California
Super Star Member
- Joined
- Jan 22, 2004
- Messages
- 14,744
- Location
- An hour north of San Francisco
- Tractor
- Yanmar YM240 Yanmar YM186D
I got home to the 'infected' pc and figured it out. Turns out I already had the solution in the thread where I declared the problem: Help with a Redirect Virus .
This nuisance Redirect is a moneymaking feature added to TBN and also subscribed to by Harbor Freight. Whenever someone here clicks on a link to Harbor Freight, the click generates a payment to TBN because the link goes via a 'man-in-the-middle' and then onward to HF.
As I posted in my initial thread, here's how your click on a HF trailer-jack link gets to HF: [spaces added so this won't actually link]
Vigilink's claim on their home page:
Turns out my ISP doesn't like one of the sites that this Vigilink redirects traffic to:
http://www.emjcd.com/1d111nmvuE/mty...74A9-kdueru-iuhljkw-wrrov-grqw-vxfn-549.kwpo<
If you don't want to click on that, (not recommended!) it looks approximately like this screen print below except emjcd.com is the site reported blocked.
Again, quoting from my prior thread:
I found a lengthy thread on this at Sonic.net, my ISP. "It's a trap! Reported phishing or malware site" : who?
To summarize that thread, Sonic subscribers complained that Washington Post was blocked at one point. Another poster said he lost out on a killing in Bitcoins when an Exchange site disappeared during a short period of abnormal prices. He proposed that this was deliberate manipulation of DNSSEC to someone's financial advantage.
The owner of the ISP referred to this description of DNSSEC which they use:
And that internal Wiki says Google's public servers also use DNSSEC, which is why my changes from 'default' to the ISP's DNS server, and then to Google's DNS server (8.8.8.8), continued to cause the same error message.
Sonic offers opt-out DNS service (unfiltered) if that's what you want: DNS_Opt-Out
In summary - DNSSEC causes Vigilink's man-in-the-middle link through emjcd .com to terminate at an error page instead of passing through to the intended destination.
As for my PC - I learned CC can modify more than I intended (fonts disappeared!). After I ran the System Restore image from January 31 everything came back to normal. I ran Windows Update, and now I'll run Ninite, to catch anything that needs update subsequent to 1/31.
Issue resolved! Thanks everyone for your good advice over in the other thread. :drink:
This nuisance Redirect is a moneymaking feature added to TBN and also subscribed to by Harbor Freight. Whenever someone here clicks on a link to Harbor Freight, the click generates a payment to TBN because the link goes via a 'man-in-the-middle' and then onward to HF.
As I posted in my initial thread, here's how your click on a HF trailer-jack link gets to HF: [spaces added so this won't actually link]
http: // api.viglink.com/api/click?format=go&jsonp=vglnk_14235203345829&key=a6c 73c8a58f6c5d5816e8336c8228973&libId=095eaefa-38af-47eb-b976-aed3cc6b6387&loc=http%3A%2F%2Fwww.tractorbynet.com %2Fforums%2Fparts-repairs%2F114176-harbor-freight-tools-dont-suck-216.html%23post4035679&v=1&out=http%3A%2F%2Fwww.ha rborfreight.com%2F1500-lb-capacity-dual-wheel-swing-back-boat-trailer-jack-67500.html&ref=http%3A%2F%2Fwww.tractorbynet.com%2 Fforums%2Fsubscription.php%3Fdo%3Dviewsubscription &title=Harbor%20Freight%20Tools%20that%20don%27t%2 0suck%20-%20Page%20216&txt=1500%20Lb.%20Capacity%20Dual%20W heel%20Swing-Back%20Boat%20Trailer%20Jack
Vigilink's claim on their home page:
VigLink is the platform on which site-to-site clicks are priced, bought, and sold.
Publishers: Get paid for the sales you drive.
Advertisers: Gain customers through relevant content.
Turns out my ISP doesn't like one of the sites that this Vigilink redirects traffic to:
http://www.emjcd.com/1d111nmvuE/mty...74A9-kdueru-iuhljkw-wrrov-grqw-vxfn-549.kwpo<
If you don't want to click on that, (not recommended!) it looks approximately like this screen print below except emjcd.com is the site reported blocked.
Again, quoting from my prior thread:
It looks like VigLink is redirecting to emjcd .com , 'Commission Junction' - a site that offers you 'valuable coupons' to download.
Herdprotect Anti-malware (whoever that is) declares that emjcd downloads malware.
This might explain why my ISP blocks the (redirected) link that should have gone directly from TBN to HF.
I found a lengthy thread on this at Sonic.net, my ISP. "It's a trap! Reported phishing or malware site" : who?
To summarize that thread, Sonic subscribers complained that Washington Post was blocked at one point. Another poster said he lost out on a killing in Bitcoins when an Exchange site disappeared during a short period of abnormal prices. He proposed that this was deliberate manipulation of DNSSEC to someone's financial advantage.
The owner of the ISP referred to this description of DNSSEC which they use:
What is DNSSEC?
DNSSEC is an enhanced level of Internet security that enables validation of DNS traffic to ensure that it has not been tampered with. This prevents hackers from injecting false information (aka DNS cache 'poisoning'), in an attempt to re-direct people trying to access a real website to a fake, phishing or criminal site.
And that internal Wiki says Google's public servers also use DNSSEC, which is why my changes from 'default' to the ISP's DNS server, and then to Google's DNS server (8.8.8.8), continued to cause the same error message.
Sonic offers opt-out DNS service (unfiltered) if that's what you want: DNS_Opt-Out
In summary - DNSSEC causes Vigilink's man-in-the-middle link through emjcd .com to terminate at an error page instead of passing through to the intended destination.
As for my PC - I learned CC can modify more than I intended (fonts disappeared!). After I ran the System Restore image from January 31 everything came back to normal. I ran Windows Update, and now I'll run Ninite, to catch anything that needs update subsequent to 1/31.
Issue resolved! Thanks everyone for your good advice over in the other thread. :drink: