# Virus attmpt via SDMB advertisment

**URL:** <https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731>\
**Category:** About This Message Board\
**Created:** [November 24, 2010, 1:41am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731 "2010-11-24T01:41:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [November 24, 2010, 1:41am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/1 "2010-11-24T01:41:12Z")

</div>

At 8:30 pm, US EST, whilst viewing the “What’s it like to sleep with someone?” thread in IMHO (link below), the SDMB browser session tried to download a trojan via one of the images in the advert playing on the page.

On attempt to cancel the action, the virus took control of the window and attempted to ‘run a scan’ on my computer, and download files to my system. My software stopped it, but was unable to capture the virus - I’m using Avast 4.8 (free version) on Win XP and IE 8.0.6x

> **[What's it like to sleep with someone?](https://boards.straightdope.com/sdmb/showthread.php?t=586047)**
>
> And no, I don’t mean sex. Does sleeping together enhance your relationship? Does it help you bond? Would it hurt your relationship to sleep apart? I’ve never as an adult slept with another person and likely never will, so I am deeply ignorant here.

---

<div class="post-metadata">

**Author:** ![Al\_Bundy](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@Al\_Bundy](https://boards.straightdope.com/u/Al_Bundy)\
**Post date:** [November 24, 2010, 2:03am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/2 "2010-11-24T02:03:36Z")

</div>

I’ve never had this problem running Foxfire and NOScript.

Glad your system stopped the threat.

Maybe it’s time to change browsers.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [November 24, 2010, 2:17am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/3 "2010-11-24T02:17:34Z")

</div>

Of course you won’t have a problem with NoScript, assuming you also have it blocking Flash. That cuts off all the attack vectors. But NoScript is a bit of a pain to use, as you have to whitelist everythign manually, and most people will find Adblock Plus sufficient.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [November 24, 2010, 3:30am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/4 "2010-11-24T03:30:36Z")

</div>

Yanno, this wasn’t an ask for advice - I’d have posted that in GQ.

This is information for the Admins so they can deal with an ad server that’s serving up infected files.  
But I thank you for your concern all the same. 😉

---

<div class="post-metadata">

**Author:** ![BlankSlate](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/blankslate/32/80_2.png) [@BlankSlate](https://boards.straightdope.com/u/BlankSlate)\
**Post date:** [November 24, 2010, 7:27am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/5 "2010-11-24T07:27:05Z")

</div>

Was the fake AV scanner called AV8?

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [November 24, 2010, 7:37am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/6 "2010-11-24T07:37:10Z")

</div>

> [@Tranquilis](#):
>
> Yanno, this wasn’t an ask for advice - I’d have posted that in GQ.
> 
> This is information for the Admins so they can deal with an ad server that’s serving up infected files.  
> But I thank you for your concern all the same. 😉

Last I heard, they already know about it but made a business decision to let it happen anyway.

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [November 24, 2010, 1:57pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/7 "2010-11-24T13:57:06Z")

</div>

We have forwarded the recent complaints about malware to our ad provider. They have been scrutinizing the ads sent to our site but so far have not been able to identify the offending advertiser. I’ve asked if there’s any specific information they need that would make it easier to get to the bottom of this. In the meantime, please provide as many details as you can when reporting malware - time/date of occurrence, what page you were looking at, exactly what happened, any messages or notices you received, etc. We apologize for the inconvenience.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [November 24, 2010, 2:05pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/8 "2010-11-24T14:05:31Z")

</div>

Thanks, Ed. 'Preciate.  
Tried to do just that, so much as I had available.

> [@BlankSlate](#):
>
> Was the fake AV scanner called AV8?

Could be - Between my software and myself, we killed it so fast I didn’t get more than a glimpse, but that seems right.

---

<div class="post-metadata">

**Author:** ![BrainGlutton](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@BrainGlutton](https://boards.straightdope.com/u/BrainGlutton)\
**Post date:** [November 24, 2010, 4:05pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/9 "2010-11-24T16:05:23Z")

</div>

This morning has to be fourth time in the past two weeks that my system has immediately disconnected me from the SDMB and warned of a Trojan horse blocked.

