HomeSecurityAdware disables Firefox's safe browsing feature

Adware disables Firefox's safe browsing feature

AdwareMintcast adware uses Firefox's user.js configuration files to remain undetected

Security researchers have identified two PuPs (potentially unwanted programs) that secretly disable Safe Browsing support in Firefox, allowing them to distribute unsolicited or arbitrary ads, and even
malware.

The two programs are named Shell&Services and Mintcast 3.0.1, they are essentially add-ons for the Firefox, Chrome & IE browsers and are installed without the user's consent as they are integrated into other software.

Both add-ons come with a new variant of the Mintcast adware, which, in addition to inserting ads into the user's browser while browsing legitimate websites, also secretly disables Safe Browsing in Firefox.

Safe Browsing is a service created by Google, and is also built into Safari and Firefox. Safe Browsing is nothing more than a list of untrusted URLs that have been previously found to be responsible for spreading malware. This list is constantly updated by Google and Mozilla and is utilized in real time, keeping users safe as they browse the web.

 

Mintcast hides in legitimate Firefox files

The Mintcast adware abuses Firefox's user.js file which can be used to store various browser settings in the form of code.

If the user.js file is not found in the “C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default” folder, the adware creates a new file which contains only three lines of code:

user_pref(“browser.safebrowsing.downloads.enabled”, false);
user_pref(“browser.safebrowsing.enabled”, false);
user_pref(“browser.safebrowsing.malware.enabled”, false);

These settings direct the browser to disable Safe Browsing when browsing the Web or downloading files, allowing the adware to redirect the user to malicious pages without the browser being able to display errors or warnings to the user.

The user.js file is executed every time the browser is started and remains active even if the user resets the settings. The only solution for the user to get rid of the malicious user.js is to remove the file from the above folder.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS