Author Topic: Avast blocking my sites  (Read 7327 times)

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #30 on: March 21, 2012, 02:29:22 PM »
Suspicious code found here: wXw.idestino dot pt/js/1_7.js suspicious
[suspicious:2] (ipaddr:195.22.10.105) (script) wXw.idestino dot pt/js/1_7.js
     status: (referer=wXw.idestino.pt/)saved 165710 bytes d28cf8f0d2ea06ee74354e9add2b368c4f12adfb
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [iframe] -31.184.242.81/link.php  this is being blocked by avast Network shield as URL:Mal
     info: [decodingLevel=0] found JavaScript
     suspicious:

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline quimkaos

  • Newbie
  • *
  • Posts: 7
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #31 on: March 21, 2012, 02:47:49 PM »
i just deleted all files and re-upload the originals, can i get a rescan, so i can report the problem to the ISP...

Offline Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17088
  • Gender: Male
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #32 on: March 21, 2012, 02:51:34 PM »
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline quimkaos

  • Newbie
  • *
  • Posts: 7
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #33 on: March 21, 2012, 02:59:40 PM »
thank you!

Offline DavidR

  • avast! Überevangelist
  • Certainly Bot
  • *****
  • Posts: 66263
  • Gender: Male
  • No support PMs thanks
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #34 on: March 21, 2012, 03:00:38 PM »
i just deleted all files and re-upload the originals, can i get a rescan, so i can report the problem to the ISP...

Avast isn't alerting, so it looks like it was the Web Shield (real time scanning) that detected it, so the clean-up would have an immediate effect.

So you need to investigate how these are getting reinfected as there appears to be a vulnerability, commonly out of date content management software, Joomla, PHP, WordPress, etc.
« Last Edit: March 21, 2012, 03:06:01 PM by DavidR »
Core2Duo E8300/ 4GB Ram/ WinXP ProSP3/ avast! free 8.0.1489/ Outpost Firewall Pro8.0/ Firefox 21.0, NoScript, RequestPolicy/ MailWasher Pro/ DropMyRights/ MalwareBytes AntiMalware Pro 1.75/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security

Offline quimkaos

  • Newbie
  • *
  • Posts: 7
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #35 on: March 21, 2012, 03:11:51 PM »
in this case i'm not using any CMS, only php(in safe mode), html, css and Javascript (with prototype). So i'm point more to a server problem. it's a shared host service.

i just changed the file permission to 444 (read only)

or a bug in prototype... thou i need to use an slightly outdated version, so fixing it would be a problem...
« Last Edit: March 21, 2012, 03:33:33 PM by quimkaos »

Offline DavidR

  • avast! Überevangelist
  • Certainly Bot
  • *****
  • Posts: 66263
  • Gender: Male
  • No support PMs thanks
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #36 on: March 21, 2012, 03:28:27 PM »
The Host software also has to have the latest versions, etc. of you are likely to revisit this problem a lot.
Core2Duo E8300/ 4GB Ram/ WinXP ProSP3/ avast! free 8.0.1489/ Outpost Firewall Pro8.0/ Firefox 21.0, NoScript, RequestPolicy/ MailWasher Pro/ DropMyRights/ MalwareBytes AntiMalware Pro 1.75/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16936
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Avast blocking my sites
« Reply #37 on: March 21, 2012, 03:29:50 PM »
Hi quimkaos,

After you did what DavidR suugests, you can additionally scan your website code here: http://evuln.com/tools/php-security/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!