Threat Database Malware YXH-youtube_player

YXH-youtube_player

By ZulaZuza in Malware

YXH-youtube_player.xpi and YXH-youtube_player.crx are noxious Youtube extensions. Attackers have created a malicious web browser extension attack which pretends to be a Youtube Player. YXH-youtube_player.xpi and YXH-youtube_player.crx target Mozilla Firefox and Google Chrome and spread via Facebook. This spam campaign becomes a lot worse when infected PC users post links on websites that are using Facebook Comments Box. At least those web-links that lead to fake Youtube websites are non-clickable. The bit.ly link reroutes affected PC users to a website which imitates youtube.com. They are then pressed via a pop-up screen to click a notification and then install a Youtube HD Player. In reality, PC users don't even need to click a notification, a download of the noxious extension starts automatically. You shouldn't install add-ons from websites you cannot trust.

File System Details

YXH-youtube_player may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\Mozilla\Firefox\Profiles\o45jfr56.default\extensions\admin@youtubeplayer.com
2. C:\Documents and Settings\\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jsgfrtofdhsjrelrjmspsjrtdcrslsjsnrt\6.1.8_0

Trending

Most Viewed

Loading...