Monday, June 4, 2007

about malware injection into Firefox: "New.net Quick Search 7.48 extension"





from my latest post in the MozillaZine forum:
http://forums.mozillazine.org/viewtopic.php?t=555117&highlight=
" a couple of days ago I downloaded a theme for windows XP. The file came in the form of an executable. While warnings from both Windows Defender and AVG anti-spyware appeared very quickly during the installation process, allowing to remove files as well as many bad registry entries, I found out later, as I wanted to change one of my extensions options, that an unwanted extension got installed without my knowledge. I'm quite aware that Firefox can prevent an unwanted extension only when it directly comes from a website. I find this ability from third party programs to infect Firefox extremely worrying anyway.
Here is the link to the bad download:
http: //dl2.themexp.org/files/g/themexpdl1/4/7/74.exe
The bad extension that it installs silently is called New.net Quick Search 7.48
with id {AF8637B0-18E3-44D3-86B7-55E09D9C4261}.
I found more info in these sites:
http://www.symantec.com/security_response/writeup.jsp?docid=2004-020511-0558-99&tabid=2

http://www.cexx.org/newnet.htm


I want to add that I've installed this malware file a second time on purpose in order to keep tracks from what it does (logs etc...), what I had not done on the first time. So this second time, Comodo Firewall was loaded and sent me an alert that the bad extension was loaded into Firefox.
Since there seems to be no way to upload files with this post here, I cannot send you screenshots, unless you tell me how.

thanks for your attention
best regards."

and adding now:
now my request is clear: it's not all just about protecting our computers, using anti-malware programs or avoiding the bad links etc...but also: HOW CAN WE ACT LEGALLY AGAINST THOSE COMPANIES hiding behind websites, and making the malware stuff? did anyone here ever worry about that or is it just business as usual? When one knows exactly who and what, like I showed in my first post here today, does Mozilla do something against the attackers. Again not from inside Firefox, but legally, with lawyers etc...I gave an example of a website who deliberately injects malware into its downloads, to infect Windows, to infect both Intermet Explorer and Firefox. From what I've seen this website has been notorious for years for making malware. All anti-spyware programs detect it; there are articles everywhere about it. SO WHY ARE THEY STILL THERE? HOW COME THAT WEBSITES LIKE THEME.XP OR NEWDOT.NET STILL EXIST? IS THERE NO AUTHORITY TO SHUT THEIR SERVERS DOWN? AND EVENTUALLY TO ARREST THESE PEOPLE? I MEAN ACTUALLY SEND THEM TO JAIL?
Don't get me wrong, I do not want to attack anyone personaly in this forum, I'm just a bit upset about this atmosphere of acceptance, these attitudes of non-response, of perpetual passiveness. Yes thinking in terms of only protecting the PC, and never attacking the malware makers is passiveness. If that was done once in a while, security software companies would sell much less of their programs...is that the real issue?

No comments: