"ASCII" wrote:
> Interesting thing is that each 'scan', or running of the applet purports to find
> several dangerous items, but with different names. If I don't DL and run the
> [exe] they offer, why is there such a non redundant variety of malware from time
> to time (each refresh and reload of the page) with hardly ever any subsequent
> detections. It's as if the list is concocted with each 'scan' and I stress that
> it's not a scan but a js applet running to appear as such.
Yep, completely fake scan witten in Javascript. It randomly selects a
handful of alerts from a list of 22 and pretends to scan 11 folders
and 206 files.
virusNames=[
["Adware.Win32.Winad","Critical"],
["Adware.Win32.Look2me.ab","Critical"],
["AdvWare.Hotbar","High"],
["Backdoor.Win32.Haxdoor.gu","High"],
["Trojan-Downloader.Win32.Small.dge","High"],
["Trojan-PSW.Win32.LdPinch.abm","Critical"],
["Trojan.Qoologic - Key Logger","High"],
["Trojan Horse IRC/Backdoor.SdBot4.FRV","Medium"],
["SHeur.ZSQ","High"],
["W32.Benjamin.Worm","High"],
["W95/Elkern F-Secure","High"],
["W32.Mypics.Worm.36352","Medium"],
["W32.Nimda.J@mm","Medium"],
["W32.Yaha.B@mm","Critical"],
["Trojan Horse Generic11.OQJ","High"],
["Trojan Horse IRC/Backdoor.SdBot4.FRV","Critical"],
["Magic DVD Ripper","High"],
["Trojan virtumonde","Critical"],
["Win32/Hoax.Renos.HX","Medium"],
["Trojan-Downloader.Win32.Small.fxf","Medium"],
["Trojan-Downloader.Win32.Tibs.tc","Medium"],
["Trojan.Fakealert.355","Medium"]];