# How can I tell if a site is infected without opening it?

**URL:** <https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895>\
**Category:** Factual Questions\
**Created:** [December 2, 2011, 10:58pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895 "2011-12-02T22:58:08Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Love\_Rhombus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/love_rhombus/32/10694_2.png) [@Love\_Rhombus](https://boards.straightdope.com/u/Love_Rhombus)\
**Post date:** [December 2, 2011, 10:58pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/1 "2011-12-02T22:58:08Z")

</div>

A friend of mine opened a site he thought was safe the other day and was infected with about 5 different trojans and such. Had to get a new computer. I’m idly curious if it was the site, as he claimed, or something else he was actually doing. Is there any way to tell if that site really is infested without risking my own computer?

---

<div class="post-metadata">

**Author:** ![pohjonen](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pohjonen/32/423_2.png) [@pohjonen](https://boards.straightdope.com/u/pohjonen)\
**Post date:** [December 2, 2011, 11:25pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/2 "2011-12-02T23:25:54Z")

</div>

Web of Trust. Stops you before you go to site with a really bad rep. Says there’s a version for all the browsers.

---

<div class="post-metadata">

**Author:** ![aceplace57](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aceplace57/32/3500_2.png) [@aceplace57](https://boards.straightdope.com/u/aceplace57)\
**Post date:** [December 2, 2011, 11:25pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/3 "2011-12-02T23:25:56Z")

</div>

Malware Bytes has an online feature that tries to detect suspicious behavior. They also have a list of known bad sites.

That list has already saved me one time. I clicked on the link and Malware Byte blocked it before it loaded. I got a message telling me why it blocked the site.

You have to register to turn on these features.

---

<div class="post-metadata">

**Author:** ![Candyman74](https://avatars.discourse-cdn.com/v4/letter/c/ad7895/32.png) [@Candyman74](https://boards.straightdope.com/u/Candyman74)\
**Post date:** [December 2, 2011, 11:29pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/4 "2011-12-02T23:29:19Z")

</div>

> [@Love\_Rhombus](#):
>
> A friend of mine opened a site he thought was safe the other day and was infected with about 5 different trojans and such. Had to get a new computer.

He went to a website and a couple of days later bought a new computer?

Sounds like he wanted a new computer. Does he have to justify the expense to a partner or something?

---

<div class="post-metadata">

**Author:** ![obbn](https://avatars.discourse-cdn.com/v4/letter/o/d6d6ee/32.png) [@obbn](https://boards.straightdope.com/u/obbn)\
**Post date:** [December 2, 2011, 11:40pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/5 "2011-12-02T23:40:34Z")

</div>

> [@Love\_Rhombus](#):
>
> A friend of mine opened a site he thought was safe the other day and was infected with about 5 different trojans and such. Had to get a new computer. I’m idly curious if it was the site, as he claimed, or something else he was actually doing. Is there any way to tell if that site really is infested without risking my own computer?

A new computer? That is a bit of overkill isn’t it? At the very worst a full reformat would take care of the problem.:smack:

---

<div class="post-metadata">

**Author:** ![chiroptera](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@chiroptera](https://boards.straightdope.com/u/chiroptera)\
**Post date:** [December 2, 2011, 11:47pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/6 "2011-12-02T23:47:08Z")

</div>

I’ve had a couple of very nasty viruses (two in the last decade), but nothing that necessitated buying a new computer. As stated, un- and re-installing everything, done by someone who knows what they’re doing, does the trick for qa fraction of the cost of a new computer.

I have the paid version of AVG; it warns me if I’m about to open a dodgy website. IIRC, the free version did the same thing.

---

<div class="post-metadata">

**Author:** ![Al\_Bundy](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@Al\_Bundy](https://boards.straightdope.com/u/Al_Bundy)\
**Post date:** [December 3, 2011, 2:15am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/7 "2011-12-03T02:15:17Z")

</div>

Really? A virus works on the software. It does not damage the hardware (unless you are Iranian and building a bomb). People need to learn how to avoid problems and fix those that happen.

---

<div class="post-metadata">

**Author:** ![Love\_Rhombus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/love_rhombus/32/10694_2.png) [@Love\_Rhombus](https://boards.straightdope.com/u/Love_Rhombus)\
**Post date:** [December 3, 2011, 2:16am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/8 "2011-12-03T02:16:34Z")

</div>

No, no. He had to get it the same day. Well, it was due soon anyway, he just had to speed it up a bit.

---

<div class="post-metadata">

**Author:** ![Tibby](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tibby/32/17030_2.png) [@Tibby](https://boards.straightdope.com/u/Tibby)\
**Post date:** [December 3, 2011, 2:26am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/9 "2011-12-03T02:26:39Z")

</div>

> [@Love\_Rhombus](#):
>
> A friend of mine opened a site he thought was safe the other day and was infected with about 5 different trojans and such. Had to get a new computer…

I had a computer virus so virulent that I not only had to buy a new computer, but also a new dog, cat and set of kids. The wife? She left with the computer repair guy. But, I’m not complaining…

---

<div class="post-metadata">

**Author:** ![Rusalka](https://avatars.discourse-cdn.com/v4/letter/r/ecd19e/32.png) [@Rusalka](https://boards.straightdope.com/u/Rusalka)\
**Post date:** [December 3, 2011, 2:27am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/10 "2011-12-03T02:27:51Z")

</div>

> [@pohjonen](#):
>
> Web of Trust. Stops you before you go to site with a really bad rep. Says there’s a version for all the browsers.

