A
A
Alexander Fomin2012-04-30 14:53:35
Google Chrome
Alexander Fomin, 2012-04-30 14:53:35

Strange infection in chrome superfish.com

Recently, I noticed that on many sites (including Habré) JS began to fall (for example, comments stopped updating). After digging into the browser console, I found such a dirty trick that sticks to all sites:

<script src="http://www.superfish.com/ws/sf_main.jsp?dlsource=Diigoreadlater&userId=feac551f44d13d5951363db3e8872379" defer="" ></script>
<script type="text/javascript" src="http://www.superfish.com/ws/js/base_single_icon.js?ver=11.0.6.3" ></script>

Inside was base_single_icon.js , sf_main.jsp .

Google gives only a few vague links to FF forums with suggestions to clear the cache and upload plugins.

I haven’t figured out how it clings yet, there don’t seem to be any left plug-ins in the browser if everything is clean in the porn mode. So far, I have solved the problem by adding 127.0.0.1 to /etc/hosts on superfish.com.
I have not analyzed the code yet, as I figure it out, I will add what I found.
If someone came across tell me what kind of rubbish it is?

Answer the question

In order to leave comments, you need to log in

14 answer(s)
S
Stdit, 2012-04-30
@Stdit

Disable all extensions and plugins (both left and right, including chrome://plugins/) and enable one at a time. When he appears, he is to blame.

P
Pavel Logachev, 2014-05-23
@Alhames

+ in this: Google Chrome™ Service Pages :)

A
Artyom Tsyplakov, 2012-04-30
@grimich

Have you tried watching with other browsers? Only in bad chrome?

G
Goder, 2012-04-30
@Goder

Had the same problem. Adblock helped.
Now the adblock is disabled, but this muck is gone. Mystic. :)

L
La2ha, 2013-09-04
@La2ha

Also encountered, the culprit is the Translate application chrome.google.com/webstore/detail/translate-selection/goanabmlmgfinmjohhepcpffcnkeobjm

M
MrTims, 2013-09-05
@MrTims

In the Translate application, I checked the I don't want to support you (turn off the ads) checkbox in the settings.
Looks like the ad is gone

K
Konstantin   , 2014-07-03
@SynCap

Using a systematic approach - search for "superfish" in *.js files in the Chrome extensions folder (for the seventh Windows: "%SystemDrive%:\Users\%USERNAME%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions \" ) caught several extensions with this "superchip".
Some of them have a checkbox in the settings, like "Disable ads" in the spirit of what I don't want to help you with. Who does not have such a daw - left the fftopka, and were replaced by analogues, or pretty cleaned up and installed, as unpacked with other IDs, so as not to be accidentally updated.
There is nothing particularly terrible in this thing - it just pumps up ads, but the trouble is that the script itself is huge and is embedded in ALL pages, and extensions such as Save Single Page or Read Later carefully save them.

A
Alexander Fomin, 2012-04-30
@Swarog

Thanks for the advice, the hero of the occasion was found this extension - Read Later Fast, now it remains to figure out what kind of rubbish is shoved into JS, because. the plugin is very useful and I would not want to abandon it because of too much paranoia.

P
pyatin, 2013-03-12
@pyatin

Same issue in FireFox 19.0 for ubuntu, Awesome Screenshot Plus culprit - Capture, Annotate & More

E
Evgeny Fedorov, 2013-09-30
@JekFdrv

I just noticed this thing in FF, put my IP in .htaccess, disabled all extensions and plugins, rebooted, nothing, turned everything back on, rebooted, nothing again, disappeared, although watching the network I remember how the data about my browser was sent .

N
NoLiveKMS, 2013-11-13
@NoLiveKMS

Previously, it was also from this application https://chrome.google.com/webstore/detail/auto-translate/obgoiaeapddkeekbocomnjlckbbfapmk can be removed in the settings.

D
Dmitry, 2014-01-21
@KenAdams

In the piggy bank of extensions with bad: Add to Feedly ™

S
Stanislav Katkov, 2014-01-28
@lunaticman

Found in Add to Feedly ™ 0.4.1
with a script, a list of sites from which it saves information is pulled - there is a large list of online stores and even paypal.com and ebay.com in the list.
I advise you to change your passwords!

E
Eugene, 2014-02-24
@Methos

This extension also found
https://chrome.google.com/webstore/detail/neat-boo...

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question