|  | 
 
 发表于 2004-12-15 15:22:18
|
显示全部楼层 
| ViRUS NAME :JS_BAIDU.A 9 A  P- R1 j7 q: M) @5 P, t) ^6 r8 d: g7 c2 x0 c) g
 b7 a; S9 h* h6 t
 QUICK LINKS Solution | Understanding New Pattern Format
 2 `. U; k4 q9 G, G" `4 w; R% f
 9 ^" H4 P/ c. o; a* j--------------------------------------------------------------------------------
 ; Q) L6 H& Z# S4 N + _% Q8 W4 u7 T* f7 w8 [
 Virus type: JavaScript   |2 Z+ L4 I* p/ P; t
 
 : k6 ]4 k; K( b% d  ZDestructive: No : o$ a: ?$ z4 B
 
 g3 b4 m* y  g) R2 W2 C& \* Y7 sPattern file needed: 2.292.08   ~0 e( F' F. C$ N' Z
 4 U: Y4 M# |# C. F: r
 Scan engine needed: 6.810 $ L. j2 y( Q- l- x$ V0 u
 
 $ U- l3 F/ W% C# C Overall risk rating:  Very Low  7 f+ D. K2 z2 V$ [, M  O. H
 
 ! T' Z2 s) Q4 {--------------------------------------------------------------------------------
 : b4 V5 T2 T( ?: N ' V: {8 g0 `' y2 {' c7 H
 Reported infections:  Low
 1 w. b- o) y9 G/ R# |
 : I9 f' u, |4 I$ ]/ ^, K' F2 [/ DDamage Potential:  Low  ' w7 b7 z1 y' P& M
 
 ! |1 L( J- v7 k* j1 i$ {Distribution Potential:  Low  ) n" Y8 U! V7 H; I! M; j+ n. L9 N) z$ \
 
 ; V! K3 h) `# m: }5 Y% r! o
 ! O0 t# B/ r( j' h/ S* I" A6 k5 z# V; Z5 X! l0 m/ f; S* b
 --------------------------------------------------------------------------------5 `! E$ Q3 R% Y
 1 I7 l$ h8 m0 l4 b, m! H
 Description:
 5 W! k# n2 t3 ?" H2 G
 4 o) R* }" i. F. P4 k! {' M% H
 / v8 Z" D' F& x3 u
 This malicious JS script may reside in an HTML file or in a malicious Web site. 2 p# R0 i' m( H0 j$ |2 j8 Q
 
 0 G6 ?, T1 n; m$ IUpon execution, this JS script automatically downloads from the URL http://barai<BLOCKED>.com/update/Search.cab. $ [! A, }- `+ i/ r1 l
 
 # C  Y6 G: J' j8 p3 I, x: ~* h" n# v* hIt exploits a codebase vulnerability in Internet Explorer, which allows automatic execution of files. ' p, w6 Y/ o0 `. U
 
 * [% X2 H* A$ F3 n* i( NIt runs on Windows 95, 98, ME, NT, 2000, and XP.
 | 
 |