# Redirected to "Getsoftfree"?

**URL:** https://boards.straightdope.com/t/redirected-to-getsoftfree/679465
**Category:** About This Message Board
**Created:** [January 22, 2014, 7:20pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465 "2014-01-22T19:20:38Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Sailboat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sailboat/32/461_2.png) [@Sailboat](https://boards.straightdope.com/u/Sailboat)
#### Post date: [January 22, 2014, 7:20pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/1 "2014-01-22T19:20:38Z")

</div>

Just searched using the Advanced Search tool, and when I hit the “back” button, I was apparently directed to “Getsoftfree” .(something-or-other, didn’t look that closely) which was identified by my system as a “web forgery.”

---

<div class="post-metadata">

### Author: ![Buck\_Godot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/buck_godot/32/6573_2.png) [@Buck\_Godot](https://boards.straightdope.com/u/Buck_Godot)
#### Post date: [January 22, 2014, 8:25pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/2 "2014-01-22T20:25:34Z")

</div>

Me too when I was using firefox, and would look at any page on the straight dope message board. Told me my video browser was out of date and I needed to download a new version. :dubious: I’m on Chrome now and not having a problem. Maybe the site is hacked?

---

<div class="post-metadata">

### Author: ![Tapioca\_Dextrin](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@Tapioca\_Dextrin](https://boards.straightdope.com/u/Tapioca_Dextrin)
#### Post date: [January 22, 2014, 9:30pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/3 "2014-01-22T21:30:30Z")

</div>

No problems here using Firefox 26.0

---

<div class="post-metadata">

### Author: ![Buck\_Godot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/buck_godot/32/6573_2.png) [@Buck\_Godot](https://boards.straightdope.com/u/Buck_Godot)
#### Post date: [January 22, 2014, 9:53pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/4 "2014-01-22T21:53:14Z")

</div>

I was also using 26.0, and am still having a problem when I enter any thread. Although now I’m getting the same “web forgery” message as Sailboat.

---

<div class="post-metadata">

### Author: ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)
#### Post date: [January 22, 2014, 10:23pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/5 "2014-01-22T22:23:49Z")

</div>

Just count yourself lucky you weren’t redirected to “Gethardfree”.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [January 22, 2014, 10:54pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/6 "2014-01-22T22:54:43Z")

</div>

You probably have “AirAdInstaller”. It’s a nasty one to remove. If your current malware software can’t remove it, Google for help.

There have been reports of browser addons being bought out by malware deliverers who then post “updates” to the addon that install malware. You may not have even done anything if the browser to set to auto-update addons. Chrome has been hit hard, not sure about Firefox.

---

<div class="post-metadata">

### Author: ![Buck\_Godot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/buck_godot/32/6573_2.png) [@Buck\_Godot](https://boards.straightdope.com/u/Buck_Godot)
#### Post date: [January 22, 2014, 11:50pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/7 "2014-01-22T23:50:06Z")

</div>

ftg,

Why would what you describe only affect sailboat and I when we visit the dope and why would it just be starting for both of us now? In any case I’ll try running a full malware sweep just in case.  
ETA: Hmmm, actually it seems to have stopped at least for now.

---

<div class="post-metadata">

### Author: ![Crazyhorse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crazyhorse/32/31_2.png) [@Crazyhorse](https://boards.straightdope.com/u/Crazyhorse)
#### Post date: [January 23, 2014, 12:08am UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/8 "2014-01-23T00:08:44Z")

</div>

In my case it isn’t local malware, it’s ads on the SDMB forcing redirects through Flash scripting.

[Here is an example](http://imageshack.com/a/img33/2383/tjld.jpg) from browsing just a few threads without my quadruple layer of adblock, secure hosts file, anti virus, anti malware, which is necessary to surf the dope safely. (server being hacked notwithstanding)

Fortunately even Chrome’s built-in security wouldn’t allow the redirect to a phishing site. If successfully redirected, I would have been encouraged to update my Flash player with a rogue, malware infected version.

