MSFT exposes Firefox users to drive-by malware download

kodi

Geriatric Member
Guru
Gold Member
VIP
Local time
1:31 PM
Messages
1,355
Location
Sydney, Australia

My Computer My Computer

At a glance

Windows 10 Pro x64i7-4770K16Gig DDR3-2400Gigabyte GT740
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built Custom Computer.
OS
Windows 10 Pro x64
CPU
i7-4770K
Motherboard
Asus Z87 Sabertooth
Memory
16Gig DDR3-2400
Graphics Card(s)
Gigabyte GT740
Sound Card
Onboard
Monitor(s) Displays
Benq 27" - Dell 23' - Benq 22"
Screen Resolution
1680x1050
Hard Drives
Samsung 840 Pro 128g SSD
1xWestern Digital Caviar Green 1tb
2xWestern Digital Caviar Green 2 tb
PSU
Seasonic 760 watt Platinum
Case
Coolermaster Haf - X
Cooling
Noctua NH-C12P CPU Cooler
Keyboard
Logitech illuminated keyboard
Mouse
Logitech Perfomance MX
Internet Speed
Cable = speeds to 20Mbps downsteam and 512kbps upsteam
Antivirus
Avast Internet Security
Browser
Firefox
This would be a "goored" type of infection ... I'm not sure, but I think MalwareBytes' have been working on this bit of malware.

This is an example when scanned with Gooredfix:
=====Suspect Goored Entries=====

C:\Program Files\Mozilla Firefox\extensions\{E616A495-EBCA-4F9D-84B9-D04016D33CA9}

C:\Program Files\Mozilla Firefox\extensions\{775372EE-D619-4557-A9CC-44BB47A03EFA}

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.11\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I assume that now that the vulnerability in question has been fixed, this is now moot, except as a new warzone in Mozilla Foundation- Microsoft wars?
 

My Computer My Computer

At a glance

Windows 7 x64 Ultimate SP1Core i7-2630QM6 GB DDR3Nvidia GT 540M / Intel HD 3000 - Optimus swit...
Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
It's a DNS redirection (including the hosts file) exploit. It can be 'fixed'. I don't see it as a war between MS and FF, but if you do, then you have your reasons.

Known as the "goored" infection, this is a Firefox hijacker that targets a variety of search engines:
Google, Yahoo, Msn, AOL and Ask.

Usually, the first sign of infection is that upon starting Firefox, you receive a notification that "1 new Add-on has been installed", although you did not knowingly install anything. When using any of the above search engines, you may notice that during the search you see names like zfsearch.com, v1.adwarefeed.com flash past in your status bar
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It seems to me that you are kinda confused about the topic. This is about a Firefox attack vector opened up by a vulnerability that was just patched.

What the heck're you writing about?
 

My Computer My Computer

At a glance

Windows 7 x64 Ultimate SP1Core i7-2630QM6 GB DDR3Nvidia GT 540M / Intel HD 3000 - Optimus swit...
Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
No, I'm not confused ..... this is the application that was added by MS .... Reason to avoid!
Microsoft .NET Framework Assistant and Windows Presentation Foundation, all versions, for all applications. Reason: *remote code execution vulnerability

*Drive-by malware download can easily redirect DNS and change the Hosts file.

The 'fix' was posted here quite a while back. This is the article
Annoyances.org - Remove the Microsoft .NET Framework Assistant (ClickOnce) Firefox Extension

I was talking about 'Goored', which is a drive-by malware download. We have a tool to 'fix' the Goored malware.

Now, if you look at my above posts, do you see where I'm coming from?
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yeah, but the connection is a bit loose, don't you think?

Anyways, Mozilla blocked both the extension and the plugin on the eve off Saturday.
 

My Computer My Computer

At a glance

Windows 7 x64 Ultimate SP1Core i7-2630QM6 GB DDR3Nvidia GT 540M / Intel HD 3000 - Optimus swit...
Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
Back
Top