Help | Contact | Forum | Affiliates | Press Purchase Download Features Screenshots Demo

Malicious Firefox Add-ons Installed Trojans

Mozilla last night announced that two experimental Firefox add-ons, Master Filer and the Sothink Web Video Downloader version 4, infected victim PCs with Trojans when either add-on was installed.

The small-distribution extensions were previously available via Mozilla's add-on site, but have since been removed. According to Mozilla's post, the Master Filer add-on had been downloaded about 600 times and installed the Bifrose Trojan. The Sothink Web Video Downloader version 4 slipped in the LdPinch Trojan, and had been downloaded about 4,000 times.

According to the open-source organization, the malicious add-ons managed to sneak by the one malware scanner (unnamed in the post) used by Mozilla. The organization says it will now be scanning with two additional detection tools (also unnamed).

If you happen to have installed either of these malicious add-ons, note that removing the add-on will not remove any installed Trojan. You'll need to run a separate antivirus scan and disinfection to clean your system. Mozilla's post includes a list of antivirus software currently known to detect the particular Trojans involved.

This unfortunate incident makes clear why relying solely on one antivirus scanner is never a good idea, as no one program detects everything. Since this has happened at least once before with an infected Vietnamese language pack, I'm curious why Mozilla doesn't simply switch to uploading all add-on submissions to the free Virustotal.com, which uses about 40 different engines to scan each submission. I've also asked Mozilla which scanner it had been using. If I get that information I'll add it to this post.

Read Original Story



News 1 month ago



Related Stories:

Huge 'botnet' amputated, but criminals reconnect

Twitter's New URL Shortener to Fight Spam

Calif. man accused of NY Life extortion attempt

Webmasters Beware: The Other Kind Of Spam

California Man Accused Of Trying To Extort NY Life Insurance

Anthony Digati arrested for allegedly threatening New York Life with email spam attack

Energizer Duo software suffers backdoor Trojan bother

Qualys to scan Web sites for malware

McAfee Says Hackers Sought Companies’ ‘Crown Jewels’ (Update2)

McAfee: Source code is easy target within corporations