Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Immortality consists largely of boredom. -- Zefrem Cochrane, "Metamorphosis", stardate 3219.8


computers / alt.comp.software.firefox / Malware on Firefox?

SubjectAuthor
* Malware on Firefox?Boris
+- Re: Malware on Firefox?Boris
+- Re: Malware on Firefox?David LaRue
+* Re: Malware on Firefox?Carlos E.R.
|`* Re: Malware on Firefox?Frank Miller
| `- Re: Malware on Firefox?Carlos E.R.
+* Re: Malware on Firefox?VanguardLH
|`* Re: Malware on Firefox?Boris
| +- Re: Malware on Firefox?Boris
| `* Re: Malware on Firefox?VanguardLH
|  `* Re: Malware on Firefox?Boris
|   `* Re: Malware on Firefox?Boris
|    +* Re: Malware on Firefox?VanguardLH
|    |`- Re: Malware on Firefox?Jörg Lorenz
|    `* Re: Malware on Firefox?Boris
|     +- Re: Malware on Firefox?Nobody
|     +* Re: Malware on Firefox?VanguardLH
|     |`- Re: Malware on Firefox?Boris
|     `- Re: Malware on Firefox?Jörg Lorenz
`- Re: Malware on Firefox?Ralph Fox

1
Malware on Firefox?

<XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3312&group=alt.comp.software.firefox#3312

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: Boris@invalid.invalid (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Malware on Firefox?
Date: Thu, 28 Mar 2024 21:55:26 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 24
Message-ID: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
Injection-Date: Thu, 28 Mar 2024 21:55:26 +0100 (CET)
Injection-Info: dont-email.me; posting-host="8e4b6a7bc1187932ba02621e1d3c282b";
logging-data="4029734"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/U2Tq0wEUrp5FPmVgosxm2"
User-Agent: Xnews/2006.08.24
Cancel-Lock: sha1:huXERKsMN9eG9d3G5xiXlbTz/s8=
 by: Boris - Thu, 28 Mar 2024 21:55 UTC

Firefox 124.0.1 64-bit
No add-ons
No extensions

For a few weeks, once in a while, when I close Firefox, there's still a
Firefox window on my screen, with an add showing Elon Musk advertising
for CBD gummies. In this window, there's still the application menu in
the upper right, and I can click on any of the items within, and they all
work fine, including "New tab", which launches the 'real' Firefox. But
when I close Firefox, the add remains. Clicking on the "X" in the upper
right will close the add.

Today, the add changed to one for McAfee.

https://postimg.cc/gallery/DWz4XxD

Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
showed up. I started Malwarebytes, but it locked up the machine.

These 'adds' do not appear in any other browsers, and I don't get them on
any other machines running Firefox.

Has anyone experienced this? I've researched, but can't find anything.

Re: Malware on Firefox?

<XnsB14399CC0113BBorisinvalidinvalid@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3313&group=alt.comp.software.firefox#3313

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: Boris@invalid.invalid (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Thu, 28 Mar 2024 22:08:20 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 33
Message-ID: <XnsB14399CC0113BBorisinvalidinvalid@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
Injection-Date: Thu, 28 Mar 2024 22:08:21 +0100 (CET)
Injection-Info: dont-email.me; posting-host="8e4b6a7bc1187932ba02621e1d3c282b";
logging-data="4038093"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+QFJLfPxWjSgyPg2wVKC39"
User-Agent: Xnews/2006.08.24
Cancel-Lock: sha1:zgMJKBa7zw3zIqe5qdsHPnljuwg=
 by: Boris - Thu, 28 Mar 2024 22:08 UTC

Boris <Boris@invalid.invalid> wrote in
news:XnsB143979BFF462Borisinvalidinvalid@135.181.20.170:

> Firefox 124.0.1 64-bit
> No add-ons
> No extensions
>
> For a few weeks, once in a while, when I close Firefox, there's still
> a Firefox window on my screen, with an add showing Elon Musk
> advertising for CBD gummies. In this window, there's still the
> application menu in the upper right, and I can click on any of the
> items within, and they all work fine, including "New tab", which
> launches the 'real' Firefox. But when I close Firefox, the add
> remains. Clicking on the "X" in the upper right will close the add.
>
> Today, the add changed to one for McAfee.
>
> https://postimg.cc/gallery/DWz4XxD
>
> Pop-up blocking is enabled, but I don't think these are pop-ups. I
> ran Microsoft Defender Full scan and Offline scan, and F-Secure.
> Nothing showed up. I started Malwarebytes, but it locked up the
> machine.
>
> These 'adds' do not appear in any other browsers, and I don't get them
> on any other machines running Firefox.
>
> Has anyone experienced this? I've researched, but can't find
> anything.
>

Permissions>Notifications is also blocked. There are no websites
appearing in the 'exceptions' window.

Re: Malware on Firefox?

<XnsB143BC4ECA13Dhueydlltampabayrrcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3314&group=alt.comp.software.firefox#3314

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: huey.dll@tampabay.rr.com (David LaRue)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Thu, 28 Mar 2024 22:30:55 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 32
Message-ID: <XnsB143BC4ECA13Dhueydlltampabayrrcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
Injection-Date: Thu, 28 Mar 2024 22:30:56 +0100 (CET)
Injection-Info: dont-email.me; posting-host="99579ff7153fa4d09f8228b7fb60a6dd";
logging-data="4042973"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+66/sRS6SfqD7aG1q80XfJ"
User-Agent: Xnews/2006.08.24
Cancel-Lock: sha1:ZMpnWqN7N8Kmgbwn1svuaV/gNaM=
 by: David LaRue - Thu, 28 Mar 2024 22:30 UTC

Boris <Boris@invalid.invalid> wrote in
news:XnsB143979BFF462Borisinvalidinvalid@135.181.20.170:

> Firefox 124.0.1 64-bit
> No add-ons
> No extensions
>
> For a few weeks, once in a while, when I close Firefox, there's still a
> Firefox window on my screen, with an add showing Elon Musk advertising
> for CBD gummies. In this window, there's still the application menu in
> the upper right, and I can click on any of the items within, and they all
> work fine, including "New tab", which launches the 'real' Firefox. But
> when I close Firefox, the add remains. Clicking on the "X" in the upper
> right will close the add.
>
> Today, the add changed to one for McAfee.
>
> https://postimg.cc/gallery/DWz4XxD
>
> Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
> Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
> showed up. I started Malwarebytes, but it locked up the machine.
>
> These 'adds' do not appear in any other browsers, and I don't get them on
> any other machines running Firefox.
>
> Has anyone experienced this? I've researched, but can't find anything.
>

I've not seen anything like what you describe. I run AdBlocker and never see
ads. I do sometimes have to allow some sites to do things to enable sound
with streaming. I love Firefox.

