# Virus attmpt via SDMB advertisment

**URL:** <https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731>\
**Category:** About This Message Board\
**Created:** [November 24, 2010, 1:41am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731 "2010-11-24T01:41:12Z")\
**Posts on this page:** 19\
**Page:** 2

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [November 27, 2010, 5:47pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/21 "2010-11-27T17:47:52Z")

</div>

> [@withaK](#):
>
> I’ve just had Chrome warn me about this site while opening the “Was Jane Austen black?” thread in Great Debates.

Do NOT open the link at that thread, because the guy who wrote that theory (NOT the OP) is a former poster her, and his site is full of malware. If you want to read it, google it and read the cached version.

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [November 27, 2010, 6:52pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/22 "2010-11-27T18:52:25Z")

</div>

> [@Ed\_Zotti](#):
>
> We have forwarded the recent complaints about malware to our ad provider. They have been scrutinizing the ads sent to our site but so far have not been able to identify the offending advertiser. I’ve asked if there’s any specific information they need that would make it easier to get to the bottom of this. In the meantime, please provide as many details as you can when reporting malware - time/date of occurrence, what page you were looking at, exactly what happened, any messages or notices you received, etc. We apologize for the inconvenience.

How long have these problems been going on with this ad provider? At what point do the admins say, “Fix it or we’re dumping you.”?

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [November 28, 2010, 6:23pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/23 "2010-11-28T18:23:11Z")

</div>

> [@Saint\_Cad](#):
>
> How long have these problems been going on with this ad provider? At what point do the admins say, “Fix it or we’re dumping you.”?

The problems have been intermittent and, till now, generally short-lived. The last outbreak before this was in August. I’ve spoken with Rubicon about ad-borne malware and have forwarded complaints to them. They’ve responded promptly in all cases and say they’re attempting to identify the offending advertiser, so far without success. The problem is the needle-in-a-haystack nature of the search. Rubicon operates what is basically an ad distribution engine and has partnerships with some 600 ad networks, each of which has its own clientele of advertisers and ad agencies. In short, there are thousands of players funneling content into the system.

Rubicon has safeguards in place to detect rogue ads, but the bad guys are constantly seeking ways to evade these and on occasion stuff gets through. Rubicon is a reputable firm and we’ve had a good relationship with them; the revenue they provide is our principal source of income. Malware is a [chronic problem](http://news.cnet.com/8301-13577_3-20023626-36.html) on the net and we have no reason to think a different provider would do better. I assure you we take malware reports seriously and I have every indication Rubicon does so as well. It has taken longer than expected to get to the bottom of this latest eruption but I remain hopeful that we’ll do so soon. In the meantime I ask your patience.

---

<div class="post-metadata">

**Author:** ![Dan\_Norder](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@Dan\_Norder](https://boards.straightdope.com/u/Dan_Norder)\
**Post date:** [November 28, 2010, 10:15pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/24 "2010-11-28T22:15:46Z")

</div>

Just had a page here automatically forward the browser window to:

[http://kklcg.viverprotect28.com/?id=2003&sz=6ae630e3a&vb=1&s=1](http://kklcg.viverprotect28.com/?id=2003&sz=6ae630e3a&vb=1&s=1)

Which did nothing, perhaps because someone else already shut the malware down there, because my Mac wouldn’t accept whatever the site was trying to download/reforward, or because the site is doing something else (counting successful referrals to implement some new strategy?)

If the advertiser who placed the ad with whomever served it up had some useful ID tag in it perhaps the URL has info that will help track it down faster.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [November 28, 2010, 10:22pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/25 "2010-11-28T22:22:46Z")

</div>

> [@Bearflag70](#):
>
> Last I heard, they [SDMB Admin] already know about it but made a business decision to let it happen anyway.

> [@Ed\_Zotti](#):
>
> I’ve spoken with Rubicon about ad-borne malware and have forwarded complaints to them … we’ve had a good relationship with them; the revenue they provide is our principal source of income.

See? 🙂

---

<div class="post-metadata">

**Author:** ![samclem](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@samclem](https://boards.straightdope.com/u/samclem)\
**Post date:** [November 28, 2010, 10:56pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/26 "2010-11-28T22:56:09Z")

</div>

> [@Bearflag70](#):
>
> Last I heard, they already know about it but made a business decision to let it happen anyway.

