"In the past we have seen threats create malicious extensions," Gutierrez writes. "All users had to do was disable that particular add-on and they would be safe.
"For Neloweg, this is not the case. Since it is a component, it does not appear as an add-on in Firefox’s add-ons Manager, like other extensions and plugins do. Furthermore, because of the way Firefox is designed, Neloweg will be recreated and reinstalled every time Firefox attempts to connect to the Internet."
Story @ The Register
Tracking and analysis @ Symantec
Tehcnical Details @ Symantec <<Useful for helpers.