Re: Malware on Firefox?

<ssahdkxops.ln2@Telcontar.valinor>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3316&group=alt.comp.software.firefox#3316

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Fri, 29 Mar 2024 00:25:48 +0100
Lines: 33
Message-ID: <ssahdkxops.ln2@Telcontar.valinor>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net HEDJwe42ZI5lAnm+fKhF6wML7fNNXkzGdcV055tK8gKSYRKbv8
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:YgSqJnYCHS5GjQgVDuKL3MQZYbo= sha256:TMjuK9QZxznq4M5NBN5Qu0nYJv+6m281RCMFhSoiwPk=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
 by: Carlos E.R. - Thu, 28 Mar 2024 23:25 UTC

On 2024-03-28 22:55, Boris wrote:
> Firefox 124.0.1 64-bit
> No add-ons
> No extensions
>
> For a few weeks, once in a while, when I close Firefox, there's still a
> Firefox window on my screen, with an add showing Elon Musk advertising
> for CBD gummies. In this window, there's still the application menu in
> the upper right, and I can click on any of the items within, and they all
> work fine, including "New tab", which launches the 'real' Firefox. But
> when I close Firefox, the add remains. Clicking on the "X" in the upper
> right will close the add.
>
> Today, the add changed to one for McAfee.
>
> https://postimg.cc/gallery/DWz4XxD
>
> Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
> Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
> showed up. I started Malwarebytes, but it locked up the machine.
>
> These 'adds' do not appear in any other browsers, and I don't get them on
> any other machines running Firefox.
>
> Has anyone experienced this? I've researched, but can't find anything.

Maybe you accepted notifications from some site. I don't know if FF
keeps a list of them somewhere.

--
Cheers, Carlos.

Re: Malware on Firefox?

<6606028E.3090406@backwurst.de>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3318&group=alt.comp.software.firefox#3318

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: miller@posteo.ee (Frank Miller)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Fri, 29 Mar 2024 00:51:42 +0100
Organization: Tschorkauer Zwetschgen-Pressen-Museum
Message-ID: <6606028E.3090406@backwurst.de>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
<ssahdkxops.ln2@Telcontar.valinor>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Injection-Info: solani.org;
logging-data="2075702"; mail-complaints-to="abuse@news.solani.org"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101
Thunderbird/38.7.2
Cancel-Lock: sha1:S1pUTIB3ekSHieWwHla0l0S8zUQ=
X-User-ID: eJwFwYEBACAEBMCVEt4bp9D+I3TnCkGFwWH+/Mli0q5sUhfGkn5G54qGRVUO0C1nN6LYVh//xBCz
In-Reply-To: <ssahdkxops.ln2@Telcontar.valinor>
 by: Frank Miller - Thu, 28 Mar 2024 23:51 UTC

Carlos E.R. wrote:
> On 2024-03-28 22:55, Boris wrote:
>> Firefox 124.0.1 64-bit
>> No add-ons
>> No extensions
>>
>> For a few weeks, once in a while, when I close Firefox, there's still a
>> Firefox window on my screen, with an add showing Elon Musk advertising
>> for CBD gummies.

[..snip..]
> Maybe you accepted notifications from some site. I don't know if FF
> keeps a list of them somewhere.

Settings - Privacy&Security - Permissions: Notifications

Re: Malware on Firefox?

<pzk2lacrtyja$.dlg@v.nguard.lh>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3319&group=alt.comp.software.firefox#3319

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!newsfeed.bofh.team!2.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Thu, 28 Mar 2024 20:29:51 -0500
Organization: Usenet Elder
Lines: 60
Sender: V@nguard.LH
Message-ID: <pzk2lacrtyja$.dlg@v.nguard.lh>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net JZRqc2nNpaTQoBl9vt5pOgPFTQnerbzQwKzbdI0HXzxl5sX16c
Keywords: VanguardLH,VLH
Cancel-Lock: sha1:cpbZMj3ylTHAbdTyXslzd40zZiI= sha256:WBktwrGzFJdXXMs8G4Y3+Wk0BxZyKz+T8ExQF1PL40s=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Fri, 29 Mar 2024 01:29 UTC

Boris <Boris@invalid.invalid> wrote:

> Firefox 124.0.1 64-bit
> No add-ons
> No extensions
>
> For a few weeks, once in a while, when I close Firefox, there's still a
> Firefox window on my screen, with an add showing Elon Musk advertising
> for CBD gummies. In this window, there's still the application menu in
> the upper right, and I can click on any of the items within, and they all
> work fine, including "New tab", which launches the 'real' Firefox. But
> when I close Firefox, the add remains. Clicking on the "X" in the upper
> right will close the add.
>
> Today, the add changed to one for McAfee.
>
> https://postimg.cc/gallery/DWz4XxD
>
> Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
> Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
> showed up. I started Malwarebytes, but it locked up the machine.
>
> These 'adds' do not appear in any other browsers, and I don't get them on
> any other machines running Firefox.
>
> Has anyone experienced this? I've researched, but can't find anything.

When you think you have exited Firefox, is firefox.exe still listed in
Task Manager?

