# If you've been hit by malware - GOOD NEWS, we hope

**URL:** <https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486>\
**Category:** About This Message Board\
**Created:** [November 30, 2010, 11:54pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486 "2010-11-30T23:54:25Z")\
**Posts on this page:** 15\
**Page:** 2

<div class="post-metadata">

**Author:** ![Giraffe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/giraffe/32/129_2.png) [@Giraffe](https://boards.straightdope.com/u/Giraffe)\
**Post date:** [December 15, 2010, 5:20pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/21 "2010-12-15T17:20:09Z")

</div>

> [@Czarcasm](#):
>
> There’s a chance that the malware didn’t even come from visiting the SDMB, because that computer became a bug collector the instant her husband “fixed” it.

True, but since there’s a chance that it did come from here, I figured it was potentially useful information so I forwarded it along. As a single event, it’s probably not actionable, but if we get more reports in short order then it helps establish a pattern, right?

---

<div class="post-metadata">

**Author:** ![NineToTheSky](https://avatars.discourse-cdn.com/v4/letter/n/b5a626/32.png) [@NineToTheSky](https://boards.straightdope.com/u/NineToTheSky)\
**Post date:** [December 15, 2010, 5:51pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/22 "2010-12-15T17:51:34Z")

</div>

> [@srzss05](#):
>
> I’m not defending the husband (in this case), but he does make a good point. I did the same thing, for the same reasons, because my “real life” programs were running like shit with the security software running, or even installed. However, I don’t really use the internet that much, so in my case I am reasonably safe as long as I take other precautions.

I’ve heard people saying this, but I don’t understand it. Millions use security software (myself included) without any ill effects, so either you’re using the wrong software, or there’s some conflict.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [December 15, 2010, 7:11pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/23 "2010-12-15T19:11:45Z")

</div>

> [@NineToTheSky](#):
>
> I’ve heard people saying this, but I don’t understand it. Millions use security software (myself included) without any ill effects, so either you’re using the wrong software, or there’s some conflict.

The big commercial vendors (or at least 1 of them in particular) have shitty software, they’ve been screwing up people’s computers for a long time.

The companies like Avast and AVG, etc. tend to do a good job.

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [December 15, 2010, 7:45pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/24 "2010-12-15T19:45:27Z")

</div>

> [@Giraffe](#):
>
> Just a heads-up: someone [posted on my site](http://www.giraffeboards.com/showpost.php?p=507635&postcount=83) that they had been infected with malware while visiting the SDMB today. Unfortunately their computer is hosed and they are pretty fed up with the site, so I doubt they’ll be able or willing to provide much data on the infection source, but I figured I’d give a heads-up that the viruses are popping their ugly heads up again.

Argh, thought we’d gotten a handle on this. Thanks for letting us know. If anyone else has malware problems while visiting the SDMB, pls let us know ASAP and provide as many details as you can, including screen shots if possible. (For PC users unfamiliar with such things, press Alt-Print Screen, open Paint, press Ctrl-V to paste in the page, then save the result as a JPEG.) Our apologies to anyone who experiences problems like this on our site.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [December 15, 2010, 10:49pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/25 "2010-12-15T22:49:50Z")

</div>

> [@NineToTheSky](#):
>
> I’ve heard people saying this, but I don’t understand it. Millions use security software (myself included) without any ill effects, so either you’re using the wrong software, or there’s some conflict.

Alot of people are also running recent version software on 5-6 year old PC’s that were low spec discount models 5-6 years ago. The end result is often the AV programs pulling large amounts of available system memory on a system like an XP box that is still running 256MB of ram that has been a slug since service pack 3 came onboard.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [December 15, 2010, 10:52pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/26 "2010-12-15T22:52:05Z")

</div>

> [@Giraffe](#):
>
> Just a heads-up: someone [posted on my site](http://www.giraffeboards.com/showpost.php?p=507635&postcount=83) that they had been infected with malware while visiting the SDMB today. Unfortunately their computer is hosed and they are pretty fed up with the site, so I doubt they’ll be able or willing to provide much data on the infection source, but I figured I’d give a heads-up that the viruses are popping their ugly heads up again.
> 
> Also, on review, I say heads up a lot.

If thats who I think it is on our beloved dope, please drop her an email I can probably help her via phone/remote.

---

<div class="post-metadata">

**Author:** ![thirdname](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@thirdname](https://boards.straightdope.com/u/thirdname)\
**Post date:** [December 21, 2010, 5:01pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/27 "2010-12-21T17:01:32Z")

</div>

I just had this happen to me on the Great Debates forum. I have sent a PM to Ed Zotti about it, and reported this post to the staff so they’ll be aware if he isn’t online now. I’ll just cut and paste my PM here:

> [@](#):
>
> I use a Mac running OSX 10.6.5, and I am using Safari 5.0.3 as a browser.
> 
> I was on the Great Debates page a few minutes ago when suddenly my browser went to another page, and I don’t think I had even clicked on anything. The page I went to was windows-online something, I believe, but I’m not sure of the whole URL because it quickly redirected me to the following: [I’m removing the link entirely from this post to be on the safe side.]
> 
> The page there looked pretty much like this screenshot somebody else posted: [http://chicago.straightdope.com/FakeAntivirus.jpg](http://chicago.straightdope.com/FakeAntivirus.jpg)
> 
> Once on that page, when I tried to close the tab, I was presented with a dialog box with some text. Clicking “cancel” didn’t do anything, it just brought up more dialog boxes. When I clicked OK, it closed the tab but it also downloaded a file called setup.exe. Of course, I am not going to open that file so I assume I’m not going to have any problems with my computer.

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [December 21, 2010, 7:14pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/28 "2010-12-21T19:14:57Z")

</div>

Well, I guess that confirms we didn’t solve the problem. I’ll get on it. Meanwhile, if others are seeing this, pls advise.

