Re: need analysis on downloaded javascript - security threat - threat.zip



Thanks for that. I never get any viruses on my machine, and pay close
attention. I was surprised when the exe file was written, and was curious
whether this is a new technique. Not knowing to what extent my machine is
infected, I've been running free virus scanners from different sites to see
if anything's found, in addition to the one I subscribe to. Nothing has been
found yet, which really irks me. I was prompted to allow internet access for
the exe, otherwise it surely would have hooked up and downloaded more code.
I don't think anything is left on my machine, but if a new threat, it
wouldn't be detected.


From: Spamless <Spamless@xxxxxxx>
Date: 30 Jun 2007 19:57:39 GMT
Lines: 102

On 2007-06-30, David McDivitt <david-del@xxxxxxxxxxxxxxxxxxxx> wrote:
I received an email telling me to read a greeting card sent by a family
member. Upon going to the website, my firewall prompted me, saying the

The Javascript tries a few things. It tries the MD2C() exploits,
for various items which may have exploitable classID which will
allow xmlHTTP to get a file, use ADODB.Stream to save to a file
and WScript to run it. The file it tries to get is

--
dgm
.



Relevant Pages

  • Re: DELDIRO
    ... I can find nothing on this exe file having trawled the net. ... and breaking down its name could lead you to believe ... suggest that it may be some kind of Virus, ... Quite often EXE file viruses are not detected as Viruses until executed, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: XP cannot find EXE files
    ... If the file association for .exe has changed automatically, this behaviour is generally caused by viruses. ... One of which is Sircamm virus, which modifies the .exe file association in registry. ... Exit the Registry Editor and restart Windows. ...
    (microsoft.public.windowsxp.general)
  • Re: wont execute programs
    ... If the file association for .exe has changed automatically, this behaviour is generally caused by viruses. ... One of which is Sircamm virus, which modifies the .exe file association in registry. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Windows file virus scanner switches...
    ... you can use an .exe file to scan files for viruses that are transferred ... What's the switch you would use with the exe-file to use symantec ... Can't find the exe file to use anywhere, ... many in the symantec folder! ...
    (alt.comp.anti-virus)