> [@Ed\_Zotti](#):
>
> I’ve spoken with Rubicon about ad-borne malware and have forwarded complaints to them… we’ve had a good relationship with them; the revenue they provide is our principal source of income.

> [@Bearflag70](#):
>
> See? 🙂

Nice editing/hatchet job. :mad:

---

<div class="post-metadata">

**Author:** ![AnalogSignal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/analogsignal/32/1085_2.png) [@AnalogSignal](https://boards.straightdope.com/u/AnalogSignal)\
**Post date:** [November 28, 2010, 11:33pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/27 "2010-11-28T23:33:44Z")

</div>

I investigated the malware inside a VMWare machine. The malware comes from this link (broken intentionally) http:// [checkwinonline.com/fps/q=jy7lno3o](http://checkwinonline.com/fps/q=jy7lno3o)

Checkwinonline redirects to [viverprotect30.com](http://viverprotect30.com) in my case. The site displays a popup via JavaScript which says: “AV8 has found suspicious activity on your pc and will perform some action on your pc.” It does fake virus scan, displays a fake Windows Security Alert, and then downloads a variant of Win32/Kryptik.IMZ trojan:

http:// [24b11615.viverprotect30.com/load/secure\_2003-1\_brs5.exe](http://24b11615.viverprotect30.com/load/secure_2003-1_brs5.exe)

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [November 28, 2010, 11:47pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/28 "2010-11-28T23:47:15Z")

</div>

> [@BrainGlutton](#):
>
> It occurs to me that, as soon as just a bit more information is available, the collective brainpower of the Doper community should be more than equal to the urgent task of tracing the malware to the live-meatspace location of its human originator and wreaking some vigilante justice of a nature to be determined later but definitely to involve lots of screaming.

I suspect that the _“brainpower of the Doper community”_ has led most of them to install AdBlock Plus or something similar on their machine. So most of us never even see these ads, and malware in the ads never has a chance to infect our machine.

Thus most of us would say ‘install AdBlock, and the problem will go away’, rather than send our ‘brainpower’ tilting at the windmill of trying to track down malware sites. Many of us have dealt with relatives or friends who won’t use anti-virus software (too much work/too annoying), but then are frequently asking for help in disinfecting their machine.

---

<div class="post-metadata">

**Author:** ![Giraffe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/giraffe/32/129_2.png) [@Giraffe](https://boards.straightdope.com/u/Giraffe)\
**Post date:** [November 29, 2010, 1:30am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/29 "2010-11-29T01:30:25Z")

</div>

> [@Ed\_Zotti](#):
>
> Rubicon operates what is basically an ad distribution engine and has partnerships with some 600 ad networks, each of which has its own clientele of advertisers and ad agencies. In short, there are thousands of players funneling content into the system.

I can’t help but wonder if this isn’t part of the problem: since Rubicon is essentially acting as a middleman for 600 (!) other ad networks, they’re going to have a fairly limited ability to fight malware coming from any given network. They may also have limited interest in doing so, if they make more money serving those ads than they lose customers from them.

Have you guys ever tried using Google Adsense to serve up your image ads? I’d imagine they pay a lot better than the text-only ads, although I don’t know if they’d be comparable to what you’re making now with Rubicon. It might be worth at least a test run, though – I’d certainly have a lot more faith in Google’s ability to detect and stop malware than Rubicon’s.

It’s also worth considering the longer-term risks of Rubicon – if we keep infecting computers we’re eventually going to start ending up on the large workplace filters’ blacklists, which is going to impact both paid members and guests alike, not to mention sending traffic and thus ad revenue through the floor.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [November 29, 2010, 2:13am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/30 "2010-11-29T02:13:18Z")

</div>

> [@samclem](#):
>
> Nice editing/hatchet job. :mad:

Tongue in cheek, hence the happy face. 🙂

---

<div class="post-metadata">

**Author:** ![Lumpy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lumpy/32/446_2.png) [@Lumpy](https://boards.straightdope.com/u/Lumpy)\
**Post date:** [November 29, 2010, 6:44am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/31 "2010-11-29T06:44:17Z")

</div>

Hit me Sunday 11-28-10 at about 10:30 pm. I got the fake AV8 screen.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [November 29, 2010, 7:43am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/32 "2010-11-29T07:43:50Z")

</div>

> [@Ed\_Zotti](#):
>
> Malware is a [chronic problem](http://news.cnet.com/8301-13577_3-20023626-36.html) on the net and we have no reason to think a different provider would do better.

