Avast WEBforum

Other => Viruses and worms => Topic started by: normski23 on April 12, 2014, 11:39:32 PM

Title: qedlaw.co.uk false positive
Post by: normski23 on April 12, 2014, 11:39:32 PM
Visitors to my website who use avast are warned about malware but the site is clean according to all other forms of virus detection software. What can I do to get a clean bill of health?
Title: Re: qedlaw.co.uk false positive
Post by: Secondmineboy on April 12, 2014, 11:45:17 PM
Can you tell us the URL please?
Title: Re: qedlaw.co.uk false positive
Post by: Eddy on April 12, 2014, 11:50:26 PM
http://zulu.zscaler.com/submission/show/f79dbafdf25538f8953e24ee09f3f9b5-1397339467 (http://zulu.zscaler.com/submission/show/f79dbafdf25538f8953e24ee09f3f9b5-1397339467)
It means  the IP is blacklisted.
If you are sure there is no malware/malicious code on the website you can ask avast to allow it through the contact form on the website.
Title: Re: qedlaw.co.uk false positive
Post by: Asyn on April 12, 2014, 11:52:45 PM
Guys, it's in the topic title. ;)
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 12, 2014, 11:54:59 PM
Many thanks for your replies.

www dot qedlaw dot co dot uk
Title: Re: qedlaw.co.uk false positive
Post by: Secondmineboy on April 12, 2014, 11:58:00 PM
Website looks clean from various testing sites.

Im getting 3 alerts from Avast.

You can report it as false positive here: http://www.avast.com/contact-form.php
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 12:04:07 AM
I reported it a month ago and nothing has been done. Is there a postal address for avast in the UK?
Title: Re: qedlaw.co.uk false positive
Post by: Eddy on April 13, 2014, 12:06:26 AM
Did you use the contact form to report it ?
Title: Re: qedlaw.co.uk false positive
Post by: Secondmineboy on April 13, 2014, 12:06:49 AM
There is no postal adress for Avast in the UK, only for Distributors, but you need to tell it to
Avast directly.

You can wait for polonus for a deeper analysis of the website if you want.
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 12:09:03 AM
Yes. I did use the online form. Other than the form is there a way of contacting avast about this?

Who is polonus?
Title: Re: qedlaw.co.uk false positive
Post by: Secondmineboy on April 13, 2014, 12:10:14 AM
You could mail them directly at the Viruslab: virus@avast.com
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 12:20:05 AM
I reported it again today and now when I click on the link to see the ticket it tells me "oops! please login to continue" but I don't have a login!

Where is the contact form I should use to report the problem?

Many thanks again.
Title: Re: qedlaw.co.uk false positive
Post by: polonus on April 13, 2014, 12:30:24 AM
IP was reported for phishing: http://support.clean-mx.de/clean-mx/phishing.php?id=3181924
Only flag is an external link to statcounter dot com, that is blocked by an extension for me, but not malicious an sich.

I think it is a general IP block and you should ask for an exclusion for your domain.

All this because of the following IP malware history: https://www.virustotal.com/nl/ip-address/95.128.128.74/information/

Threat from IP was for Alien Vault - threat danger level 4, 1 connection, last seen 3 months ago, according to ThreatSTOP.

Report here: www.avast.com/nl-nl/contact-form.php‎

polonus
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 12:44:05 AM
Thank you Polonus. The link you gave me takes me to a Dutch form. Will it be ok if I submit in English?

Title: Re: qedlaw.co.uk false positive
Post by: DavidR on April 13, 2014, 12:53:20 AM
Thank you Polonus. The link you gave me takes me to a Dutch form. Will it be ok if I submit in English?

Use this form, http://www.avast.com/contact-form.php?loadStyles (http://www.avast.com/contact-form.php?loadStyles), it detects your language and comes up with the correct form.
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 01:31:05 AM
Thank you to everyone for your prompt and helpful responses. I am very grateful for your assistance.
Title: Re: qedlaw.co.uk false positive
Post by: polonus on April 13, 2014, 01:38:45 AM
Hi nomski23,

You are welcome and we hope that your issue will be settled asap,

polonus
Title: Re: qedlaw.co.uk false positive
Post by: normski23 on April 13, 2014, 08:37:47 AM
Hi Polonus,

How long does it normally take to resolve such issues? And will they contact me or just fix it?

Normski23
Title: Re: qedlaw.co.uk false positive
Post by: Milos on April 13, 2014, 02:37:22 PM
Hello,
there was "qedlaw.co.uk/677c4c3f7815aad0/q.php" (BlackHole exploit), can you confirm that you have cleaned it? I suggest to change all passwords and update all systems.

Milos
Title: Re: qedlaw.co.uk false positive
Post by: polonus on April 13, 2014, 02:40:57 PM
@nomski23,

You see how soon they are here to "keep your pulse" now  ;)

@Milos,

Thanks, see: http://urlquery.net/report.php?id=1397393367082  (see time-stamp, so still there)

polonus