---

<div class="post-metadata">

### Author: ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)
#### Post date: [January 23, 2014, 1:51am UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/9 "2014-01-23T01:51:40Z")

</div>

> [@ftg](#):
>
> There have been reports of browser addons being bought out by malware deliverers who then post “updates” to the addon that install malware. You may not have even done anything if the browser to set to auto-update addons. Chrome has been hit hard, not sure about Firefox.

Here’s a link to an article from several days ago in which this was discussed.

[Adware vendors buy Chrome Extensions to send ad- and malware-filled updates](http://arstechnica.com/security/2014/01/malware-vendors-buy-chrome-extensions-to-send-adware-filled-updates/) by Ron Amadeo, arstechnica, Jan 17, 2014.

Excerpt:

> [@](#):
>
> To make matters worse, ownership of a Chrome extension can be transferred to another party, and users are never informed when an ownership change happens. Malware and adware vendors have caught wind of this and have started showing up at the doors of extension authors, looking to buy their extensions. Once the deal is done and the ownership of the extension is transferred, the new owners can issue an ad-filled update over Chrome’s update service, which sends the adware out to every user of that extension.

You can Google for many more articles on the subject, as this was much in the news lately.

---

<div class="post-metadata">

### Author: ![Siam\_Sam](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@Siam\_Sam](https://boards.straightdope.com/u/Siam_Sam)
#### Post date: [January 23, 2014, 3:30am UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/10 "2014-01-23T03:30:52Z")

</div>

> [@Tapioca\_Dextrin](#):
>
> No problems here using Firefox 26.0

Ditto.

---

<div class="post-metadata">

### Author: ![Tapioca\_Dextrin](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@Tapioca\_Dextrin](https://boards.straightdope.com/u/Tapioca_Dextrin)
#### Post date: [January 23, 2014, 5:06am UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/11 "2014-01-23T05:06:18Z")

</div>

> [@Tapioca\_Dextrin](#):
>
> No problems here using Firefox 26.0

Also, paid member, plus Adblock

---

<div class="post-metadata">

### Author: ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)
#### Post date: [January 23, 2014, 4:37pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/12 "2014-01-23T16:37:53Z")

</div>

So can’t tell if this is coming from an ad specifically or from your brower? Fiendish. Bastids.

Just the same, we have to try to look at things. If you see this, please try to look at what else is on the page – a screen shot would be helpful. Send that to me. [tubadiva@straightdope.com](mailto:tubadiva@straightdope.com)

---

<div class="post-metadata">

### Author: ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)
#### Post date: [January 23, 2014, 4:47pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/13 "2014-01-23T16:47:26Z")

</div>

Thank you for the link, Senegoid – that is very useful, especially in view of what’s been happening lately. I have sent all this upstairs.

If you encounter any of these situations and you’re reporting them in this thread, please also list your operating system and browser, that may be helpful. Also screen shots are almost always helpful as well; if we can point to any one ad entity as a bad actor, we may be able to do something. Of course if it’s something more broad-based (like your browser), that’s more difficult. ☹

---

<div class="post-metadata">

### Author: ![Sailboat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sailboat/32/461_2.png) [@Sailboat](https://boards.straightdope.com/u/Sailboat)
#### Post date: [January 23, 2014, 5:16pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/14 "2014-01-23T17:16:05Z")

</div>

Well, it hasn’t happened today. Windows 7 Enterprise Edition, Mozilla Firefox 26.0.

IT staff may or may not have done things behind the scenes on my end.

---

<div class="post-metadata">

### Author: ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)
#### Post date: [January 23, 2014, 6:40pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/15 "2014-01-23T18:40:17Z")

</div>

> [@Senegoid](#):
>
> Here’s a link to an article from several days ago in which this was discussed.
> 
> [Adware vendors buy Chrome Extensions to send ad- and malware-filled updates](http://arstechnica.com/security/2014/01/malware-vendors-buy-chrome-extensions-to-send-adware-filled-updates/) by Ron Amadeo, arstechnica, Jan 17, 2014.
> 
> Excerpt:  
> You can Google for many more articles on the subject, as this was much in the news lately.

Anecdote. Firefox suggested I “Reset” it if my startup was slow. It was and I did yesterday. When reinstalling addons, I chose the wrong version of IEView, which sent me to a scammy webpage in Firefox. No worries: I uninstalled it.

