08   #6
farihabest
No Life Poster
 
farihabest's Avatar
 
Join Date: Oct 2007
Location: MX-Key and me ...The Best
Posts: 587
Member: 617692
Status: Offline
Thanks: 95
Thanked 177 Times in 81 Posts
With due respect

Infinity Team please reply... My kaspersky also detected viruses(trojan) in calculater.exe that I have download from Infinity support area
 
Old 06-24-2009, 07:34   #7
cel_phon
No Life Poster
 
cel_phon's Avatar
 
Join Date: Jan 2009
Location: MBDin.fleeforum.com
Posts: 2,154
Member: 950201
Status: Offline
Thanks: 44
Thanked 872 Times in 554 Posts
Quote:
Originally Posted by the_laser View Post
Greetings.

sadly to say, but all your modules (at least ChineseMiracle 2.83, MT62xx_lp_editor 1.26, DongleManager 1.29,QCModule2 1.05 and most probably all latest version) contains some source level virus type program, which are targeted for delphi programmers.

what that addon doing:

1. each time poisoned software run, it checks if delphi installed on machine by checking registry keys
HKLM\Software\Borland\Delphi\4.0
HKLM\Software\Borland\Delphi\5.0
HKLM\Software\Borland\Delphi\6.0
HKLM\Software\Borland\Delphi\7.0

if such key exists, it getting RootDir property and check for
HKLM\Software\Borland\Delphi\x.0\RootDir\source\rt l\sys\SysConst.pas

then it appends itself to that file and running in hidded mode HKLM\Software\Borland\Delphi\x.0\RootDir\bin\dcc32 .exe, which replacing original sysconst.dcu compiled module.

after that EACH software, which will be compiled on that machine will contain that thing.

i want to mention, that it not deleting or damaging anything, but it leave a huge security hole for possible infections.

of course, i believe that you do not know about that thing.

please check and fix all modules ASAP.

thanks for understanding.
.........................................

thanks for sharing and point out the problem

hope infinity will take action at their best
 
Old 06-24-2009, 08:42   #8
pankaj_gsm
Freak Poster
 
Join Date: Mar 2009
Posts: 121
Member: 983750
Status: Offline
Thanks: 48
Thanked 22 Times in 19 Posts
dere is no problem in infinity box setup working very fine
i think its anti virus problem which shows virus in many exe file
 
The Following User Says Thank You to pankaj_gsm For This Useful Post:
Old 06-24-2009, 08:50   #9
ABDULMANAN
No Life Poster
 
ABDULMANAN's Avatar
 
Join Date: Apr 2008
Location: GOLRA ShARIF ISLAMABAD
Posts: 523
Member: 754324
Status: Offline
Sonork: 100.1586047
Thanks: 46
Thanked 79 Times in 65 Posts
some antivirus show good file virus and damage files
 
Old 06-24-2009, 19:07   #10
Barabaka
Crazy Poster
 
Join Date: Apr 2005
Age: 35
Posts: 57
Member: 140289
Status: Offline
Thanks: 4
Thanked 5 Times in 4 Posts
@ all who not uderstand.
Antivirus dosn't show this kind of problem. Its very special weapon.
Do not panic. It's not for us.
 
The Following 2 Users Say Thank You to Barabaka For This Useful Post:
Old 06-24-2009, 20:02   #11
s.Mobi
No Life Poster
 
s.Mobi's Avatar
 
Join Date: Nov 2001
Location: Donetsk, Ukraine
Age: 28
Posts: 500
Member: 7436
Status: Offline
Thanks: 23
Thanked 51 Times in 35 Posts
Yes, this virus not for all. Now my system cleaned and after some time i make next version of China Editor without this ****ing insecticide.

To the_laser - very big TNX for info!!!
 
Old 06-24-2009, 20:04   #12
InfinitySupport
Product Manager
 
Join Date: Mar 2005
Location: www.infinity-box.com
Posts: 31,827
Member: 130995
Status: Offline
Thanks: 5,394
Thanked 14,991 Times in 3,050 Posts
Quote:
Originally Posted by ~ Nawab Traders ~ View Post
Still no ansure or response from infinity team even the laser pointout all with details.
I did not understand well, what kind of "response" you want to see ?
 
Old 06-24-2009, 20:07   #13
InfinitySupport
Product Manager
 
Join Date: Mar 2005
Location: www.infinity-box.com
Posts: 31,827
Member: 130995
Status: Offline
Thanks: 5,394
Thanked 14,991 Times in 3,050 Posts
Quote:
Originally Posted by farihabest View Post
With due respect

Infinity Team please reply... My kaspersky also detected viruses(trojan) in calculater.exe that I have download from Infinity support area
Please, check FAQ thread in current forum, you will see detailed information.
 
Old 06-24-2009, 20:08   #14
InfinitySupport
Product Manager
 
Join Date: Mar 2005
Location: www.infinity-box.com
Posts: 31,827
Member: 130995
Status: Offline
Thanks: 5,394
Thanked 14,991 Times in 3,050 Posts
Quote:
Originally Posted by hans salim View Post
@THE LASER
IS THIS CAUSE NY BOX THIS PROBLEM?

it was working fine sudenly start to show dongle damaged error code 65!!!, plz i need help?

http://forum.gsmhosting.com/vbb/show...96&postcount=1
How to repair "Error code #32, #65":

. uninstall any kind of usb-sharing software
. reboot PC
. make "Read S/N" operation via DongleManager
. contact to InfinityRemoteUpdate@yahoo.co.uk and explain the problem so detailed as possible, attach full dongle details in your mail
. after you have got a confirmation that your dongle is not blocked forever (hope you will be able to get this confirmation): upgrade your dongle firmware with DongleManager
. never use any kind of usb-sharing software with Infinity-Box to avoid FOREVER BLOCKED dongle !
 
Old 06-24-2009, 20:11   #15
InfinitySupport
Product Manager
 
Join Date: Mar 2005
Location: www.infinity-box.com
Posts: 31,827
Member: 130995
Status: Offline
Thanks: 5,394
Thanked 14,991 Times in 3,050 Posts
@Laser
Thanks for warning, we will check it.

@all
Thread closed to avoid tons of posts from people who did not understand what this thread talk about.
 
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 17:17.


GSMCity - GSM Hosting - 1999-2009
Page generated in 0.10785 seconds with 9 queries