A possibility for your problem is the use of service workers. They are
disabled in Private mode. See:

https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API

Disable service workers. In about:config, edit:

dom.serviceWorkders.enabled = FALSE

You can go to about:serviceworkers to see a list of registered workers,
and about:debugging#/runtime/this-firefox, too. I have them disabled,
so the internal page reports "Service Workers are not enabled". If not
disabled, about:serviceworkers will list them, and there will be an
Unregister button to delete them (until you again visit the web page
that registers them). Service workers do not automatically update, so
you have to unregister them to re-register to get a later version.

I don't know what is the current vulnerability state of service workers,
but they have had past vulnerabilities.

https://portswigger.net/daily-swig/the-service-worker-hiding-in-your-browser
https://book.hacktricks.xyz/pentesting-web/xss-cross-site-scripting/abusing-service-workers
https://www.akamai.com/blog/security/abusing-the-service-workers-api

They also provide in-domain tracking. They cannot be used cross-domain
(same-domain origin policy is enforced), but are lurking in your web
browser upon revisit to the same domain.

Try the about:config setting, and reload Firefox to see the problem
persists. Have you also flushed all locally cached data for Firefox?

Re: Malware on Firefox?

<pn7c0j9p7k7d4124jsfgfrq1edivpn0iuk@4ax.com>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3321&group=alt.comp.software.firefox#3321

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx46.iad.POSTED!not-for-mail
From: -rf-nz-@-.invalid (Ralph Fox)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Message-ID: <pn7c0j9p7k7d4124jsfgfrq1edivpn0iuk@4ax.com>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
User-Agent: ForteAgent/8.00.32.1272
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Face: 5gSW~"1=jGDo(BXfTrgL2BnC3tUB_\d0u@mP~wA1fvK`z8I[>1jXVVZ!N6ittQ.K<5!i3l> ==jcyAk.[B>kLg8TY{+8%edZ(le:ncPt%s8Pr?]QXNXO]0RC#V_zt|%>=bt>rZ2iCI^-yl7Be(]Ep> OfyI!3Bf|e
Lines: 56
X-Complaints-To: abuse@easynews.com
Organization: Forte - www.forteinc.com
X-Complaints-Info: Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly.
Date: Fri, 29 Mar 2024 14:53:27 +1300
X-Received-Bytes: 3000
 by: Ralph Fox - Fri, 29 Mar 2024 01:53 UTC

On Thu, 28 Mar 2024 21:55:26 -0000 (UTC), Boris wrote:

> Firefox 124.0.1 64-bit
> No add-ons
> No extensions
>
> For a few weeks, once in a while, when I close Firefox, there's still a
> Firefox window on my screen, with an add showing Elon Musk advertising
> for CBD gummies. In this window, there's still the application menu in
> the upper right, and I can click on any of the items within, and they all
> work fine, including "New tab", which launches the 'real' Firefox. But
> when I close Firefox, the add remains. Clicking on the "X" in the upper
> right will close the add.
>
> Today, the add changed to one for McAfee.
>
> https://postimg.cc/gallery/DWz4XxD
>
> Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
> Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
> showed up. I started Malwarebytes, but it locked up the machine.
>
> These 'adds' do not appear in any other browsers, and I don't get them on
> any other machines running Firefox.
>
> Has anyone experienced this? I've researched, but can't find anything.

Pop-up blocking blocks *unrequested* windows. It does not block
windows that open in response to a link you clicked. A few sites
are quite devious about opening pop-ups when you click on what
appears to be a legitimate button or link. If the Firefox preference
"dom.disable_window_flip" is set to false [1], the site can easily
hide this window behind your normal browser window so you may not
know it has been opened until much later.

I have not seen this for several years. I have seen it in the more
distant past with a few devious sites.

I presume you are closing Firefox with the red 'X' in the upper right.
Do you still get this ad (ADvertisement) if you close Firefox with the
"File >> Exit" menu, or with Ctrl+Shift+Q ? The red 'X' closes only
the current Firefox window while "File >> Exit" and Ctrl+Shift+Q close
all Firefox windows.

____
REFERENCES
[1] <https://support.mozilla.org/en-US/questions/960546>

--
Kind regards
Ralph Fox
🦊

Out of sight out of mind.

Re: Malware on Firefox?

<1pjhdkxqsa.ln2@Telcontar.valinor>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3322&group=alt.comp.software.firefox#3322

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!newsfeed.bofh.team!2.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Fri, 29 Mar 2024 02:57:21 +0100
Lines: 22
Message-ID: <1pjhdkxqsa.ln2@Telcontar.valinor>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
<ssahdkxops.ln2@Telcontar.valinor> <6606028E.3090406@backwurst.de>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 7wUin70oqBwZQyRe5/ZEognAcy+nmH8T9d2fJ8IsrdQDhFr007
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:4jOImdta9T7BprYYMGZoHaiWo1A= sha256:8d44CjR7sdH2UFdAV3ebbud7+59TeCUZlmfFX1soiKQ=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <6606028E.3090406@backwurst.de>
 by: Carlos E.R. - Fri, 29 Mar 2024 01:57 UTC

On 2024-03-29 00:51, Frank Miller wrote:
> Carlos E.R. wrote:
>> On 2024-03-28 22:55, Boris wrote:
>>> Firefox 124.0.1 64-bit
>>> No add-ons
>>> No extensions
>>>
>>> For a few weeks, once in a while, when I close Firefox, there's still a
>>> Firefox window on my screen, with an add showing Elon Musk advertising
>>> for CBD gummies.
>
> [..snip..]
>> Maybe you accepted notifications from some site. I don't know if FF
>> keeps a list of them somewhere.
>
> Settings - Privacy&Security - Permissions: Notifications

Ah, thanks.

--
Cheers, Carlos.

Re: Malware on Firefox?

<XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3323&group=alt.comp.software.firefox#3323

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Mon, 1 Apr 2024 21:49:49 -0000 (UTC)
Organization: This space for rent.
Lines: 73
Message-ID: <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh>
Injection-Date: Mon, 01 Apr 2024 21:49:50 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="279d0419f59ac9fc934ded9c264b8b78";
logging-data="2876853"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX187aeOjDyKM2Gwp4ANAx5ge"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:+iQtaHhXNHQTbZFC3yMs/g767nw=
 by: Boris - Mon, 1 Apr 2024 21:49 UTC

VanguardLH <V@nguard.LH> wrote in news:pzk2lacrtyja$.dlg@v.nguard.lh:

> Boris <Boris@invalid.invalid> wrote:
>
>> Firefox 124.0.1 64-bit
>> No add-ons
>> No extensions
>>
>> For a few weeks, once in a while, when I close Firefox, there's still a
>> Firefox window on my screen, with an add showing Elon Musk advertising
>> for CBD gummies. In this window, there's still the application menu in
>> the upper right, and I can click on any of the items within, and they
>> all work fine, including "New tab", which launches the 'real' Firefox.
>> But when I close Firefox, the add remains. Clicking on the "X" in the
>> upper right will close the add.
>>
>> Today, the add changed to one for McAfee.
>>
>> https://postimg.cc/gallery/DWz4XxD
>>
>> Pop-up blocking is enabled, but I don't think these are pop-ups. I ran
>> Microsoft Defender Full scan and Offline scan, and F-Secure. Nothing
>> showed up. I started Malwarebytes, but it locked up the machine.
>>
>> These 'adds' do not appear in any other browsers, and I don't get them
>> on any other machines running Firefox.
>>
>> Has anyone experienced this? I've researched, but can't find anything.
>
> When you think you have exited Firefox, is firefox.exe still listed in
> Task Manager?

Yes, Task Manager shows Firefox is still running.

>
> A possibility for your problem is the use of service workers. They are
> disabled in Private mode. See:
>
> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>
> Disable service workers. In about:config, edit:
>
> dom.serviceWorkders.enabled = FALSE

Done. Now I'll wait and see.

https://postimg.cc/T5r5CxCY

>
> You can go to about:serviceworkers to see a list of registered workers,
> and about:debugging#/runtime/this-firefox, too. I have them disabled,
> so the internal page reports "Service Workers are not enabled". If not
> disabled, about:serviceworkers will list them, and there will be an
> Unregister button to delete them (until you again visit the web page
> that registers them). Service workers do not automatically update, so
> you have to unregister them to re-register to get a later version.
>
> I don't know what is the current vulnerability state of service workers,
> but they have had past vulnerabilities.
>
> https://portswigger.net/daily-swig/the-service-worker-hiding-in-your-brow
> ser
> https://book.hacktricks.xyz/pentesting-web/xss-cross-site-scripting/abusi
> ng-service-workers
> https://www.akamai.com/blog/security/abusing-the-service-workers-api
>
> They also provide in-domain tracking. They cannot be used cross-domain
> (same-domain origin policy is enforced), but are lurking in your web
> browser upon revisit to the same domain.
>
> Try the about:config setting, and reload Firefox to see the problem
> persists. Have you also flushed all locally cached data for Firefox?

Re: Malware on Firefox?

<XnsB147973C18AB8nospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3324&group=alt.comp.software.firefox#3324

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Mon, 1 Apr 2024 21:52:01 -0000 (UTC)
Organization: This space for rent.
Lines: 8
Message-ID: <XnsB147973C18AB8nospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>
Injection-Date: Mon, 01 Apr 2024 21:52:01 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="279d0419f59ac9fc934ded9c264b8b78";
logging-data="2876853"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19NXVQUyI+MHqZIgUKwBNij"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:P5QRJ65W+lfIE+eFZXIhLvrRik8=
 by: Boris - Mon, 1 Apr 2024 21:52 UTC

Boris <nospam@invalid.com> wrote in news:XnsB14796DCC11B6nospaminvalidcom@
135.181.20.170:

> https://postimg.cc/T5r5CxCY

serviceWorkers:

https://postimg.cc/SY0z6RLv

Re: Malware on Firefox?

<tpiujuglgwly$.dlg@v.nguard.lh>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3325&group=alt.comp.software.firefox#3325

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Mon, 1 Apr 2024 19:33:34 -0500
Organization: Usenet Elder
Lines: 25
Sender: V@nguard.LH
Message-ID: <tpiujuglgwly$.dlg@v.nguard.lh>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net RBhfed6apsHa5nq7oM2pXwzM8bMebgIW750MXcLE9kkCJrbkMc
Keywords: VanguardLH,VLH
Cancel-Lock: sha1:B+V88lYHaRkBMVGiX4LjBuYBfmk= sha256:kbk2NGAh41Tfry84+RFIJXC4QJTPl7/1PGJJWNx/4OI=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Tue, 2 Apr 2024 00:33 UTC

Boris <nospam@invalid.com> wrote:

> VanguardLH <V@nguard.LH> wrote:
>
>> A possibility for your problem is the use of service workers. They
>> are disabled in Private mode. See:
>>
>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>
>> Disable service workers. In about:config, edit:
>>
>> dom.serviceWorkders.enabled = FALSE
>
> Done. Now I'll wait and see.

As verification, after changing the setting to false, and restarting
Firefox, go to:

about:serviceworkers

You should get a message that service workers are not enabled.

Later when you think you have exited Firefox, and wait maybe a minute,
but there are still firefox.exe process listed in Task Manager, it
didn't really exit. Something else is keeping it loaded.

Re: Malware on Firefox?

