There is no such thing as urgent Firefox patches.

LNK_KOVTER.SM is yet another horrific Trojan virus that should be removed immediately form your PC. It has been programmed by vicious cyber criminals in order to perform several malicious activities in victimized computer remotely. When you see the Critical Firefox Update page, you may immediately notice a pop-up alongside it, asking you to download firefox-patch.js: This.js file is the infection file of the Kovter Trojan horse. The Kovter malware family has been plaguing systems for many years and seems to be restless. A new click-ad-fraud strain of fileless Kovter is currently being spread via drive-by download attacks. The infection is triggered by a legitimate Mozilla Firefox browser update pack (firefox-patch.exe). New Fileless Kovter Uses Legitimate Certificate. Kovter AdFraud Malware Updates Flash Plugin to Latest Version. The moves by this ad fraud Trojan is very much similar to a housebreaker climbing into the house through an opening, and then closing that opening to keep other housebreakers out. This is the reason behind Kovter updating Flash plugin to an up-to-date version.

  • Kovter malware masquerades as Firefox update Click-ad-fraud Kovter malware, packaged as a legitimate Firefox browser update, is being delivered to unsuspecting victims via drive-by-download attacks.
  • I and others are receiving a full screen popup window in Firefox (47.0.1) indicating that there is an emergency Firefox security patch that needs to be downloaded. The download window shows an address with a binary file typically in the mid 300k size. A search on whois shows the address to be bogus.

This sounds like you encountered a site claiming to have what is a fake Firefox patch .exe. The fake updates exe can install things like trojans, viruses or unwanted software based on past reports.

The desktop Firefox is not just for Windows as it is for Mac OSX and Linux also so .exe would not be an effective way to send out Firefox updates. The updates are done internally in Firefox (with a .mar file) during automatic and check for updates or by download from mozilla.org like say www.mozilla.org/firefox/all/

Even if Mozilla were to use .exe for Firefox updates on Windows, they would be serving them from a *.mozilla.org url and not from random websites with weird names.

There was actually a 47.0.1 update on June 28https://www.mozilla.org/firefox/47.0.1/releasenotes/ however it is not a automatic update and will be for those who manually check for Firefox updates in Help or by download at mozilla.org or www.mozilla.org/firefox/all/

Report fake Firefox updates sites like this as 'distributing modified Firefox/malware' at https://www.mozilla.org/legal/fraud-report/ (url is at bottom of many mozilla.org sites) and Google may block if reported enough at https://www.google.com/safebrowsing/report_phish/ which can be accessed by Help > Report Web Forgery in Firefox.

A drive-by malware attack happened today on my pc screen. I was visiting a news website(Guardian), and all of the sudden got a Firefox update screen saying 'critical update'. And there was a file that automatically popped up on my screen to be downloaded. I did not download it and my MSE notified me about the attack, and that I don't have to do anything on my part. I checked the quarantine, and it said Trojan 32 Kovter. I removed that from quarantine. Then, I ran rKill, which didn't find anything. Then, I ran Malwarebytes, which didn't find anything, as well. It appears that there is no malware on my pc, but I just wanted to make sure that it is the case. Also, I deleted my history/downloads/cache for the past 1 hour prior to that, so the bad file/anything else is gone. I didn't write down the redirected website's URL, however, it was something weird(not firefox).

I am running Vista Enterprise 64-bit. One thing to note is that about 1 hour prior to the event described above, one of my family members was using another pc, and clicked on a phishing link. The site was blocked by Firefox and we navigated from it using 'Get me out of here' button, but perhaps the damage was done by that time. Maybe my pc has this problem because of the other pc incident(network hacked?) I ran a Malwarebytes scan on that pc as well, which didn't find any infections. This second pc is using Vista Business SP2 32-bit.

Any help would be appreciated.