While this is true in general, I note that this is the only site I’ve seen that has this particular problem. Most of these places use Google Adsense.

And, yes, Google’s back on my good side since they admitted that should have contacted TVTropes before pulling the ads. That’s all I was asking.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [November 29, 2010, 7:16pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/33 "2010-11-29T19:16:40Z")

</div>

**Ed** , no offense, honestly, but I haven’t ever seen this problem at any other message board I visit that has ads. Rubicon has proven to be unreliable – why not just try out another ad provider? (Google, as suggested)

You know what they say about doing the same thing over and over and expecting a different response?  
(In the mean time people, if you’re not on a public computer - AD BLOCK PLUS!!!)

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [November 29, 2010, 8:04pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/34 "2010-11-29T20:04:28Z")

</div>

> [@Ed\_Zotti](#):
>
> Rubicon has safeguards in place to detect rogue ads, but the bad guys are constantly seeking ways to evade these and on occasion stuff gets through. Rubicon is a reputable firm and we’ve had a good relationship with them; the revenue they provide is our principal source of income. Malware is a [chronic problem](http://news.cnet.com/8301-13577_3-20023626-36.html) on the net and we have no reason to think a different provider would do better.

Running the ads through computers with web browsers would most certainly catch all the rogue ads. :smack:

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [November 30, 2010, 7:52pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/35 "2010-11-30T19:52:33Z")

</div>

Rubicon tech support informs me they’ve pulled some suspicious tags but are uncertain if these were the root cause of the malware problems. They said it would be helpful if users who have experienced problems in the past would volunteer to install software that records ad calls for later inspection. One such program is Firebug, an add-on for Firefox. One user has already been kind enough to do this. If you got a questionable virus alert or the like you would then save the HTML for the page for review. This will make it easier to identify bad ads.

---

<div class="post-metadata">

**Author:** ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)\
**Post date:** [November 30, 2010, 10:49pm UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/36 "2010-11-30T22:49:34Z")

</div>

> [@](#):
>
> Rubicon is a reputable firm and we’ve had a good relationship with them

**You** have had a good relationship with them. **Your users** haven’t. And I’d argue that your relationship with them isn’t all that good if they expect to shrug and say “yeah, we think we found it” and then ask your users to install debugging tools in order to make it easier to report the malware that will inevitably slip through in the future.

You say you don’t think a different ad provider would be any different. Have any of these malware reports been narrowed down to the Google ads?

---

<div class="post-metadata">

**Author:** ![MsWhatsit](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@MsWhatsit](https://boards.straightdope.com/u/MsWhatsit)\
**Post date:** [December 1, 2010, 12:22am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/37 "2010-12-01T00:22:46Z")

</div>

This is embarrassing. I have suggested the SDMB to friends in the past but am no longer going to do so until this problem is fixed. I don’t want to be even indirectly responsible for someone getting hit with malware. And yes, I participate at several other message boards, some largeish, all ad-supported, and the SDMB is the only one that has this problem.

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [December 1, 2010, 12:39am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/38 "2010-12-01T00:39:49Z")

</div>

Another issue is the lack of a solution is encouraging people to simply block ads, which cuts down on your income. I realize that only a very small percentage of the “guests” probably use ad blockers, but it has been suggested several times, so people will eventually take the hint.

By the way, why is a rubiconproject script ([http://tap-cdn.rubiconproject.com/partner/scripts/rubicon/alice.js?pc=7184/13018](http://tap-cdn.rubiconproject.com/partner/scripts/rubicon/alice.js?pc=7184/13018) in my case) being run even for members?

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 1, 2010, 12:59am UTC](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731/39 "2010-12-01T00:59:32Z")

</div>

You wouldn’t have to remove rubicon right away if you want to experiment with Google. But I’ll point out that it generated so much revenue for TVTropes that the loss of it was nearly fatal (even if they downplayed it.)

[Previous page](https://boards.straightdope.com/t/virus-attmpt-via-sdmb-advertisment/561731.md?page=1)
