Author Topic: New malware ruins Firefox...  (Read 4442 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
New malware ruins Firefox...
« on: March 31, 2009, 06:22:39 PM »
Hi malware fighters,

DNS-malware infects Firefox users: http://blog.webroot.com/2009/03/25/new-malware-ruins-firefox/
The first malware here is a DNSChanger malware variant, a browser hijacking tool. Once active the malware will install a DLL fiel to run under components in the Firefox process. Just like  DNSChanger it will alter Google search results as those of Yahoo's and other search-engines and sends the search queries to an Ukrain server.

The second Firefox specific malware only working under Firefox 3.x, is a plugin by the name of PlayMP3z. This plugin uses an extensive EULA that clearly states it is adware. During being installed it tries to install the Mirar toolbar. Who prevents this one from installing will be treated to another piece of adware, by the name of Foxicle. This adware will launch various popups as well as popunder ads. Both malware plugins cannot be traced in the Firefox. "While the spread of it is low at the moment an increase of it is being expected", according to Brandts.

The researcher comments that the malware does not exploit a security leak or another bug in Firefox, but comes with other malware.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: New malware ruins Firefox...
« Reply #1 on: March 31, 2009, 07:15:14 PM »
Damien,
Maybe if your stupid enough to install that unapproved plug-in,
you deserve this headache.  ;D
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: New malware ruins Firefox...
« Reply #2 on: March 31, 2009, 08:04:51 PM »
Hi bob3160,

It isn't that simple, DNSChanger firefox is a Zlob infection,
it best be handled through deep scanning with a fully updated MBAM scanner,
read here:
http://www.computerforum.com/134231-can-i-remove-zlob-dnschanger-trojan-virus.html

This is the malicious dll inside the components folder in Firefox 3.x: C:\Program Files\Mozilla Firefox\components\iamfamous.dll and that starts running whenever Fx 3.x  is launched

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Mr.Agent

  • Guest
Re: New malware ruins Firefox...
« Reply #3 on: March 31, 2009, 11:31:30 PM »
Damien,
Maybe if your stupid enough to install that unapproved plug-in,
you deserve this headache.  ;D

Well some people didnt know really mush in computer so i didnt think they will learn at all what they need ! :D

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: New malware ruins Firefox...
« Reply #4 on: April 01, 2009, 12:30:17 AM »
Hi bob3160,

It isn't that simple, DNSChanger firefox is a Zlob infection,
it best be handled through deep scanning with a fully updated MBAM scanner,
read here:
http://www.computerforum.com/134231-can-i-remove-zlob-dnschanger-trojan-virus.html

This is the malicious dll inside the components folder in Firefox 3.x: C:\Program Files\Mozilla Firefox\components\iamfamous.dll and that starts running whenever Fx 3.x  is launched

polonus

Without installing that plugin, you wouln't have the malicious dll.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

alisonnic

  • Guest
Re: New malware ruins Firefox...
« Reply #5 on: June 09, 2009, 10:29:52 PM »
Hi bob3160,

It isn't that simple, DNSChanger firefox is a Zlob infection,
it best be handled through deep scanning with a fully updated MBAM scanner,
read here:
http://www.computerforum.com/134231-can-i-remove-zlob-dnschanger-trojan-virus.html

This is the malicious dll inside the components folder in Firefox 3.x: C:\Program Files\Mozilla Firefox\components\iamfamous.dll and that starts running whenever Fx 3.x  is launched

polonus

Without installing that plugin, you wouln't have the malicious dll.

I got this trojan; detected it this morning, but now that I know the symptoms I realize it has been running for at least two days.

I've cleaned the system using MBAM quick scan and am now doing a deep scan with MBAM.

How did I get this trojan? I am certain I did not install the PlayMP3z plugin. I am running a fully updated Avast! Free (at least, it was fully updated until the trojan got into the system.)

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: New malware ruins Firefox...
« Reply #6 on: June 09, 2009, 10:50:24 PM »
What does that have to do with firefox?

*Seriously, did you have to bump a topic. -_-*
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: New malware ruins Firefox...
« Reply #7 on: June 09, 2009, 10:56:19 PM »
I got this trojan; detected it this morning, but now that I know the symptoms I realize it has been running for at least two days.

I've cleaned the system using MBAM quick scan and am now doing a deep scan with MBAM.

How did I get this trojan? I am certain I did not install the PlayMP3z plugin. I am running a fully updated Avast! Free (at least, it was fully updated until the trojan got into the system.)
You're posting twice the same, just double the help effort...
http://forum.avast.com/index.php?topic=45998.msg385838#msg385838
The best things in life are free.