I was just working with a client and I instructed them to download Firefox because Internet Explorer was giving them problems. They did a Google search for "Firefox" and clicked on the first result without realizing that it was a paid advertisement. Consequently, a bunch of malicious software was installed onto their system, including those fake virus scanners which warn the user that they have hundreds of infections and that they must purchase the product to have them removed. The client had AVG installed so I told them to do a scan but it found nothing. So I started to look around for some more information about the malicious website (
www.ez-download.com).
Besides this
Mozilla bug report which is now a year old, one of the only articles I could find about this malicious website was a
blog post on webroot:
Our sensors continue detecting rogue ads that expose users to bogus propositions in an attempt to install privacy-invading Potentially Unwanted Applications (PUAs) on their PCs. The most recent campaign consists of a successful brand-jacking abuse of Mozilla’s Firefox browser, supposedly offered for free, while in reality, the rogue download manager entices users into installing multiple rogue toolbars, most commonly known as InstallCore.
More details:
Sample screenshot of the landing page:
![](https://ip.bitcointalk.org/?u=http%3A%2F%2Fs27.postimg.org%2Fruwpnok2r%2Fip_bitcointalk_org.jpg&t=671&c=gjNFU2yhHgkOTw)
Rogue download URL:
hxxp://www.ez-download.com/mozilla-firefox
Based on what my client described to me I would say that "potentially unwanted" is a vast understatement. So I tried visiting the website myself and my WOT plugin gave me a warning that the website had a very bad rating. I took a look at the
WOT user reviews and nearly every one of them were saying that the website gave them a virus/trojan. I also noticed that some of the reviews were posted near the very start of 2013, over 1 year ago. So I started to wonder how this site was still at the top of the Google search results for "firefox". Here is a screenshot I took showing the malicious website at the top (the little green and red circles are part of the WOT addon for Firefox):
![](https://ip.bitcointalk.org/?u=http%3A%2F%2Fs12.postimg.org%2Fdth3wkyzh%2Ffirefox_search.jpg&t=671&c=x29L358u3rDcLQ)
So I did some more searching and to my surprise I found that WOT was essentially the only website which recognized the malicious nature of ez-download.com. This
TrustPilot review page gives the website a rating of 9.2/10. Even this
Norton Safe Web Report for ez-download.com lists 0 detected threats and gives it a big green "OK" and says it is "safe". One Norton user posted the following comment nearly a month ago:
"Norton Says Safe? They had a pretty nasty virus on their Foxfire download so I don't understand how Norton can consider this site safe. I will never use their site again. It was the sort of thing that should not have passed even basic scans."
Indeed, so how did it pass their scan and why has this website been freely operating for over a year now as we can clearly see by the Mozilla bug report and the WOT reviews? I started searching for a solution to the problem so that I could help my client remove the infections from their computer. There was nearly nothing written on this topic but I did find a
Yahoo answer page related to this issue:
What can I do about the damage this site ( mozilla-firefox.ez-download.com ) caused to my computer?
I tell you do-not-download-this. I had Mozilla Firefox installed from this site and my entire computer crashed... The system is designed to have you blackmailed in order to save your computer from the damage they cause you. I had to buy a new computer.
BEST ANSWER:
There is nothing to be done unfortunately. In-fact the US government is sanctioning the use of new malware to be developed as a deterrent for downloading copyrighted material. (another confirmation politicians are in the pocket of big business and don't even bother hiding it).
Report website to virustotal.com. It may help others to avoid it in the future.
I would have dismissed this answer as a paranoid fantasy if not for what I had already learnt about this website. So based on his answer I took a look on virustotal.com to see if anyone submitted this malicious website to them. I found the virustotal
scan report for ez-download.com and to my amazement only 2 out of the 53 scanners said the site was malicious (WOT and Dr.Web), the other 51 reported that the site was "clean". As I was looking through the Mozilla bug report and the WOT reviews and some of the other articles I have linked to in this post, I also came across some other virustotal links where people had submitted the Fake Firefox installer for scanning, such as these four:
Antivirus scan for firefox_setup.exe (1 year ago) - 2/46
Antivirus scan for Firefox_Setup_21.0.exe (8 months ago) - 4/46
Antivirus scan for Firefox_Setup.exe (3 months ago) - 1/46
Antivirus scan for firefox_downloader.exe (4 days ago) - 6/46
The one from 4 days ago is a scan of the installer which you can download from ez-download.com right now. At least the anti-virus software seems to be getting a little bit better with 6 out of 46 positive detection results, but that is still absolutely pathetic imo. It was missed by so many of the "top line" scanners including the ones made by Symantec, TrendMicro, Panda, McAfee, Microsoft, Kaspersky, F-Secure, Comodo, BitDefender, Avast, AVG, Ad-Aware, and the list goes on. All of them have consistently been unable to detect these fake Firefox installers, even though this malicious website has been disseminating them for over a year now. And even with such a long history of malicous activities, now Google has placed them at the top of the search results for the simple search phrase "firefox". Just what in the hell is going on here? I submitted a report to Google but so have many other people before me and they still haven't done anything about it. This is absolutely unbelievable...