---

<div class="post-metadata">

**Author:** ![BrainGlutton](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@BrainGlutton](https://boards.straightdope.com/u/BrainGlutton)\
**Post date:** [November 24, 2010, 4:07pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/10 "2010-11-24T16:07:28Z")

</div>

> [@Ed\_Zotti](#):
>
> We have forwarded the recent complaints about malware to our ad provider. They have been scrutinizing the ads sent to our site but so far have not been able to identify the offending advertiser. I’ve asked if there’s any specific information they need that would make it easier to get to the bottom of this. In the meantime, please provide as many details as you can when reporting malware - time/date of occurrence, what page you were looking at, exactly what happened, any messages or notices you received, etc. We apologize for the inconvenience.

It occurs to me that, as soon as just a bit more information is available, the collective brainpower of the Doper community should be more than equal to the urgent task of tracing the malware to the live-meatspace location of its human originator and wreaking some vigilante justice of a nature to be determined later but definitely to involve lots of screaming.

Just a suggestion.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [November 25, 2010, 11:21pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/11 "2010-11-25T23:21:38Z")

</div>

> [@Tranquilis](#):
>
> Could be - Between my software and myself, we killed it so fast I didn’t get more than a glimpse, but that seems right. .

if you open your antivirus/antispyware program, there should be a tab or link for viewing the scanning/removal logs, which will tell you what program was removed.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [November 26, 2010, 4:27am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/12 "2010-11-26T04:27:19Z")

</div>

> [@Fear\_Itself](#):
>
> if you open your antivirus/antispyware program, there should be a tab or link for viewing the scanning/removal logs, which will tell you what program was removed.

I had my log settings too low, so I don’t have a record of the kill. ☹

---

<div class="post-metadata">

**Author:** ![Lynn\_Bodoni](https://avatars.discourse-cdn.com/v4/letter/l/e47c2d/32.png) [@Lynn\_Bodoni](https://boards.straightdope.com/u/Lynn_Bodoni)\
**Post date:** [November 26, 2010, 10:04am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/13 "2010-11-26T10:04:22Z")

</div>

> [@BrainGlutton](#):
>
> It occurs to me that, as soon as just a bit more information is available, the collective brainpower of the Doper community should be more than equal to the urgent task of tracing the malware to the live-meatspace location of its human originator and wreaking some vigilante justice of a nature to be determined later but definitely to involve lots of screaming.
> 
> Just a suggestion.

Don’t think that I haven’t been tempted to put out a Call to Action on various companies/people. If I can ever get a volume discount on Tasers, I might do it.

---

<div class="post-metadata">

**Author:** ![The\_Tao\_s\_Revenge](https://avatars.discourse-cdn.com/v4/letter/t/73ab20/32.png) [@The\_Tao\_s\_Revenge](https://boards.straightdope.com/u/The_Tao_s_Revenge)\
**Post date:** [November 26, 2010, 11:01pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/14 "2010-11-26T23:01:06Z")

</div>

I just had firefox warn me [http://checkwinonline.com/fps/q=jy7lno3o](http://checkwinonline.com/fps/q=jy7lno3o) was an attack site when I opened a thread in MPSIMS. An ad on the page must of had browser hijack code.

Posting in case that narrows down the search any.

---

<div class="post-metadata">

**Author:** ![The\_Tao\_s\_Revenge](https://avatars.discourse-cdn.com/v4/letter/t/73ab20/32.png) [@The\_Tao\_s\_Revenge](https://boards.straightdope.com/u/The_Tao_s_Revenge)\
**Post date:** [November 26, 2010, 11:03pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/15 "2010-11-26T23:03:53Z")

</div>

Also

> **[Google Transparency Report](https://transparencyreport.google.com/safe-browsing/search?url=http:%2F%2Fcheckwinonline.com%2Ffps%2Fq=jy7lno3o&hl=en-US)**

Is the “why this page was blocked” info page.