<XnsB14993D8E8F44nospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3328&group=alt.comp.software.firefox#3328

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Wed, 3 Apr 2024 21:32:01 -0000 (UTC)
Organization: This space for rent.
Lines: 36
Message-ID: <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh>
Injection-Date: Wed, 03 Apr 2024 21:32:01 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="15f9d9ca20f3a6220e280ddcfcab93fe";
logging-data="183978"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/H9O6GgKjL/XIVctIrQaes"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:adQVjvFmjl1x8Sq7ODs/SnunGjg=
 by: Boris - Wed, 3 Apr 2024 21:32 UTC

VanguardLH <V@nguard.LH> wrote in news:tpiujuglgwly$.dlg@v.nguard.lh:

> Boris <nospam@invalid.com> wrote:
>
>> VanguardLH <V@nguard.LH> wrote:
>>
>>> A possibility for your problem is the use of service workers. They
>>> are disabled in Private mode. See:
>>>
>>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>>
>>> Disable service workers. In about:config, edit:
>>>
>>> dom.serviceWorkders.enabled = FALSE
>>
>> Done. Now I'll wait and see.
>
> As verification, after changing the setting to false, and restarting
> Firefox, go to:
>
> about:serviceworkers
>
> You should get a message that service workers are not enabled.

Yes, I got that message.

>
> Later when you think you have exited Firefox, and wait maybe a minute,
> but there are still firefox.exe process listed in Task Manager, it
> didn't really exit. Something else is keeping it loaded.

I exited, waited a while, and Firefox was not running in Task Manager.

It's been 48 hours, and the the pop-ups, new or old, have not reappeared.

Many thanks.

Re: Malware on Firefox?

<XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3334&group=alt.comp.software.firefox#3334

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Fri, 5 Apr 2024 23:18:27 -0000 (UTC)
Organization: This space for rent.
Lines: 48
Message-ID: <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170>
Injection-Date: Fri, 05 Apr 2024 23:18:28 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="7bebbd9dd30ec25194c4dfe8b0b28d6d";
logging-data="1754077"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+MnTfJSytjBcCbr6SG6qWy"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:CzddZnvm8LemeG2yzf0KN5MB4kE=
 by: Boris - Fri, 5 Apr 2024 23:18 UTC

Boris <nospam@invalid.com> wrote in news:XnsB14993D8E8F44nospaminvalidcom@
135.181.20.170:

> VanguardLH <V@nguard.LH> wrote in news:tpiujuglgwly$.dlg@v.nguard.lh:
>
>> Boris <nospam@invalid.com> wrote:
>>
>>> VanguardLH <V@nguard.LH> wrote:
>>>
>>>> A possibility for your problem is the use of service workers. They
>>>> are disabled in Private mode. See:
>>>>
>>>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>>>
>>>> Disable service workers. In about:config, edit:
>>>>
>>>> dom.serviceWorkders.enabled = FALSE
>>>
>>> Done. Now I'll wait and see.
>>
>> As verification, after changing the setting to false, and restarting
>> Firefox, go to:
>>
>> about:serviceworkers
>>
>> You should get a message that service workers are not enabled.
>
> Yes, I got that message.
>
>>
>> Later when you think you have exited Firefox, and wait maybe a minute,
>> but there are still firefox.exe process listed in Task Manager, it
>> didn't really exit. Something else is keeping it loaded.
>
> I exited, waited a while, and Firefox was not running in Task Manager.
>
> It's been 48 hours, and the the pop-ups, new or old, have not reappeared.
>
> Many thanks.

The pop-up is back:

https://postimg.cc/jLTvg834

It's not causing any problems (that I know of). I just wonder how it got
started. From my reading of 'service workers', I wonder if the pop-up is
triggered by an infected website that I visit. Maybe I'll just visit one
site per browsing session and see when the pop-up appears.

Re: Malware on Firefox?

<1bsm55rxu870u$.dlg@v.nguard.lh>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3335&group=alt.comp.software.firefox#3335

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Fri, 5 Apr 2024 19:49:36 -0500
Organization: Usenet Elder
Lines: 18
Sender: V@nguard.LH
Message-ID: <1bsm55rxu870u$.dlg@v.nguard.lh>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170> <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 4UXtQsnEslT2TfGsBYD3Zw5reQSs2w9QE+JP+OLYnHfw7TFk4R
Keywords: VanguardLH,VLH
Cancel-Lock: sha1:u7UEkB0MT5iaIvyRUYb+3nSZXxI= sha256:b1QTVLVM2J56kp9g5M8K5Bsf19rTYyzAA4wKhyZDPzY=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Sat, 6 Apr 2024 00:49 UTC

Boris <nospam@invalid.com> wrote:

> The pop-up is back:
>
> https://postimg.cc/jLTvg834
>
> It's not causing any problems (that I know of). I just wonder how it got
> started. From my reading of 'service workers', I wonder if the pop-up is
> triggered by an infected website that I visit. Maybe I'll just visit one
> site per browsing session and see when the pop-up appears.

The URL you show in the first screenshot had "/ads_" in its path, so
you're seeing some ad. If the second screenshot is what you see, that's
rogueware pretending you have McAfee. I bet if you hover over the
hyperlinks in that ad that they do not point to a McAfee web site.
You're being phished.

You don't use an adblocker? I use uBlock Origin (in expert mode).

Re: Malware on Firefox?

<uuqtuh$1upt0$1@dont-email.me>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3336&group=alt.comp.software.firefox#3336

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: hugybear@gmx.net (Jörg Lorenz)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Sat, 6 Apr 2024 09:34:40 +0200
Organization: Camembert Normand au Lait Cru
Lines: 25
Message-ID: <uuqtuh$1upt0$1@dont-email.me>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
<pzk2lacrtyja$.dlg@v.nguard.lh>
<XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>
<tpiujuglgwly$.dlg@v.nguard.lh>
<XnsB14993D8E8F44nospaminvalidcom@135.181.20.170>
<XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>
<1bsm55rxu870u$.dlg@v.nguard.lh>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 06 Apr 2024 07:34:41 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="9d768fa2564eb3dc326904bed6954249";
logging-data="2058144"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18YLNWg6sQs3rgtsEGnoEyD+tE1bAXy3cw="
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:115.0)
Gecko/20100101 Thunderbird/115.9.0
Cancel-Lock: sha1:fRCn/+WHHo2Doq3OOPFz33yzAwg=
In-Reply-To: <1bsm55rxu870u$.dlg@v.nguard.lh>
Content-Language: de-CH
 by: Jörg Lorenz - Sat, 6 Apr 2024 07:34 UTC

On 06.04.2024 02:49, VanguardLH wrote:
> Boris <nospam@invalid.com> wrote:
>
>> The pop-up is back:
>>
>> https://postimg.cc/jLTvg834
>>
>> It's not causing any problems (that I know of). I just wonder how it got
>> started. From my reading of 'service workers', I wonder if the pop-up is
>> triggered by an infected website that I visit. Maybe I'll just visit one
>> site per browsing session and see when the pop-up appears.
>
> The URL you show in the first screenshot had "/ads_" in its path, so
> you're seeing some ad. If the second screenshot is what you see, that's
> rogueware pretending you have McAfee. I bet if you hover over the
> hyperlinks in that ad that they do not point to a McAfee web site.
> You're being phished.
>
> You don't use an adblocker? I use uBlock Origin (in expert mode).

FACK. Add NoScript to it as well and you will eyperience peace and quiet.

--
"Ave Caesar! Morituri te salutant!"

Re: Malware on Firefox?

<XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3337&group=alt.comp.software.firefox#3337

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Sat, 6 Apr 2024 22:45:43 -0000 (UTC)
Organization: This space for rent.
Lines: 82
Message-ID: <XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170> <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>
Injection-Date: Sat, 06 Apr 2024 22:45:44 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="1bd22674146b9a29274fe4cd0fa0c37d";
logging-data="2476623"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+Uk8GZp4AWft1bQ65NL3M7"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:BgKtdrGIsC1/ytVYAMN9jefmVvI=
 by: Boris - Sat, 6 Apr 2024 22:45 UTC

Boris <nospam@invalid.com> wrote in
news:XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170:

> Boris <nospam@invalid.com> wrote in
> news:XnsB14993D8E8F44nospaminvalidcom@ 135.181.20.170:
>
>> VanguardLH <V@nguard.LH> wrote in news:tpiujuglgwly$.dlg@v.nguard.lh:
>>
>>> Boris <nospam@invalid.com> wrote:
>>>
>>>> VanguardLH <V@nguard.LH> wrote:
>>>>
>>>>> A possibility for your problem is the use of service workers. They
>>>>> are disabled in Private mode. See:
>>>>>
>>>>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>>>>
>>>>> Disable service workers. In about:config, edit:
>>>>>
>>>>> dom.serviceWorkders.enabled = FALSE
>>>>
>>>> Done. Now I'll wait and see.
>>>
>>> As verification, after changing the setting to false, and restarting
>>> Firefox, go to:
>>>
>>> about:serviceworkers
>>>
>>> You should get a message that service workers are not enabled.
>>
>> Yes, I got that message.
>>
>>>
>>> Later when you think you have exited Firefox, and wait maybe a minute,
>>> but there are still firefox.exe process listed in Task Manager, it
>>> didn't really exit. Something else is keeping it loaded.
>>
>> I exited, waited a while, and Firefox was not running in Task Manager.
>>
>> It's been 48 hours, and the the pop-ups, new or old, have not
>> reappeared.
>>
>> Many thanks.
>
> The pop-up is back:
>
> https://postimg.cc/jLTvg834
>
> It's not causing any problems (that I know of). I just wonder how it
> got started. From my reading of 'service workers', I wonder if the
> pop-up is triggered by an infected website that I visit. Maybe I'll
> just visit one site per browsing session and see when the pop-up
> appears.

I began visiting each of my usual sites, one at a time per browsing
session, to see if a pop-up would appear, and if so, with which website.
When I visited "www.americanthinker.com", the Elon Musk selling CBD popped
up. (The URL in this pop-up is 761 characters long.) Clicking on any
link on this pop-up's page takes one to the same place each time, a page
to order CBD gummies. The pop-up's domain in the URL is
"rightdailyfeed.com".

When I go to https://www.rightdailyfeed.com, I'm taken to an empty
webpage, with "code: 3465468754"in the upper left hand corner.

A search on "code: 3465468754" takes me to some google images, one of
which is "rightdailyfeed.com Traffic Analytics - Similarweb".

Clicking on that image takes me to
https://www.similarweb.com/website/rightdailyfeed.com/.

If I scroll down the page to "rightdailyfeed.com Target Audience", there's
americanthinker.com, the site that when I went there, Elon's CBD pop-up
appeared.

https://postimg.cc/gallery/4HQKgmY
But, if I cruise around similarweb's page a little more, I see lots of
other well known websites I occasionally, such as finance, health care,
insurance, etc., so these other sites may trigger a pop-up. I just don't
understand how this all works.

I'm going to install an ad blocker, and see what happens.

Re: Malware on Firefox?

<h1m31jt2rsf7u2blnv45c086iivkvneag8@4ax.com>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3338&group=alt.comp.software.firefox#3338

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jock@soccer.com (Nobody)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Sat, 06 Apr 2024 16:25:41 -0700
Organization: A noiseless patient Spider
Lines: 65
Message-ID: <h1m31jt2rsf7u2blnv45c086iivkvneag8@4ax.com>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170> <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170> <XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 06 Apr 2024 23:25:42 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="89dd4a6296ca4edfaeb258f087f3218e";
logging-data="2492696"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18jPLnR87stESylKBlIzOKw"
User-Agent: ForteAgent/8.00.32.1272
Cancel-Lock: sha1:ifu43x70qOHjlHXwNg2xf+0Xt54=
 by: Nobody - Sat, 6 Apr 2024 23:25 UTC

On Sat, 6 Apr 2024 22:45:43 -0000 (UTC), Boris <nospam@invalid.com>
wrote:

