madison

Hardware 2.0

Adrian Kingsley-Hughes

UPDATE: Firefox add-on contained toxic Trojan code

By | February 5, 2010, 9:09am PST

Summary: Mozilla has issued users with a warning that two add-on available from the official Add-ons website (addons.mozilla.org) contained code that infected Windows PCs.

UPDATE: Mozilla has issued users with a warning that two add-on available from the official Add-ons website (addons.mozilla.org) contained code that infected Windows PCs.

Two One add-ons are affected:

  • Master Filer - Infected with a password-stealing Trojan called Win32.LdPinch.gen
  • Sothink Web Video Downloader - Infected with a backdoor Trojan called Win32.Bifrose.32.Bifrose

Important note: The Sothink Web Video Downloader was incorrectly identified by Mozilla as a trojan because the virus scanner used threw up a false-positive. This add-on is 100% safe.

Here’s what Mozilla has to say:

If a user installs one of these infected add-ons, the trojan would be executed when Firefox starts and the host computer would be infected by the trojan. Uninstalling these add-ons does not remove the trojan from a user’s system. Users with either of these add-ons should uninstall them immediately. Since uninstalling these extensions does not remove the trojan from a user’s system, an antivirus program should be used to scan and remove any infections.

It is believed that some 4,600 users have been infected.

Mozilla does scan all uploaded add-ons for malware, and blocks any that are infected. However, in this case the process failed. Now Mozilla has added two new malware detection tools to the scan chain to offer additional protection. It was at this stage that the malware hidden in the Sothink Web Video Downloader was discovered.

Important note: The Sothink Web Video Downloader was incorrectly identified by Mozilla as a trojan because the virus scanner used threw up a false-positive. This add-on is 100% safe.

Bottom line, it’s unwise to rely solely on scanning done by a third-party.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Adrian Kingsley-Hughes is an internationally published technology author who has devoted over a decade to helping users get the most from technology.

Disclosure

Adrian Kingsley-Hughes

All opinions expressed on Hardware 2.0 are those of Adrian Kingsley-Hughes. Every effort is made to ensure that the information posted is accurate. If you have any comments, queries or corrections, please contact Adrian via the email link here. Any possible conflicts of interest will be posted below. [Updated: February 23, 2010] - Adrian Kingsley-Hughes has no business relationships, affiliations, investments, or other actual/potential conflicts of interest relating to the content posted so far on this blog.

Biography

Adrian Kingsley-Hughes

Adrian Kingsley-Hughes is an internationally published technology author who has devoted over a decade to helping users get the most from technology -- whether that be by learning to program, building a PC from a pile of parts, or helping them get the most from their new MP3 player or digital camera.

Adrian has authored/co-authored technical books on a variety of topics, ranging from programming to building and maintaining PCs. His most recent books include "Build the Ultimate Custom PC", "Beginning Programming" and "The PC Doctor's Fix It Yourself Guide". He has also written training manuals that have been used by a number of Fortune 500 companies.

Adrian also runs a popular blog under the name The PC Doctor, where he covers a range of computer-related topics -- from security to repairing and upgrading.

Talkback Most Recent of 52 Talkback(s)

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources