Virus Profile: JS/Exploit.gen

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 2/2/2009
Date Added: 2/2/2009
Origin: N/A
Length: N/A
Type: Trojan
Subtype: Generic
DAT Required: 5514
Removal Instructions
   
 
 
   

Description

JS/Exploit Generic is detection for suspiciously encoded JavaScript.  Scripts containing certain attributes used to maliciously exploit a browser or other web content rendering mechanisms are detected under this classification name.

JS/Exploit is not a virus, but rather an exploit that takes advantage of security vulnerability in some versions of Microsoft Internet Explorer, Outlook and Outlook Express.

Indication of Infection

The presence of download files resulting from the script execution.

This vulnerability modifies the browsers start page, search page and also add some unauthorized links to the "Favorites" folder of Microsoft Internet Explorer.

Typically this exploit is used to execute other programs.  Those programs can be whatever the author chooses to run on the vulnerable system.  Therefore it is not possible to provide specific information as one attack can vary from the next. 

Methods of Infection

Browsing an infected website containing this script.

This threat could be delivered via an email message, or an infectious web page.

   

Virus Characteristics

This is a generic detection.  Specific payloads, urls, or IP address may very for specific samples.

Js/Exploit.gen contains the encrypted JAVA Script codes that use vulnerability in some version of Microsoft Internet Explorer to execute. Once the vulnerabilities are exploited, then the binary files are downloaded from the malicious URL. After that the downloaded files are saved in Temp folder %temp%. Finally the files are executed.

   
All Users:
Use current engine and DAT files for detection. Delete any file which contains this detection.