This site is infected

Sort:
Gedgey

I've just had a response from Chess who have told me this:

 

We’d received reports that this might be happening, and we need just a few more URLS. Our guess at the moment is that the ad group we’re using is cycling in some ads that we do NOT approve of. However, the two reports we had so far turned out to be malware on the reporter’s end (malware can use empty ad space to put up an ad, and be based on the users computer, not the internet).

If you could send me a screenshot of such an ad, I can make sure we either get that removed.

There seems to be some sense in what Chess.com say as Im a BT customer and the adds often refer to and are branded to BT thats what nearly got me however I only ever get the adds when im on the chess site normally after ive been on here some time.  The page doesnt appear as a pop up it actually knocks out the chess game im in and replace the url with scam site. There is no cross to come only an accept option - you have to close the page entirely and log back into chess to continue.  I will send them images and links as soon as it appears again.  Ill post here too so you can be vigilant too.

Gedgey

Ok just checked my history and have found some of the pages which i will submit to Chess.

Please be aware of the problems these link might cause of you click them.

Below is a screenshot.  The responses they show are bogus.

The URL also changes as you will see from time to time I think they have done this by hijacking some server space somewhere as not to be traced.

 

http://wayretail.com/?57f611a52fec3998ccc6a901d98e7dc7

phpONSajL.png

Gedgey

Heres the small print

phptOaFiX.png

 

The_Chin_Of_Quinn
Gedgey wrote:

Ok just checked my history and have found some of the pages which i will submit to Chess.

Please be aware of the problems these link might cause of you click them.

Below is a screenshot.  The responses they show are bogus.

The URL also changes as you will see from time to time I think they have done this by hijacking some server space somewhere as not to be traced.

 

http://wayretail.com/?57f611a52fec3998ccc6a901d98e7dc7

 

Clicked it and no website loads. I only got this:

 

phpFMO72e.png

 

 

Gedgey

Same add different link..

 

http://bandretail.com/?1e5437d5d4715ac510873121a827430d

 

Gedgey

Thanks Chin I clicked it from this page and got the same page up   mmmmmmmmm...

Gedgey

Yep its now giving me the same error....

Gedgey

Looks like they expire somehow...

Gedgey

 

http://wayretail.com/?4bb1fd1ea5ceded5ebf4a8286eae0ffb

 

Ok just found another in history try this one and just to prove the page comes from the link heres the image with URL

 

phpVRVaml.png

 

CookedQueen
Barneyandfriendz spams:
<<< Spam removed >>>

Are you spamming every thread with this now?

EscherehcsE

Yeah, the suspect links were flagged as malicious by Google Safe Browsing, so they're definitely up to no good. So, Chess.com thinks it may be part of a malvertising scheme; Just a confirmation that using an ad blocker might be a good idea. Laughing

Indirect

Where are the mods? He needs to be muted.

Gedgey

Thank you buddy your help is appreciated.  Have a good weekend.

 

D

Gedgey

Oh Dear they still dont get it the site is still infected and is invoking scam phishing pages

 

CookedQueen

Can you name some links? Recently lots of sites were connected when I'm on chess.com. Fortunately my security software detects and blocks this. So can you tell some link names?

Cherub_Enjel

This is no surprise. I started a thread about this weeks ago, with Indian spammers in the forums. Just don't click on any strange links.

Gedgey

http://aldie.fezox.xyz/?sov=93073471&hid=ewisisommukieew&&redid=38265&gsid=68&campaign_id=20&id=XNSX.deu-r38265-t68&impid=09fef72a-0dbc-11e7-9781-fa245441bcee

 

Gedgey

Thats the most recent one however there are more above they appear as survey scams but you are really signing up to agree to pay money for rubbish you dont want and you agree to pay for it in the small print..  I have emailed all this to the site admins but they keep coming back with canned responses - nobody is really doing anything about it.  I guess one of their sites that advertise has some code in it, which when it appears diverts your link to its page.  Im using google chrome which i guess has some weakness in it.

The_Chin_Of_Quinn

That link doesn't work for me, says website can't be found.

shcherbak

its adware, you do need to thoroughly scan your system. Or better yet, do back up of data only and nuke the rest. 

It might be newer version of stuff described in this link https://malwaretips.com/blogs/remove-survey-2015-virus/