ETA: I’ve been in contact with one of our ad providers, and they say they’re going to load some software that emulates what users do - in essence it’ll click repetitively on SDMB pages waiting for the fake malware ad to show up. Since we’re getting reports at long intervals, it’s likely the bad ad is coming from a network in a low-frequency rotation, meaning this is a needle in a haystack proposition. However, they tell me if the ad turns up, the software will spot it.

---

<div class="post-metadata">

**Author:** ![Garfield226](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@Garfield226](https://boards.straightdope.com/u/Garfield226)\
**Post date:** [December 21, 2010, 9:07pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/29 "2010-12-21T21:07:08Z")

</div>

Potentially related, not sure.

This happened yesterday, but I couldn’t reproduce it. Then it happened twice today, and I managed to stay on the page.

It’s the GQ forum (not sure that matters), and the top banner ad and the one just under the thread list say “Ads by Pulse360”. The bottom ad is for Buick Regal.

The behavior is that on pageload, the my computer downloads a file called “bct” (it’s always “bct”), which is empty, reporting itself as plain text and zero KB.

I’m on a Mac, using Safari 5.0.3 with no ad blockers or anything.

I’ll leave the tab open in case there are any other questions this afternoon.

---

<div class="post-metadata">

**Author:** ![Shot\_From\_Guns](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@Shot\_From\_Guns](https://boards.straightdope.com/u/Shot_From_Guns)\
**Post date:** [December 21, 2010, 9:10pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/30 "2010-12-21T21:10:18Z")

</div>

Thank you for the update.

1.) Why didn’t they use that tool as soon as the first malware reports started popping up over a year ago?

2.) Will they keep the tool in use after this particular outbreak is theoretically dealt with?

3.) Do you consider this to be the new “cost of doing business” (i.e., no matter how many future outbreaks there are, you will never consider moving away from using Rubicon), or is there some cutoff point at which you’d cut your losses and dump them so as to avoid losing all ad revenue as visitors to the board stop trusting that you’re able to provide a safe posting environment?

---

<div class="post-metadata">

**Author:** ![Garfield226](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@Garfield226](https://boards.straightdope.com/u/Garfield226)\
**Post date:** [December 21, 2010, 10:36pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/31 "2010-12-21T22:36:42Z")

</div>

Got it again, this time on Page 2 of "The Usual Suspects " thread, where the ads are HP Direct on top, Sprint after the first post, and then a sketchy three-white-boxes with IP-targeted ads in them (LED TVs, Acai Berry and work at home) at the bottom.

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [December 21, 2010, 11:10pm UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/32 "2010-12-21T23:10:19Z")

</div>

I will try to capture a Fiddler log of this when I get home from work tonight which unfortunately will be pretty late.

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [December 22, 2010, 2:52am UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/33 "2010-12-22T02:52:24Z")

</div>

> [@Garfield226](#):
>
> Potentially related, not sure.
> 
> This happened yesterday, but I couldn’t reproduce it. Then it happened twice today, and I managed to stay on the page.
> 
> It’s the GQ forum (not sure that matters), and the top banner ad and the one just under the thread list say “Ads by Pulse360”. The bottom ad is for Buick Regal.
> 
> The behavior is that on pageload, the my computer downloads a file called “bct” (it’s always “bct”), which is empty, reporting itself as plain text and zero KB.
> 
> I’m on a Mac, using Safari 5.0.3 with no ad blockers or anything.
> 
> I’ll leave the tab open in case there are any other questions this afternoon.

Questions:

1. How do you know “bct” is downloading? Is there some indication of this at the bottom of the browser, as on PCs?

2. Is “bct” stored on your hard drive? Where, in the root directory?

3. Is this the only behavior? You don’t see an fake virus screen or anything like that?

Thanks for the info. Sorry if you’re having problems.

---

<div class="post-metadata">

**Author:** ![Garfield226](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@Garfield226](https://boards.straightdope.com/u/Garfield226)\
**Post date:** [December 22, 2010, 3:33am UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/34 "2010-12-22T03:33:55Z")

</div>

> [@Ed\_Zotti](#):
>
> Questions:
> 
> 1. How do you know “bct” is downloading? Is there some indication of this at the bottom of the browser, as on PCs?
> 
> 2. Is “bct” stored on your hard drive? Where, in the root directory?
> 
> 3. Is this the only behavior? You don’t see an fake virus screen or anything like that?
> 
> Thanks for the info. Sorry if you’re having problems.

1. The download history window of Safari pops up, just as if I’d intentionally clicked a link to download something.

2. Yes, it’s saved, it goes to my default downloads folder.

3. That’s it, no popups or anything (and I don’t think they’re blocked, unless Safari does that automatically – it isn’t my default browser). If Safari didn’t pop up the “Hey, you’re downloading something” window, I wouldn’t even notice it (until I happened to look in my downloads folder).

I haven’t noticed it causing any problems on the computer – it’s just weird and I thought it might be related to these problems. The downloaded files seem to be empty, though I suppose it’s possible they’re telling the Mac to report them as Zero KB even if they aren’t.

FWIW, I’ve used Safari to access the boards for many months from that computer, and that behavior only started happening within the last few days.

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [December 22, 2010, 6:29am UTC](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486/35 "2010-12-22T06:29:05Z")

</div>

I just spent an hour reloading the SDMB with Fiddler running looking for malware but none was served to me. 90% of the ads were for Toyota so there wasn’t a lot of opportunity for the bad ads to get through. This time it does seem like looking for a needle in a haystack. Last time the malware was served very frequently.

[Previous page](https://boards.straightdope.com/t/if-youve-been-hit-by-malware-good-news-we-hope/562486.md?page=1)
