 SUMware Premium join:2002-05-21
2 edits | reply to Steve Re: Wow! Mozilla distributing infected code!
As has been stated, the infection occured in one language extension addon. The Firefox browser itself was/is not infected.
said by fatness :Wired News article quote: Trojan Horse code seemingly accidentally embedded in a language pack available on its Add-ons site. The virus's signature was unknown at the time, and thus passed Mozilla's testing of add-ons.
»https://bugzilla.mozilla.org/show_bug.cgi?id=432406 quote: Dave Miller (MoCo) 2008-05-06 01:47:24 PDT clamscan says: vietnamese_language_pack-2.0-fx-win.xpi: HTML.Xorer FOUND The file is dated February 18, the virus signature is date April 14, so we apparently had this in the wild for about 2 months before the scanners were detecting it.
Axel Hecht [:Pike] 2008-05-06 01:50:23 PDT FWIW, I think we're talking about http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview. aspx?idvirus=189095&sitepanda=particulares, right?
Dave Miller (MoCo) 2008-05-06 01:53:02 PDT The signature I found that said April 14 on it was HTML.Xorer.A. The one you just found is much more likely to be a match, and the window looks much smaller there.
Hai-Nam Nguyen (jcisio) 2008-05-06 02:01:26 PDT With info from Panda security, I think it just because the author's local network was infected with the virus, so it modified html files. The main virus is a Win32 program. The infected code just display annoying banner but it can't propagate. I think we might just remove the script and everything backs ok.
Justin Scott [:fligtar] 2008-05-06 10:20:09 PDT Since we seem to have determined it wasn't malicious on the part of the author, I've changed the add-on status to be in the sandbox and deleted both files. Jasper, please upload a new version without the virus and let us know and we'll check it out before pushing it public again.
Dan Guido 2008-05-07 21:07:14 PDT Was the source of this malicious code found?
Jasper Thái 2008-05-08 05:04:42 PDT Sorry for the inconvenient! I've found that translated help files was modified by a virus, come from China. I'm so busy these days, but I've cleaned up malicious code. The new fresh pack coming soon. Thanks!
|
|
  BeesTea Network Janitor Premium,VIP join:2003-03-08 00000
| said by SUMware :As has been stated, the infection occured in one language extension addon. The Firefox browser itself was/is not infected. An important thing to note. The extent of involvement for the Mozilla project directly was marginal. I don't know if the addons are even directly hosted with Mozilla. This is essentially 3rd party. -- Overpower, overcome. |
|
  alamarco o.O
join:2003-06-18 Windsor, ON clubs:
| reply to SUMware Thanks for that quote from Bugzilla SUMware . However I still don't really know what type of virus this was. Was it a trojan? Spyware/data mining? For those infected, what would be the harm?
Most articles just mention "virus" and nothing about the nature of it. |
|
 SUMware Premium join:2002-05-21
| From »www.pandasecurity.com/homeusers/···iculares
Brief Description Xorer.O is a worm that only affects computers that belong to the same local network.
Its main aim is to capture and modify the HTTP-type network packets that are sent from the computers.
As a consequence, the websites requested by the user will be displayed with alterations. However, this anomaly will not be displayed in the infected computer.
Xorer.O spreads through the local, removable and mapped drives, making copies of itself in them.
Visible Symptoms Xorer.O is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.
However, as Xorer.O only affects computers that belong to a local network, there will be symptoms in other computers.
In the computers that are part of the same network as the affected computer, the visited websites will have anomalies, a pop-up window will appear at the bottom right of the website, as in the image below:

Common name: Xorer.O Technical name: W32/Xorer.O.worm Threat level: Medium Type: Worm Effects: It only affects computers that belong to the same local network. It captures and modifies the HTTP-type network packets that are sent from these computers, in such a way that the websites visited by the user will be displayed with alterations. It spreads through the local, removable and mapped drives. Affected platforms: Windows 2003/XP/2000/NT/ME/98/95/3.X First detected on: Feb. 28, 2008 Detection updated on: March 1, 2008 |
|
  alamarco o.O
join:2003-06-18 Windsor, ON clubs: | Thank-you! I appreciate that information. |
|