|
|
发表于 2004-12-15 15:22:18
|
显示全部楼层
ViRUS NAME :JS_BAIDU.A
. E, X0 e* y- j# r1 n q! s: D5 s, Z2 ^* z/ ]1 }6 X) Y2 B
" n: X1 K" s7 z& J. bQUICK LINKS Solution | Understanding New Pattern Format # C& C9 N+ I2 a0 K" k& J$ F
; D& z1 W, b# [7 A--------------------------------------------------------------------------------
# j1 y$ i m, i$ `
% @/ R1 B% I9 Q5 A. v* X% LVirus type: JavaScript
: }* x) R! N( u8 v' d% K ! B4 t: d* ?! x
Destructive: No 7 G; S! ~+ L, P0 K* x7 P( W9 [ N
$ I9 j7 k. q. f1 G' l @! a$ f& bPattern file needed: 2.292.08
* ?2 W0 @5 I& }$ Y% S# r+ P* } . v& U* o9 ]+ K+ W9 ~, P
Scan engine needed: 6.810
" b( g- t0 g- Y1 e' s 2 J. A0 W1 J: x; U: Q+ F
Overall risk rating: Very Low $ P! Q2 V: V# M3 a
9 Z' K' _! l' M& d
--------------------------------------------------------------------------------- ?; K& C/ ~0 n- u1 @( ^2 o
- g7 d- C4 v' X6 y) S9 lReported infections: Low 0 k/ ]7 P& |- L8 H& W% V: Z& ]6 v
& p/ T3 J$ T; u( {( J
Damage Potential: Low 1 ^" |+ d" z3 ^
3 b; v6 g+ R& f5 x$ C6 ^9 ?+ A
Distribution Potential: Low
2 |) L( I& l, m6 c- y 5 z4 s) U: e+ Z+ p1 Z& i- a# f
5 W3 S8 @. t4 b! i
9 v& g6 d7 p0 s" Q- Z2 a$ x. M
--------------------------------------------------------------------------------% u* @; P1 L, L
( t5 m# v2 l) H n& t: s3 dDescription:
1 V# y+ v5 ?" K: T; u* H W, p9 M! Q( q. \
. E( F( }& }6 @2 c) d$ T8 w
1 R" v/ e6 g, @, B$ c7 \* X& `This malicious JS script may reside in an HTML file or in a malicious Web site. 0 O% X8 Y( w$ d
* k4 P, w* E% G; b
Upon execution, this JS script automatically downloads from the URL http://barai<BLOCKED>.com/update/Search.cab.
+ |0 V" Z( ?, Q5 c
, J- Z) c- t* _( t' sIt exploits a codebase vulnerability in Internet Explorer, which allows automatic execution of files.
* y4 D8 U! K: Z* q; A- A; S* l
( ?$ w! y5 O% v. a4 Q, uIt runs on Windows 95, 98, ME, NT, 2000, and XP. |
|