Detection Virus.Win32.Induc.a spreads by infecting the systems running the Delphi development environment. When the Detection Virus.Win32.Induc.a code is executed it will first check if Delphi (version 4 through 7) is installed on the computer via registry entries, If found, it will get the Delphi installation folder from the same registry key and
copy %Delphi_Installation_Folder%SourceRtlSysSysConst.pas to %Delphi_Installation_Folder%LibSysConst.pas and add its malicious code in the implementation section of this copy. This file will be then compiled, resulting an infected sysconst.dcu (Delphi compiled unit) but not before making a copy of the once clean sysconst.dcu file under sysconst.bak. Then the copy of sysconst.pas will be deleted.

Alias: W32.Induc.A [Symantec], Virus.Win32.Induc.a [Kaspersky Lab], W32/Induc [McAfee], W32/Induc-A [Sophos], Virus:Win32/Induc.A [Microsoft], Virus.Win32.Induc [Ikarus], Win32/Induc [AhnLab]

Damage Level: Medium

Systems Affected: Windows