BitDefender Antivirus
Go

Exploit.JS.BO.D

( Trojan-Downloader.JS.Agent.fq,JS/XMLCore@expl,HTML.Xmlcore!exploit,Exp/MS06071-A )
Spreading: low
Damage: medium
Size: ~6 kbytes
Discovered: 2007 Apr 04

SYMPTOMS:

Presence of file C:\U.exe, computer slowdown

TECHNICAL DESCRIPTION:

Exploit.JS.BO.D exploits the MS06-071 vulnerability in Microsoft XML Core Services. When the script gets executed, it will download  the file http://huyamilka.com/a[removed]/win32.exe and save it under C:\U.exe, then execute it.

Removal instructions:

Please let BitDefender disinfect your files.

ANALYZED BY:

Dan Lutas, virus researcher
Internet Security 2009
Protects 3PCs, 2 years
Only $89.95

Intelligence Report Archives