> [@](#):
>
> What happened when Google visited this site?
> 
> ```
> Of the 3 pages we tested on the site over the past 90 days, 1 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-11-25, and the last time suspicious content was found on this site was on 2010-11-25.
> 
> Malicious software includes 4 scripting exploit(s). Successful infection resulted in an average of 1 new process(es) on the target machine.
> 
> Malicious software is hosted on 10 domain(s), including rltk.gen.in/, web-case.tk/, erpo.in/.
> 
> This site was hosted on 1 network(s) including AS35415 (WEBAZILLA).
> 
> ```
> 
> Has this site acted as an intermediary resulting in further distribution of malware?
> 
> ```
> Over the past 90 days, checkwinonline.com did not appear to function as an intermediary for the infection of any sites.
> 
> ```
> 
> Has this site hosted malware?
> 
> ```
> No, this site has not hosted malicious software over the past 90 days.
> 
> ```
> 
> How did this happen?
> 
> ```
> In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message
> 
> ```

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [November 27, 2010, 5:16am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/16 "2010-11-27T05:16:13Z")

</div>

> [@The\_Tao\_s\_Revenge](#):
>
> I just had firefox warn me [http://checkwinonline.com/fps/q=jy7lno3o](http://checkwinonline.com/fps/q=jy7lno3o) was an attack site when I opened a thread in MPSIMS. An ad on the page must of had browser hijack code.

I am getting the exact same warning about [checkwinonline.com](http://checkwinonline.com) now and I originally got warned about this site on Nov. 25.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [November 27, 2010, 5:34am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/17 "2010-11-27T05:34:59Z")

</div>

> [@BigT](#):
>
> … most people will find Adblock Plus sufficient.

This. I cannot reccomend it enough.  
Seriously, this has been going on for what, almost a year now? Is there ANY serious talk of dumping rubicon?

---

<div class="post-metadata">

**Author:** ![withaK](https://avatars.discourse-cdn.com/v4/letter/w/8e7dd6/32.png) [@withaK](https://boards.straightdope.com/u/withaK)\
**Post date:** [November 27, 2010, 3:30pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/18 "2010-11-27T15:30:50Z")

</div>

> [@The\_Tao\_s\_Revenge](#):
>
> I just had firefox warn me [http://checkwinonline.com/fps/q=jy7lno3o](http://checkwinonline.com/fps/q=jy7lno3o) was an attack site when I opened a thread in MPSIMS. An ad on the page must of had browser hijack code.
> 
> Posting in case that narrows down the search any.

I’ve just had Chrome warn me about this site while opening the “Was Jane Austen black?” thread in Great Debates.

---

<div class="post-metadata">

**Author:** ![Lord\_Ashtar](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@Lord\_Ashtar](https://boards.straightdope.com/u/Lord_Ashtar)\
**Post date:** [November 27, 2010, 4:52pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/19 "2010-11-27T16:52:20Z")

</div>

Chrome just gave me the following error when getting ready to reply to [this thread](http://boards.straightdope.com/sdmb/showthread.php?t=580690):

_The website at [checkwinonline.com](http://checkwinonline.com) appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that hosts malware can infect your computer.  
For detailed information about the problems with this site, visit the Google Safe Browsing diagnostic page for [checkwinonline.com](http://checkwinonline.com).  
Learn more about how to protect yourself from harmful software online._

Please fix this.

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [November 27, 2010, 5:40pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/20 "2010-11-27T17:40:03Z")

</div>

[checkwinonline.com](http://checkwinonline.com) is still going strong on day 3 of activity.

Don’t bother reporting the thread. The ads are rotated randomly and are not thread specific. I seem to get it on about 5% of the pages viewed.

The SDMB is an excellent vector of attack for malware purveyors considering how many people look at the site, how often malware ads are served, and how many days known malware ads are allowed to remain on the site.

[Next page](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731.md?page=2)
