Virus from Chess.com

Sort:
Michel76

Dear Admin,

I receive pop-ups from F-secure claiming that malware is comming from ip: 67.201.34.169. If i enter this ip in IE it sends me to chess.com. It's Bagle.C on port 2745.

Is this a local problem?

billwall

The machine seems to be tal.chess.com that you are logging into via https.

It may be that your machine is arbitrarily selecting port 2745 as the outbound port, which is what port Bagle/Beagle used back in 2004.  Look for bbeagle.exe or d3dupdate.exe on your system or in the \run registry key. 

igor

from the screenshots provided what I see is that the connection was made from 192.168.1.10 port 2745(your workstation) to our server at 67.201.34.169 port 443. which means you went to check your email via our webmail interface via encrypted(https, port 443) connection.

I'm not sure why your AV thinks there is some kind of malware, I am 100% sure we don't have anything like that on our servers.

Maybe the signatures used by your AV to detect malware match valid traffic.

For example, my best guess about what happens is that your PC made a connection(outgoing port is assigned randomly) from a port which is used by a well-known malware and started receiving data from our server. your AV detected the traffic and thought there is a probe from our IP, which in reality is impossible as your IP address is unroutable and all the traffic from us to 192.168.1.10 would just get dropped at the next hop.

I would recommend checking your system for viruses and malware and if you don't find anything, disregard the warning. you still have a tiny chance of getting the warning in the future if that same port is randomly selected to make an outgoing connection to our(or other) servers on the Internet.