# Malware warning

**URL:** <https://boards.straightdope.com/t/malware-warning/479853>\
**Category:** Factual Questions\
**Created:** [January 4, 2009, 10:03pm UTC](https://boards.straightdope.com/t/malware-warning/479853 "2009-01-04T22:03:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 10:03pm UTC](https://boards.straightdope.com/t/malware-warning/479853/1 "2009-01-04T22:03:01Z")

</div>

I clicked on a link at another site and received a malware warning. I had the option of ignoring, or closing the page.

Is this a legitimate warning? If it is, with all of the malware out there why do I see such warnings only rarely? Where does the warning come from? I’m running OS 10.4.11 with the latest security update. Does it come from my OS? Safari? My ISP? Or is it a ‘fake’ warning?

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [January 4, 2009, 10:06pm UTC](https://boards.straightdope.com/t/malware-warning/479853/2 "2009-01-04T22:06:59Z")

</div>

Not nearly enough info to answer. You received a malware warning from what? What did it look like? Where did it appear on the screen?

There are more and more infected websites which display popups which appear to be malware warnings but are really invitations to download and install malware, not anti-malware programs.

If what you saw looked like it was inside a browser window, the odds are very high it was one of those false solicitations.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 10:13pm UTC](https://boards.straightdope.com/t/malware-warning/479853/3 "2009-01-04T22:13:16Z")

</div>

> [@LSLGuy](#):
>
> You received a malware warning from what?

That’s what I want to know.

> [@LSLGuy](#):
>
> What did it look like? Where did it appear on the screen?

It looks [like this](http://www.flickr.com/photos/27492458@N05/3168441694/).

EDIT: The link is to a screenshot, not the actual page.

---

<div class="post-metadata">

**Author:** ![mks57](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mks57](https://boards.straightdope.com/u/mks57)\
**Post date:** [January 4, 2009, 10:27pm UTC](https://boards.straightdope.com/t/malware-warning/479853/4 "2009-01-04T22:27:29Z")

</div>

That looks like a message from your web browser. Google has a service that flags web sites that have been infected with malware. A web browser can use that service to check for problems before it loads a web page. It’s a legitimate warning. Visiting such a web site with an insecure browser can result in your computer being compromised. It doesn’t have to be a porn or warez site for your computer to be attacked.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 10:38pm UTC](https://boards.straightdope.com/t/malware-warning/479853/5 "2009-01-04T22:38:57Z")

</div>

Interesting. Where can I ‘see’ this service?

---

<div class="post-metadata">

**Author:** ![mks57](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mks57](https://boards.straightdope.com/u/mks57)\
**Post date:** [January 4, 2009, 10:43pm UTC](https://boards.straightdope.com/t/malware-warning/479853/6 "2009-01-04T22:43:36Z")

</div>

> [@Johnny\_L.A](#):
>
> Interesting. Where can I ‘see’ this service?

> **[Google Safe Browsing  |  Google for Developers](https://developers.google.com/safe-browsing?csw=1)**
>
> APIs to access the Google Safe Browsing lists of unsafe web resources.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 10:48pm UTC](https://boards.straightdope.com/t/malware-warning/479853/7 "2009-01-04T22:48:03Z")

</div>

Is Safari a ‘client application’?

---

<div class="post-metadata">

**Author:** ![mks57](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mks57](https://boards.straightdope.com/u/mks57)\
**Post date:** [January 4, 2009, 10:55pm UTC](https://boards.straightdope.com/t/malware-warning/479853/8 "2009-01-04T22:55:08Z")

</div>

> [@Johnny\_L.A](#):
>
> Is Safari a ‘client application’?

Yes.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 10:59pm UTC](https://boards.straightdope.com/t/malware-warning/479853/9 "2009-01-04T22:59:18Z")

</div>

So is it reasonable to assume that this is an integral part of Safari, and I have no control over it? (Not that I’d shut it off, of course!)

---

<div class="post-metadata">

**Author:** ![mks57](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mks57](https://boards.straightdope.com/u/mks57)\
**Post date:** [January 4, 2009, 11:26pm UTC](https://boards.straightdope.com/t/malware-warning/479853/10 "2009-01-04T23:26:46Z")

</div>

> [@Johnny\_L.A](#):
>
> So is it reasonable to assume that this is an integral part of Safari, and I have no control over it? (Not that I’d shut it off, of course!)

See Safari’s security preferences.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 4, 2009, 11:32pm UTC](https://boards.straightdope.com/t/malware-warning/479853/11 "2009-01-04T23:32:30Z")

</div>

Aha. I checked Tiger’s security settings, but I forgot to check Safari’s. It does indeed say to ‘Warn when visiting a fraudulent website’. That’s a very cool feature.

