|
发表于 2004-12-15 15:22:18
|
显示全部楼层
ViRUS NAME :JS_BAIDU.A6 w$ n" {1 L& `; u( X/ J
# y9 Y$ o6 H4 S3 N0 @ ~4 @+ U0 T6 i
" T+ W7 a$ L2 D& G, {QUICK LINKS Solution | Understanding New Pattern Format
! O+ n0 D! ~: \& J( {" f$ e/ P' r V7 _* S* q3 e7 K
--------------------------------------------------------------------------------6 G. }$ ~) i( m% { K3 ]6 {! W
/ M7 @! ^9 y* ?6 QVirus type: JavaScript
9 z7 c2 w4 X3 m+ T ' B6 J$ E! V8 E
Destructive: No 3 _5 \ S O; F2 v t( ~
2 t. b" N( H+ g1 ? t% V& FPattern file needed: 2.292.08
& ^, X. k: n% R5 c7 ]
1 e- B! Y! [ [( |3 D; G+ I7 B3 ^Scan engine needed: 6.810 ; t; v' A+ Z* v% w8 o! K
: l' B% U7 M6 G' Q; n& x3 h
Overall risk rating: Very Low
' `2 M8 `, n& `! x! n
% O* V v4 [7 x" ^' P--------------------------------------------------------------------------------& a3 U1 T% F5 d% f; D
. B% F7 l1 z. h- X9 G! NReported infections: Low + \" z! E' ^# l/ Y7 @0 _1 v
- q- u2 M) e2 Z# b; p$ x1 Y6 Z- IDamage Potential: Low ! [% x9 U& \. a7 k, L- }0 @
6 s# u8 n @- p7 b
Distribution Potential: Low
! @+ M9 d6 Q- Y# q6 x3 V; k: y; z- n, b
1 d1 d* X6 t" U W9 ~( f! L
1 b6 [! t/ {: ]6 Z( k4 O
/ t1 o; d0 J6 Y, W' B--------------------------------------------------------------------------------
. E8 W! x$ a: i: S6 d* J/ P
+ M! X4 x6 c; ?Description:/ r: F/ @, m" w' x# j! a# i
0 y" z; j; ]; S& I& y' l' o- M5 [4 H% L& I/ e! D
5 {. e8 L8 [" l5 xThis malicious JS script may reside in an HTML file or in a malicious Web site. 4 L) y( t1 i3 k: D" h1 D& V
# b2 c3 G+ U; n& j# \, _; K9 dUpon execution, this JS script automatically downloads from the URL http://barai<BLOCKED>.com/update/Search.cab.
1 b) D$ `/ o1 u( Z) p0 z' K
; O- n9 w& S$ dIt exploits a codebase vulnerability in Internet Explorer, which allows automatic execution of files. 7 c8 c8 b3 M* q, k* s2 ?* R
# [# S L3 m3 W# DIt runs on Windows 95, 98, ME, NT, 2000, and XP. |
|