Oh Noes! Trojans!
So I’m browsing and I get a popup that says a trojan was detected, then my browser went full-screen and the attached image appeared.I would have been afraid, except there were two mistakes.
The first mistake is that firefox doesn’t allow you to eliminate the borders of a window (at least the way I have it configured) so I could see it was in a browser and not my desktop. If I were an IE user, it might have convinced me it was my desktop. With FireFox, I wasn’t impressed. I could tell. Lesson #1: use open source, or at least use browsers that allow you to configure your javascript more intelligently.
The second mistake is that my desktop couldn’t possibly look like that. I don’t have a C: drive. Or a D: drive. Or a “Shared Documents” folder. Or “My Documents” folder. Nor the blue ’system tasks” bit. My computer runs Linux, and so all my hard drives look like a single big file system rooted at “/” instead of “C:”. Also, although the various Unixes have allowed spaces in filenames for decades, Unix users don’t use spaces in filenames. It’s considered uncouth to make people wrap quotation marks around file and folder names. We can, we just don’t. Lesson #2, use open source, or at least Linux.
Maybe some day a jerky attacker like this may put up an attack versus linux machines, but we all have custom desktops, themes, backgrounds, window control themes, and the like. Would the jerk write it against Gnome? KDE? OpenBox/FluxBox? XFCE? What? Another advantage to having more choices is that it’s harder for bad guys to predict.
Nice try, no buy, goodbye bad guy.
