Here's the problem. Sourceforge, like 10s of millions of other websites, allows advertising via various Ad networks, including Google Adsense. Context sensitive Ads are served up randomly, based on keywords contained on a given webpage and optionally, keywords entered by the account holder. Advertisers want you to download various download managers, trial-ware, tool-bars and such, which may contain adware or spyware. When you go to a download page on any website that uses one of these Ad networks, like Google Adsense, the context search scripts will pick up the keyword "download" and start serving up ADs that contain a download button, in hopes that some of the users will click and install that by mistake.
Windows users are the most vulnerable because as a matter of practice, they install binaries from various websites all over the internet. This opens Windows users up to a plethora of potential attack vectors, so they have to be extra careful not to fall prey to these types of shenanigans. In the end though, they are agreeing to install the junk and they should take a moment to the read the TOS before answering "yes" to anything. For the most part, Linux users don't have to worry about these kinds of things because they usually install binaries from their disros' repositories. Windows users also tend to be less "techie" and can be easily confused when it comes to installing binaries.
Getting to my main point, this is an issue that Windows users face on any website that displays Ads from Google or any other Ad network, no matter which package, GIMP or otherwise, they are looking to download and install. The same type of ADs containing download buttons appear on every package on Sourceforge. Just pick a package at random, refresh the screen that contains the ADs a few times, and you'll see what I mean.
Here is a screen shot of a case in point: emule.

So, what is the solution? The only solution is to place the files on a page that doesn't display ADs from Google (or one of the other popular AD networks). As far as GIMP is concerned, that would be whoever is responsible for the decision to use Sourceforge as their binary hosting site. My suggestion, to avoid this kind of thing, would be for GIMP binaries to be hosted directly on gimp.org.