Web of Trust is great software.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [December 3, 2011, 2:32am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/11 "2011-12-03T02:32:33Z")

</div>

[http://www.google.com/safebrowsing/diagnostic?site=www.example.com](http://www.google.com/safebrowsing/diagnostic?site=www.example.com)

Change _[www.example.com](http://www.example.com)_ to the site address.

---

<div class="post-metadata">

**Author:** ![furryman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/furryman/32/99_2.png) [@furryman](https://boards.straightdope.com/u/furryman)\
**Post date:** [December 3, 2011, 6:33pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/12 "2011-12-03T18:33:20Z")

</div>

> [@Tibbytoes](#):
>
> I had a computer virus so virulent that I not only had to buy a new computer, but also a new dog, cat and set of kids. The wife? She left with the computer repair guy. But, I’m not complaining…

I’m still sneezing from the computer virus I got.

---

<div class="post-metadata">

**Author:** ![njtt](https://avatars.discourse-cdn.com/v4/letter/n/ecd19e/32.png) [@njtt](https://boards.straightdope.com/u/njtt)\
**Post date:** [December 3, 2011, 7:27pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/13 "2011-12-03T19:27:12Z")

</div>

Firefox has an option (on the Security tab of Options) to “Block Reported Attack Sites”. I believe it is based on a list maintained, and frequently updated, by Google of sites that have such problems. It automatically warns you if you try to go to a bad site. I believe most other modern browsers have a similar built in facility. I have used Web of Trust, but found it far too intrusive. It was always warning me of stuff that was actually quite harmless. Firefox’s built in protection, on the other hand, has worked well for me.

If you are among the first few people to visit a bad site (or one that has recently been hacked and had malware put on it), then yo are out of luck, as it will not have been reported yet. Unfortunately, no-one has any way of knowing what sites ae bad before someone gets hit by it.

There are three other simple precautions against attack sites that I have found helpful. Prevent flash apps from playing automatically (I use the FF addon Flashblock, although it has lost some of its effectiveness recently), do _not_ use Adobe Reader as your default PDF reader, and make sure you set your browser to download PDFs instead of displaying them automatically in the browser window. If your browser downloads a PDF or similar file when you are not expecting it to, do not attempt to view the file, but delete it immediately.

---

<div class="post-metadata">

**Author:** ![Qadgop\_the\_Mercotan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/qadgop_the_mercotan/32/83_2.png) [@Qadgop\_the\_Mercotan](https://boards.straightdope.com/u/Qadgop_the_Mercotan)\
**Post date:** [December 3, 2011, 7:37pm UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/14 "2011-12-03T19:37:07Z")

</div>

I look for redness, swelling, warmth, or fluctuance at the site. Also, if the patient has sweats or chills or myalgias, infection is very possible.

If the site seems ripe enough, I open it and release the infection, and sometimes leave a wick in to ensure adequate drainage.  
What?

:smack:

---

<div class="post-metadata">

**Author:** ![Hail\_Ants](https://avatars.discourse-cdn.com/v4/letter/h/dc4da7/32.png) [@Hail\_Ants](https://boards.straightdope.com/u/Hail_Ants)\
**Post date:** [December 4, 2011, 1:49am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/15 "2011-12-04T01:49:13Z")

</div>

> [@Love\_Rhombus](#):
>
> A friend of mine opened a site he thought was safe the other day and was infected with about 5 different trojans and such. Had to get a new computer. I’m idly curious if it was the site, as he claimed, or something else he was actually doing. Is there any way to tell if that site really is infested without risking my own computer?

You didn’t say but I can only assume he wasn’t running any antivirus software which, unless you’re not connected to the internet _at all_, is simply not viable. Even the [free version of AVG](http://download.cnet.com/AVG-Anti-Virus-Free-Edition-2012/3000-2239_4-10320142.html) has a ‘link scanner’ which will do what you need.

---

<div class="post-metadata">

**Author:** ![asterion](https://avatars.discourse-cdn.com/v4/letter/a/4da419/32.png) [@asterion](https://boards.straightdope.com/u/asterion)\
**Post date:** [December 4, 2011, 2:56am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/16 "2011-12-04T02:56:49Z")

</div>

Simply looking at the TLD can be a good habit. Obviously “thought it was safe” or even “was safe until site was infected” doesn’t stop that, but staying out, for instance, the Russian websites helps.

Running things like Noscript and Ghostery can help. Stopping scripts helps with some vectors.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [December 4, 2011, 3:12am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/17 "2011-12-04T03:12:11Z")

</div>

[ClearCloud DNS](http://clearclouddns.com/FAQ/) does a good job of blocking bad sites.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [December 4, 2011, 3:23am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/18 "2011-12-04T03:23:42Z")

</div>

> [@yoyodyne](#):
>
> [ClearCloud DNS](http://clearclouddns.com/FAQ/) does a good job of blocking bad sites.

Sorry, looks like they stopped ClearCloud.

---

<div class="post-metadata">

**Author:** ![BeaMyra](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@BeaMyra](https://boards.straightdope.com/u/BeaMyra)\
**Post date:** [December 4, 2011, 9:34am UTC](https://boards.straightdope.com/t/how-can-i-tell-if-a-site-is-infected-without-opening-it/604895/19 "2011-12-04T09:34:47Z")

</div>

A lot of programs like Avast and AVG will do link protection. The problem is, that it slows your computer down a lot, because the antivirus is going to check all the links on a page before letting you see it.

Spybot also has an immunity feature but it only works with IE.