# My point is that this problem afflicts Firefox as well.

No problems at this board though.

---

<div class="post-metadata">

### Author: ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)
#### Post date: [January 24, 2014, 8:14pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/16 "2014-01-24T20:14:01Z")

</div>

I really, really, really really wish it wasn’t Google bankrolling Firefox.

---

<div class="post-metadata">

### Author: ![Crazyhorse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crazyhorse/32/31_2.png) [@Crazyhorse](https://boards.straightdope.com/u/Crazyhorse)
#### Post date: [January 24, 2014, 11:33pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/17 "2014-01-24T23:33:01Z")

</div>

> [@TubaDiva](#):
>
> If you encounter any of these situations and you’re reporting them in this thread, please also list your operating system and browser, that may be helpful. Also screen shots are almost always helpful as well; if we can point to any one ad entity as a bad actor, we may be able to do something. Of course if it’s something more broad-based (like your browser), that’s more difficult. ☹

Just a suggestion, but it might help the administrators of the board see how common, frequent, and easy to reproduce these issues are if they just view the site with ads themselves. It is probably simple to make the administrator/mod groups subject to ads, and then you could be getting first-hand reports for the folks upstairs.

In my case, mentioned in post #8, this was definitely an ad. No add-on, extension, or other malware on my own system was involved. An ad displayed on the SDMB tried to redirect me to a phony Adobe website. I have no way of saying which ad because by that time I was at another website viewing a stern warning from Chrome not to proceed. By the time I returned to the SDMB page from where I began there would be an entirely different set of ads.

I’m not willing to keep reloading pages over and over with no adblocker hoping to encounter malware again, but as I said if the admins and mods regularly used the site with ads themselves it would be a short time before you had some first-hand cases to report.

---

<div class="post-metadata">

### Author: ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)
#### Post date: [January 25, 2014, 1:08am UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/18 "2014-01-25T01:08:58Z")

</div>

Even without changing the administrator settings, you could get the same effect just by logging out.

---

<div class="post-metadata">

### Author: ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)
#### Post date: [January 25, 2014, 3:54pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/19 "2014-01-25T15:54:55Z")

</div>

> [@Crazyhorse](#):
>
> Just a suggestion, but it might help the administrators of the board see how common, frequent, and easy to reproduce these issues are if they just view the site with ads themselves. It is probably simple to make the administrator/mod groups subject to ads, and then you could be getting first-hand reports for the folks upstairs.
> 
> In my case, mentioned in post #8, this was definitely an ad. No add-on, extension, or other malware on my own system was involved. An ad displayed on the SDMB tried to redirect me to a phony Adobe website. I have no way of saying which ad because by that time I was at another website viewing a stern warning from Chrome not to proceed. By the time I returned to the SDMB page from where I began there would be an entirely different set of ads.
> 
> I’m not willing to keep reloading pages over and over with no adblocker hoping to encounter malware again, but as I said if the admins and mods regularly used the site with ads themselves it would be a short time before you had some first-hand cases to report.

I do this from time to time.

I have yet to see anything personally. Maybe I’m just lucky. ☹

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [January 25, 2014, 3:56pm UTC](https://boards.straightdope.com/t/redirected-to-getsoftfree/679465/20 "2014-01-25T15:56:59Z")

</div>

> [@Crazyhorse](#):
>
> Just a suggestion, but it might help the administrators of the board see how common, frequent, and easy to reproduce these issues are if they just view the site with ads themselves. It is probably simple to make the administrator/mod groups subject to ads, and then you could be getting first-hand reports for the folks upstairs.

One of the difficulties sites have in duplicating bad ads is that the secondary ad servers can send different ads to users based on IP addresses. So if someone with an IP address in the same range as the client server views a page, they might get innocuous, sound-free, ads.

The real solution is that the primary ad companies have to host all the ads on their own site, after running them thru safety scripts. Allowing ads to be hosted on any random site is a horrible idea. Sure this ups their bandwidth costs, but the bandwidth is being paid by someone, just move the cost to the primary site. The ad suppliers pay more for ad placement, but less for bandwidth.

Why the clients put up with this is beyond me.