>Boris <nospam@invalid.com> wrote in
>news:XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170:
>
>> Boris <nospam@invalid.com> wrote in
>> news:XnsB14993D8E8F44nospaminvalidcom@ 135.181.20.170:
>>
>>> VanguardLH <V@nguard.LH> wrote in news:tpiujuglgwly$.dlg@v.nguard.lh:
>>>
>>>> Boris <nospam@invalid.com> wrote:
>>>>
>>>>> VanguardLH <V@nguard.LH> wrote:
>>>>>
>>>>>> A possibility for your problem is the use of service workers. They
>>>>>> are disabled in Private mode. See:
>>>>>>
>>>>>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>>>>>
>>>>>> Disable service workers. In about:config, edit:
>>>>>>
>>>>>> dom.serviceWorkders.enabled = FALSE
>>>>>
>>>>> Done. Now I'll wait and see.
>>>>
>>>> As verification, after changing the setting to false, and restarting
>>>> Firefox, go to:
>>>>
>>>> about:serviceworkers
>>>>
>>>> You should get a message that service workers are not enabled.
>>>
>>> Yes, I got that message.
>>>
>>>>
>>>> Later when you think you have exited Firefox, and wait maybe a minute,
>>>> but there are still firefox.exe process listed in Task Manager, it
>>>> didn't really exit. Something else is keeping it loaded.
>>>
>>> I exited, waited a while, and Firefox was not running in Task Manager.
>>>
>>> It's been 48 hours, and the the pop-ups, new or old, have not
>>> reappeared.
>>>
>>> Many thanks.
>>
>> The pop-up is back:
>>
>> https://postimg.cc/jLTvg834
>>
>> It's not causing any problems (that I know of). I just wonder how it
>> got started. From my reading of 'service workers', I wonder if the
>> pop-up is triggered by an infected website that I visit. Maybe I'll
>> just visit one site per browsing session and see when the pop-up
>> appears.

<Rather Large Surgical Incision>

>I'm going to install an ad blocker, and see what happens.

So after this whole lengthy rigmarole, you admit to not having an *ad
blocker* installed/running?

<sigh>

Re: Malware on Firefox?

<57l7kmib4bgm.dlg@v.nguard.lh>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3339&group=alt.comp.software.firefox#3339

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Sat, 6 Apr 2024 22:12:32 -0500
Organization: Usenet Elder
Lines: 36
Sender: V@nguard.LH
Message-ID: <57l7kmib4bgm.dlg@v.nguard.lh>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170> <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170> <XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net HE6iBDj46P4H1/VJxHC+GwxZmiENZzY3URDVamuvuWj4ldqieb
Keywords: VanguardLH,VLH
Cancel-Lock: sha1:ug0Ux06fQwUUWktirMeWbyKKpBk= sha256:M5Cigq/mrV7heGbXZjadCKgtvajaTfoW4HJquxELMZs=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Sun, 7 Apr 2024 03:12 UTC

Boris <nospam@invalid.com> wrote:

> I began visiting each of my usual sites, one at a time per browsing
> session, to see if a pop-up would appear, and if so, with which website.
> When I visited "www.americanthinker.com", the Elon Musk selling CBD popped
> up. (The URL in this pop-up is 761 characters long.) Clicking on any
> link on this pop-up's page takes one to the same place each time, a page
> to order CBD gummies. The pop-up's domain in the URL is
> "rightdailyfeed.com".
>
> When I go to https://www.rightdailyfeed.com, I'm taken to an empty
> webpage, with "code: 3465468754"in the upper left hand corner.
>
> A search on "code: 3465468754" takes me to some google images, one of
> which is "rightdailyfeed.com Traffic Analytics - Similarweb".
>
> Clicking on that image takes me to
> https://www.similarweb.com/website/rightdailyfeed.com/.
>
> If I scroll down the page to "rightdailyfeed.com Target Audience", there's
> americanthinker.com, the site that when I went there, Elon's CBD pop-up
> appeared.
>
> https://postimg.cc/gallery/4HQKgmY
> But, if I cruise around similarweb's page a little more, I see lots of
> other well known websites I occasionally, such as finance, health care,
> insurance, etc., so these other sites may trigger a pop-up. I just don't
> understand how this all works.
>
> I'm going to install an ad blocker, and see what happens.

I went to americanthinker.com, and go no popups. I use uBlock Origin
(in expert mode), and my choice of blacklist subscriptions might not
match those selected by another user of uBO. Besides domain blocks,
many URL substrings are also included in the filters of many blacklists,
like paths or args that point to possible ad sources.

Re: Malware on Firefox?

<uutb3h$2k173$2@dont-email.me>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3340&group=alt.comp.software.firefox#3340

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: hugybear@gmx.net (Jörg Lorenz)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Sun, 7 Apr 2024 07:31:29 +0200
Organization: Camembert Normand au Lait Cru
Lines: 66
Message-ID: <uutb3h$2k173$2@dont-email.me>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170>
<pzk2lacrtyja$.dlg@v.nguard.lh>
<XnsB14796DCC11B6nospaminvalidcom@135.181.20.170>
<tpiujuglgwly$.dlg@v.nguard.lh>
<XnsB14993D8E8F44nospaminvalidcom@135.181.20.170>
<XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170>
<XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 07 Apr 2024 05:31:30 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="d6b35a8410a86fb41d7a254c5f617a6a";
logging-data="2753763"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/RmF3qHSyMakuAj23iHBckVfGFt5ERoVo="
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:115.0)
Gecko/20100101 Thunderbird/115.9.0
Cancel-Lock: sha1:QFD6Pa8gQGktyC/I8oCTAeTSdQs=
Content-Language: de-CH
In-Reply-To: <XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170>
 by: Jörg Lorenz - Sun, 7 Apr 2024 05:31 UTC

