# SDMB malware

**URL:** <https://boards.straightdope.com/t/sdmb-malware/561877>\
**Category:** About This Message Board\
**Created:** [November 25, 2010, 3:03pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877 "2010-11-25T15:03:39Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Loach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/loach/32/350_2.png) [@Loach](https://boards.straightdope.com/u/Loach)\
**Post date:** [November 25, 2010, 3:03pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/1 "2010-11-25T15:03:39Z")

</div>

one of your wonderful pop down ads just made my virus protection light up like a Christmas tree. Don’t know what it was cause I shut it down very quick. Do you take money from anyone or do you check it out first? I know have to decide if I’m ever going to come back. As a general rule I try to stay away from sites that effect my computer. I don’t think I’m alone in that.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [November 25, 2010, 3:12pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/2 "2010-11-25T15:12:15Z")

</div>

As I understand it, the ads come from an ad broker.

If you can, TPTB need things like screenshots or some identification of the ad so they can forward the report to the provider.

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [November 25, 2010, 3:30pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/3 "2010-11-25T15:30:32Z")

</div>

This again? Straight Dope ads are the worst! No malware for me in a while but at least 2-3 times a week an ad on SD will crash my Explorer

---

<div class="post-metadata">

**Author:** ![Loach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/loach/32/350_2.png) [@Loach](https://boards.straightdope.com/u/Loach)\
**Post date:** [November 25, 2010, 3:33pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/4 "2010-11-25T15:33:10Z")

</div>

> [@runner pat](#):
>
> As I understand it, the ads come from an ad broker.
> 
> If you can, TPTB need things like screenshots or some identification of the ad so they can forward the report to the provider.

Well I was too concerned with keeping my laptop from being ruined to gather the information for the admins. Guess the malware stays. Good luck everyone!:smack:

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [November 25, 2010, 3:41pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/5 "2010-11-25T15:41:46Z")

</div>

Besides paying for a sub, I also run AdBlock Plus and NoScript in Firefox so I never get the ads. Keeps the system clean.

I think the way it works is there are spaces in the page that are reserved for the ads and the ads are fed direct from the broker with no control by The Dope or Creative Loafing.

ETA: might be time for a new ad provider as this one doesn’t seem to check the ads they’re serving.

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [November 25, 2010, 4:17pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/6 "2010-11-25T16:17:50Z")

</div>

Reported.

---

<div class="post-metadata">

**Author:** ![Loach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/loach/32/350_2.png) [@Loach](https://boards.straightdope.com/u/Loach)\
**Post date:** [November 25, 2010, 4:47pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/7 "2010-11-25T16:47:03Z")

</div>

> [@TubaDiva](#):
>
> Reported.

Thank you.

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [November 25, 2010, 4:50pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/8 "2010-11-25T16:50:00Z")

</div>

I think I just got this from the SDMB. I sandbox my browser so it doesn’t really affect me.

This web page at **[checkwinonline.com](http://checkwinonline.com)** has been reported as an attack page and has been blocked based on your security preferences.

Attack pages try to install programs that steal private information, use your computer to attack others, or damage your system.

Some attack pages intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [November 25, 2010, 5:32pm UTC](https://boards.straightdope.com/t/sdmb-malware/561877/9 "2010-11-25T17:32:42Z")

</div>

> [@runner pat](#):
>
> As I understand it, the ads come from an ad broker.
> 
> If you can, TPTB need things like screenshots or some identification of the ad so they can forward the report to the provider.

Perhaps they need a new ad broker then? This isn’t a new problem, it’s been pointed out time and time again.  
(In the mean time, thank GOD, for Ad Block Plus!)

---

<div class="post-metadata">

**Author:** ![dzero](https://avatars.discourse-cdn.com/v4/letter/d/5f9b8f/32.png) [@dzero](https://boards.straightdope.com/u/dzero)\
**Post date:** [November 26, 2010, 2:32am UTC](https://boards.straightdope.com/t/sdmb-malware/561877/10 "2010-11-26T02:32:40Z")

</div>

I use adblock+ but do allow scripts to run - at least, SDMB scripts. I do however block the tracking sites (exelate, google analytics, quantcast and rubicon) with ghostery.

As was already stated, because of adblock and noscript, I rarely have a problem, but I did recently with Peapod. It seems that the ads they serve are hosted on their own servers so by allowing scripts on their site, any malware in an ad triggers my AV software.

I reported this to them but never got an answer as to where the ads come from. Fortunately, they are presented in frames rather than being incorporated into each web page so it’s easy enough to use adblock to kill those frames.
