Redirect 'virus' resolved ... its a TBN feature!

   / Redirect 'virus' resolved ... its a TBN feature! #1  

California

Super Star Member
Joined
Jan 22, 2004
Messages
14,744
Location
An hour north of San Francisco
Tractor
Yanmar YM240 Yanmar YM186D
I got home to the 'infected' pc and figured it out. Turns out I already had the solution in the thread where I declared the problem: Help with a Redirect Virus .

This nuisance Redirect is a moneymaking feature added to TBN and also subscribed to by Harbor Freight. Whenever someone here clicks on a link to Harbor Freight, the click generates a payment to TBN because the link goes via a 'man-in-the-middle' and then onward to HF.

As I posted in my initial thread, here's how your click on a HF trailer-jack link gets to HF: [spaces added so this won't actually link]

http: // api.viglink.com/api/click?format=go&jsonp=vglnk_14235203345829&key=a6c 73c8a58f6c5d5816e8336c8228973&libId=095eaefa-38af-47eb-b976-aed3cc6b6387&loc=http%3A%2F%2Fwww.tractorbynet.com %2Fforums%2Fparts-repairs%2F114176-harbor-freight-tools-dont-suck-216.html%23post4035679&v=1&out=http%3A%2F%2Fwww.ha rborfreight.com%2F1500-lb-capacity-dual-wheel-swing-back-boat-trailer-jack-67500.html&ref=http%3A%2F%2Fwww.tractorbynet.com%2 Fforums%2Fsubscription.php%3Fdo%3Dviewsubscription &title=Harbor%20Freight%20Tools%20that%20don%27t%2 0suck%20-%20Page%20216&txt=1500%20Lb.%20Capacity%20Dual%20W heel%20Swing-Back%20Boat%20Trailer%20Jack

Vigilink's claim on their home page:
VigLink is the platform on which site-to-site clicks are priced, bought, and sold.
Publishers: Get paid for the sales you drive.

Advertisers: Gain customers through relevant content.

Turns out my ISP doesn't like one of the sites that this Vigilink redirects traffic to:

http://www.emjcd.com/1d111nmvuE/mty...74A9-kdueru-iuhljkw-wrrov-grqw-vxfn-549.kwpo<

If you don't want to click on that, (not recommended!) it looks approximately like this screen print below except emjcd.com is the site reported blocked.

file.php


Again, quoting from my prior thread:
It looks like VigLink is redirecting to emjcd .com , 'Commission Junction' - a site that offers you 'valuable coupons' to download.

Herdprotect Anti-malware (whoever that is) declares that emjcd downloads malware.

This might explain why my ISP blocks the (redirected) link that should have gone directly from TBN to HF.

I found a lengthy thread on this at Sonic.net, my ISP. "It's a trap! Reported phishing or malware site" : who?


To summarize that thread, Sonic subscribers complained that Washington Post was blocked at one point. Another poster said he lost out on a killing in Bitcoins when an Exchange site disappeared during a short period of abnormal prices. He proposed that this was deliberate manipulation of DNSSEC to someone's financial advantage.

The owner of the ISP referred to this description of DNSSEC which they use:
What is DNSSEC?

DNSSEC is an enhanced level of Internet security that enables validation of DNS traffic to ensure that it has not been tampered with. This prevents hackers from injecting false information (aka DNS cache 'poisoning'), in an attempt to re-direct people trying to access a real website to a fake, phishing or criminal site.

And that internal Wiki says Google's public servers also use DNSSEC, which is why my changes from 'default' to the ISP's DNS server, and then to Google's DNS server (8.8.8.8), continued to cause the same error message.

Sonic offers opt-out DNS service (unfiltered) if that's what you want: DNS_Opt-Out

In summary - DNSSEC causes Vigilink's man-in-the-middle link through emjcd .com to terminate at an error page instead of passing through to the intended destination.


As for my PC - I learned CC can modify more than I intended (fonts disappeared!). After I ran the System Restore image from January 31 everything came back to normal. I ran Windows Update, and now I'll run Ninite, to catch anything that needs update subsequent to 1/31.

Issue resolved! Thanks everyone for your good advice over in the other thread. :drink:
 

Tractor & Equipment Auctions

2018 Toro Grounds Master 7200 72in Zero Turn Commercial Mower (A42744)
2018 Toro Grounds...
2014 CS&P  BLENDER (A45333)
2014 CS&P BLENDER...
Unused 418' Fence W/ 18' Swing Gate (A42021)
Unused 418' Fence...
2009 CHARLTON & HILL HYDRATION TRAILER (A45333)
2009 CHARLTON &...
PALLET OF GAS CANS (A45333)
PALLET OF GAS CANS...
2015 FREIGHTLINER CASCADIA TANDEM AXLE SLEEPER (A43003)
2015 FREIGHTLINER...
 
Top