Am 07.04.24 um 00:45 schrieb Boris:
> Boris <nospam@invalid.com> wrote in
> news:XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170:
>
>> Boris <nospam@invalid.com> wrote in
>> news:XnsB14993D8E8F44nospaminvalidcom@ 135.181.20.170:
>>
>>> VanguardLH <V@nguard.LH> wrote in news:tpiujuglgwly$.dlg@v.nguard.lh:
>>>
>>>> Boris <nospam@invalid.com> wrote:
>>>>
>>>>> VanguardLH <V@nguard.LH> wrote:
>>>>>
>>>>>> A possibility for your problem is the use of service workers. They
>>>>>> are disabled in Private mode. See:
>>>>>>
>>>>>> https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API
>>>>>>
>>>>>> Disable service workers. In about:config, edit:
>>>>>>
>>>>>> dom.serviceWorkders.enabled = FALSE
>>>>>
>>>>> Done. Now I'll wait and see.
>>>>
>>>> As verification, after changing the setting to false, and restarting
>>>> Firefox, go to:
>>>>
>>>> about:serviceworkers
>>>>
>>>> You should get a message that service workers are not enabled.
>>>
>>> Yes, I got that message.
>>>
>>>>
>>>> Later when you think you have exited Firefox, and wait maybe a minute,
>>>> but there are still firefox.exe process listed in Task Manager, it
>>>> didn't really exit. Something else is keeping it loaded.
>>>
>>> I exited, waited a while, and Firefox was not running in Task Manager.
>>>
>>> It's been 48 hours, and the the pop-ups, new or old, have not
>>> reappeared.
>>>
>>> Many thanks.
>>
>> The pop-up is back:
>>
>> https://postimg.cc/jLTvg834
>>
>> It's not causing any problems (that I know of). I just wonder how it
>> got started. From my reading of 'service workers', I wonder if the
>> pop-up is triggered by an infected website that I visit. Maybe I'll
>> just visit one site per browsing session and see when the pop-up
>> appears.
>
> I began visiting each of my usual sites, one at a time per browsing
> session, to see if a pop-up would appear, and if so, with which website.
> When I visited "www.americanthinker.com",

This page is a piece of shit. Trump is a traitor and the biggest loser ever.

Nothing pops up here with uBlock Origin and NoScrip.

--
"Gutta cavat lapidem." (Ovid)

Re: Malware on Firefox?

<XnsB14FDCADD93C1nospaminvalidcom@135.181.20.170>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=3364&group=alt.comp.software.firefox#3364

  copy link   Newsgroups: alt.comp.software.firefox
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@invalid.com (Boris)
Newsgroups: alt.comp.software.firefox
Subject: Re: Malware on Firefox?
Date: Wed, 10 Apr 2024 04:41:37 -0000 (UTC)
Organization: This space for rent.
Lines: 53
Message-ID: <XnsB14FDCADD93C1nospaminvalidcom@135.181.20.170>
References: <XnsB143979BFF462Borisinvalidinvalid@135.181.20.170> <pzk2lacrtyja$.dlg@v.nguard.lh> <XnsB14796DCC11B6nospaminvalidcom@135.181.20.170> <tpiujuglgwly$.dlg@v.nguard.lh> <XnsB14993D8E8F44nospaminvalidcom@135.181.20.170> <XnsB14BA5E4B6A6nospaminvalidcom@135.181.20.170> <XnsB14CA0577C07Fnospaminvalidcom@135.181.20.170> <57l7kmib4bgm.dlg@v.nguard.lh>
Injection-Date: Wed, 10 Apr 2024 04:41:38 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="eebac111cd12f054e61a4944417dfecc";
logging-data="806338"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+J370fsfLUhryJLgSzGzY0"
User-Agent: Xnews/5.04.25
Cancel-Lock: sha1:/4DhoNksSfRug4IHQavsrSRoRLM=
 by: Boris - Wed, 10 Apr 2024 04:41 UTC

VanguardLH <V@nguard.LH> wrote in news:57l7kmib4bgm.dlg@v.nguard.lh:

> Boris <nospam@invalid.com> wrote:
>
>> I began visiting each of my usual sites, one at a time per browsing
>> session, to see if a pop-up would appear, and if so, with which
>> website. When I visited "www.americanthinker.com", the Elon Musk
>> selling CBD popped up. (The URL in this pop-up is 761 characters
>> long.) Clicking on any link on this pop-up's page takes one to the
>> same place each time, a page to order CBD gummies. The pop-up's domain
>> in the URL is "rightdailyfeed.com".
>>
>> When I go to https://www.rightdailyfeed.com, I'm taken to an empty
>> webpage, with "code: 3465468754"in the upper left hand corner.
>>
>> A search on "code: 3465468754" takes me to some google images, one of
>> which is "rightdailyfeed.com Traffic Analytics - Similarweb".
>>
>> Clicking on that image takes me to
>> https://www.similarweb.com/website/rightdailyfeed.com/.
>>
>> If I scroll down the page to "rightdailyfeed.com Target Audience",
>> there's americanthinker.com, the site that when I went there, Elon's
>> CBD pop-up appeared.
>>
>> https://postimg.cc/gallery/4HQKgmY
>> But, if I cruise around similarweb's page a little more, I see lots of
>> other well known websites I occasionally, such as finance, health care,
>> insurance, etc., so these other sites may trigger a pop-up. I just
>> don't understand how this all works.
>>
>> I'm going to install an ad blocker, and see what happens.
>
> I went to americanthinker.com, and go no popups. I use uBlock Origin
> (in expert mode), and my choice of blacklist subscriptions might not
> match those selected by another user of uBO. Besides domain blocks,
> many URL substrings are also included in the filters of many blacklists,
> like paths or args that point to possible ad sources.

I installed UBlock Origin, and low and behold, not only did the 'normal'
pop-ups stop, but so did the two (Elon Musk ad for CBD gummies, and McAfee
ad) full page in the background pop-ups stop.

I didn't consider the Elon/McAfee pop-ups to be 'normal' pop-ups, since
they were full page and remained after closing Firefox. I wanted to
figure out where they came from and why the Firefox default setting "block
pop-up windows", when enabled, didn't stop any pop-ups. That setting
seemed useless.

I'm not running uBlock Origin in Advanced mode, until I figure more of it
out, but I do like the logger.

Many thanks again.


computers / alt.comp.software.firefox / Malware on Firefox?

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor