Follow Us

Fake Firefox update spreads unwanted app

Installs successor to notorious to Zango Toobar.

The successor program to the notorious Zango spyware Toolbar is being used to target users of Mozilla's Firefox with fake browser updates, a security company has alleged.

According to a warning put out by eSoft, the reprised Hotbar app, run as of May last year by a new entity called Pinball Corp, is being fed to users via a fake but convincing Firefox update page. The update page - which users would come to through a search engine for the latest updates - looks identical to the genuine page in everything bar the version it is claiming to offer (3.5 where the most recent is 3.6) and some misspelling.

Windows users fooled into downloading and installing from the fake page will actually be getting a toolbar app that also hits the user with pop-up ads and a weather application in the system tray.

According to eSoft, the software is actually being fed without the direct knowledge of its creators, Pinball, which will likely be paying a third party affiliate for every install. As with the distribution of the original Zango Toolbar, how that install gets on to a user's PC is not their business.

Zango disappeared last April after several years in which it was accused of sneaking spyware on to users' PC without their consent, invariably by paying third parties to do the dirty work. In 2006, it was fined $3 million by the US Federal Trade Commission (FTC) for its actions.

It should be pointed out that what is at fault here is not the new toolbar app per se, but the way it is being distributed by a separate entity and installed under false pretences. As ever, an application becomes legitimate if the user consents to its installation having had the proposition explained in an accurate way, but that is certainly not happening in this instance.

The genuine install site for Firefox updates can be found here.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *