|
|
发表于 2004-12-15 15:22:18
|
显示全部楼层
ViRUS NAME :JS_BAIDU.A5 B: o7 T& {+ u
+ e$ q; ~% {( X* t1 Z
& I3 j& w+ H2 w3 a3 x; P2 [QUICK LINKS Solution | Understanding New Pattern Format * w8 `. N) r$ s
1 ?" [* V" V1 q5 ?-------------------------------------------------------------------------------- v. t0 l% e7 u' W6 C
7 | ^; o4 H* ?$ EVirus type: JavaScript
. [, H7 H9 O) U4 m# @
$ q% _2 U, B8 nDestructive: No
0 O- q! o9 E8 X, u+ S
7 s) k* ^. A4 \/ f$ Q2 GPattern file needed: 2.292.08
t+ `' }! q% j# {
3 o% V. ]+ v9 V/ T5 QScan engine needed: 6.810 7 h, G0 F4 J% B& Z# Z7 g7 e
( ~2 ~' z4 D% \ l0 f3 o Overall risk rating: Very Low ) ]; f0 A. K! x+ w
6 S9 P$ k. g% P% K$ ^
--------------------------------------------------------------------------------5 l5 J/ b1 x+ U0 k
: Y" k4 ^, A7 I6 J7 B3 @Reported infections: Low . \! |6 g% A" ]( ?. u6 t2 @
- @8 I) x* I2 ^
Damage Potential: Low
3 X* @9 [7 S3 s+ t9 s8 h+ r- l! m7 t
9 K& r3 c) T- B- Y9 \# t7 b' TDistribution Potential: Low 7 o/ g ^' N; o
' a7 C! C, r, f- e/ }) n/ w ' K1 n/ D( m; b7 Y$ c) P
) s O- \4 Q' n- f8 o--------------------------------------------------------------------------------
7 ?4 v+ f# K C1 L, Z
" j- q9 x' G [% n6 x( n" c1 oDescription:) b2 z5 L* [$ `7 L* X4 M6 f- _
1 y, E }/ t# u* t7 ?& n8 q
) z( y- @$ e( N7 ]! A: C6 O+ g
. Q1 ~! p S& J XThis malicious JS script may reside in an HTML file or in a malicious Web site. ; Z9 ^# l$ V$ s2 d! \' q& D/ T
! E+ e! Z6 U9 w
Upon execution, this JS script automatically downloads from the URL http://barai<BLOCKED>.com/update/Search.cab.
* C; ~& K, }1 Z; C8 c" R* _
$ L v% d! W# k8 e X* j/ NIt exploits a codebase vulnerability in Internet Explorer, which allows automatic execution of files. ; i$ F# e* ~* j* d
3 A& X9 ^3 { x9 VIt runs on Windows 95, 98, ME, NT, 2000, and XP. |
|