Thanks for all of the info.

---

<div class="post-metadata">

**Author:** ![rbroome](https://avatars.discourse-cdn.com/v4/letter/r/838e76/32.png) [@rbroome](https://boards.straightdope.com/u/rbroome)\
**Post date:** [January 5, 2009, 1:27am UTC](https://boards.straightdope.com/t/malware-warning/479853/12 "2009-01-05T01:27:05Z")

</div>

> [@Johnny\_L.A](#):
>
> I clicked on a link at another site and received a malware warning. I had the option of ignoring, or closing the page.
> 
> Is this a legitimate warning? If it is, with all of the malware out there why do I see such warnings only rarely? Where does the warning come from? I’m running OS 10.4.11 with the latest security update. Does it come from my OS? Safari? My ISP? Or is it a ‘fake’ warning?

I believe it is an optional security protection. Safari and Firefox can be set to check a database of sites known to be serving malware. If one visits those sites, you get that page. I have seen it several times lately. Usually sites I shouldn’t be visiting in the first place anyway so no loss to skip the site…

---

<div class="post-metadata">

**Author:** ![Patch](https://avatars.discourse-cdn.com/v4/letter/p/a183cd/32.png) [@Patch](https://boards.straightdope.com/u/Patch)\
**Post date:** [January 5, 2009, 4:28am UTC](https://boards.straightdope.com/t/malware-warning/479853/13 "2009-01-05T04:28:01Z")

</div>

Ummm… the warning message gives a link to the Google Safe Browsing Diagnostic Page at “[easywebsiteauditor.ru](http://easywebsiteauditor.ru)”. Isn’t it more likely it’s a scam and they’re trying to direct you to use that like and thereby go to an infected page? I have a hard time imagining Google storing their diagnostic services in Russia, and Frith knows friends have gotten serious spyware/malware infections from there.

---

<div class="post-metadata">

**Author:** ![cckerberos](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cckerberos](https://boards.straightdope.com/u/cckerberos)\
**Post date:** [January 5, 2009, 4:33am UTC](https://boards.straightdope.com/t/malware-warning/479853/14 "2009-01-05T04:33:29Z")

</div>

> [@Patch](#):
>
> Ummm… the warning message gives a link to the Google Safe Browsing Diagnostic Page at “[easywebsiteauditor.ru](http://easywebsiteauditor.ru)”.

Not at, for.

---

<div class="post-metadata">

**Author:** ![Patch](https://avatars.discourse-cdn.com/v4/letter/p/a183cd/32.png) [@Patch](https://boards.straightdope.com/u/Patch)\
**Post date:** [January 5, 2009, 4:47am UTC](https://boards.straightdope.com/t/malware-warning/479853/15 "2009-01-05T04:47:06Z")

</div>

> [@cckerberos](#):
>
> Not at, for.

Ah.

Well, then. I’ll just be… leaving.

---

<div class="post-metadata">

**Author:** ![groo](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@groo](https://boards.straightdope.com/u/groo)\
**Post date:** [January 5, 2009, 8:12am UTC](https://boards.straightdope.com/t/malware-warning/479853/16 "2009-01-05T08:12:26Z")

</div>

This is interesting. I looked in both Safari and Firefox in both Tiger and Leopard, and didn’t have such an option. Did you (anyone?) install something like the Google Toolbar or Google Apps or somesuch? (Or is it a Chrome thing?)

On my Windows Vista machine (which rocks, which is a strong statement from such a pro-Mac person as myself), I have McAffee super-panduperious-mega-expensive protection against everything, and it didn’t show an alert for the [prorev.com/legacy.htm](http://prorev.com/legacy.htm) page in your browser.

IAC, I found my way to a demo of “Safe Browsing” on google, and the window they showed looked the same, so the error message you saw appears to be legit.

P.S. When you put screenshots up, do you intend to note your interest in Clinton conspiracy theories, Indiana Jones or handgun auctions? I only ask that because, in a dispute with Amazon at one point, I sent them a screenshot which coincidentally-on-purpose showed that I had another tab open to [www.ftc.gov](http://www.ftc.gov), and “attorney general” was in the google search box. The matter was resolved rather quickly, to my satisfaction, though I have no idea if anyone picked up on my hints. In a related, humorous note, there’s also a picture I saw somewhere (probably [failblog.org](http://failblog.org)) wherein a happy couple were posing for a picture, and right there on the nightstand was a big old tub of Anal Lube.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 5, 2009, 2:47pm UTC](https://boards.straightdope.com/t/malware-warning/479853/17 "2009-01-05T14:47:06Z")

</div>

> [@groo](#):
>
> This is interesting. I looked in both Safari and Firefox in both Tiger and Leopard, and didn’t have such an option.

Safari =\> Preferences =\> Security. The first line is Fraudulent sites.

I was checking out the Indy fan site last year, but rarely go there anymore. They have a gun section, and I like pre-WWII firearms. As for the gun site, I think everyone knows I like shooting. 😉 That site is like eBay for guns. I shouldn’t go there, since it can be expensive. I still need a .32 Colt 1903, a Walther P.38, a Luger P.08…

You threw me with the ‘Clinton conspiracy theories’, as I’m not aware that I have anything on my toolbar. Then I remembered that the site was one a CCT cited for the ‘Clinton Death Count’. I admit I have a little fun poking far-Right types with sticks, and I wanted to see what he was saying before debunking his claims. 😉

---

<div class="post-metadata">

**Author:** ![The\_Surb](https://avatars.discourse-cdn.com/v4/letter/t/ce73a5/32.png) [@The\_Surb](https://boards.straightdope.com/u/The_Surb)\
**Post date:** [January 5, 2009, 3:21pm UTC](https://boards.straightdope.com/t/malware-warning/479853/18 "2009-01-05T15:21:25Z")

</div>

> [@cckerberos](#):
>
> Not at, for.

Not to be pedantic but, isn’t that link a url\*? And if so, wouldn’t it be at this URL and also for this website?

- Using a common but not always accurate definition of URL.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 5, 2009, 3:28pm UTC](https://boards.straightdope.com/t/malware-warning/479853/19 "2009-01-05T15:28:32Z")

</div>

> [@The\_Surb](#):
>
> Not to be pedantic but, isn’t that link a url\*? And if so, wouldn’t it be at this URL and also for this website?
> 
> - Using a common but not always accurate definition of URL.

I did a Crtl+click (right-click to PC users) to copy the URL to see if that’s where it’s going. Instead of the normal menu to choose the Copy address option, I was taken directly to this page:

[Google Transparency Report](http://google.com/safebrowsing/diagnostic?tpl=safari&site=easywebsiteauditor.ru&hl=en) [Formatting not copied.]

> [@](#):
>
> Safe Browsing  
> Diagnostic page for [easywebsiteauditor.ru](http://easywebsiteauditor.ru)
> 
> What is the current listing status for [easywebsiteauditor.ru](http://easywebsiteauditor.ru)?  
> Site is listed as suspicious - visiting this web site may harm your computer.
> 
> Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.
> 
> What happened when Google visited this site?  
> Of the 2 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2008-12-19, and the last time suspicious content was found on this site was on 2008-12-19.  
> Malicious software includes 8 trojan(s), 4 scripting exploit(s). Successful infection resulted in an average of 0 new processes on the target machine.
> 
> This site was hosted on 2 network(s) including AS48511, AS44997 (UATELECOM).
> 
> Has this site acted as an intermediary resulting in further distribution of malware?  
> Over the past 90 days, [easywebsiteauditor.ru](http://easywebsiteauditor.ru) did not appear to function as an intermediary for the infection of any sites.
> 
> Has this site hosted malware?  
> Yes, this site has hosted malicious software over the past 90 days. It infected 10 domain(s), including [prorev.com/](http://prorev.com/), [daytonac.com/](http://daytonac.com/), [bpaindia.org/](http://bpaindia.org/).
> 
> How did this happen?  
> In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.
> 
> Next steps:  
> Return to the previous page.  
> If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google’s Webmaster Help Center.

---

<div class="post-metadata">

**Author:** ![Beware\_of\_Doug](https://avatars.discourse-cdn.com/v4/letter/b/278dde/32.png) [@Beware\_of\_Doug](https://boards.straightdope.com/u/Beware_of_Doug)\
**Post date:** [January 5, 2009, 3:54pm UTC](https://boards.straightdope.com/t/malware-warning/479853/20 "2009-01-05T15:54:04Z")

</div>

> [@groo](#):
>
> In a related, humorous note, there’s also a picture I saw somewhere (probably [failblog.org](http://failblog.org)) wherein a happy couple were posing for a picture, and right there on the nightstand was a big old tub of Anal Lube.

[If you must](http://www.ebaumsworld.com/pictures/view/1422/)

They don’t look all that happy.

[Next page](https://boards.straightdope.com/t/malware-warning/479853.md?page=2)
