Sophos

Troj/JSXor-Gen

Aliases
  • JS_DLOADER.NUF
  • Trojan-Downloader.JS.Agent.kd
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Web browsing
Affected operating systems Windows
Protection available since 1 July 2007 11:57:11 (GMT)
Last updated 31 July 2007 20:33:34 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/JSXor-Gen is a JavaScript downloader Trojan which attempts to exploit a buffer overflow vulnerabilty to download and run executable code.

Troj/JSXor-Gen is a JavaScript downloader Trojan which attempts to exploit a buffer overflow vulnerabilty to download and run executable code.

Troj/JSXor-Gen typically arrives via HTML content within spam email messages, or by browsing websites whose HTML pages contain the script, or link to the script.

The Troj/JSXor-Gen script first decodes an encrypted string and writes it to the current page via document.write. This decoded content is another JavaScript (detected seperately as JS/DlrShl-A and Mal/JSShell-B) which attempts to exploit a vulnerability associated with Windows Media Player to run executable code. See Microsoft Security Bulletin MS06-006.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer