Feeds

Fake Firefox site bundles undead adware

Zango crapware rises from the grave

Intelligent flash storage arrays

Adware slingers have taken advantage of the buzz around the latest version of Firefox to establish a fake browser download site.

The counterfeit Firefox download site is disguised as a kosher browser download site and might easily fool the unwary. A closer look, however, reveals the version of Firefox on offer is version 3.5 (instead of the latest 3.6 version supplied by Mozilla). In addition, terms such as "Anti-Pishing" (sic) are misspelled on the glossy counterfeit download site.

Web users taken in by the scam will wind up downloading browser software contaminated with the Hotbar toolbar from Pinball Corp, formerly Zango. The software bombards marks with irksome pop-up ads while also further slowing performance by loading the Hotbar weather application in the system tray.

Security firm eSoft, which documents the risk here, reckons that the ruse is more likely the brainchild of a rogue Pinball agent rather than the firm itself. Pinball rewards its pay-per-install affiliate with up to $1.45 per install, eSoft adds.

Users looking to get the latest version of Firefox are advised to go to Mozilla's getfirefox.com site. eSoft has blocked access to the fake site for users of its technology. Other vendors can be expected to follow suit.

Zango was repeatedly obliged to defend itself against accusations that its ad-serving software was distributed without the informed consent of users. Security firms routinely categorised Zango's software as adware, sparking unsuccessful lawsuits against Kaspersky Lab and PC Tools in 2007. Its PR staff tenaciously held the line that any problems were down to rogue affiliates, which it was in the process of culling even before it paid the FTC to settle a privacy lawsuit back in 2006.

However its chief tormentors - Ben Edelman, an assistant professor at the Harvard Business School, and Chris Boyd, former security researcher at Facetime Security - continued to document evidence of malpractice by Zango years after the FTC settlement. Zango went titsup last April, but its Hotbar technology lingers on the interwebs, as evidenced by the fake Firefox download ruse. ®

Security for virtualized datacentres

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Shellshock over SMTP attacks mean you can now ignore your email
'But boss, the Internet Storm Centre says it's dangerous for me to reply to you'
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.