Author Topic: false positive malicious URL warning on photography site  (Read 3835 times)

0 Members and 1 Guest are viewing this topic.

manddd

  • Guest
false positive malicious URL warning on photography site
« on: September 09, 2011, 04:13:30 AM »
Hi, I believe Avast users are encountering false positive malicious URL warnings when going to my photography company's website.  Only users of Avast are hitting this issue.  I submitted a inquiry via the submission form but hoping there's something that I may do quickly. 

www . manddphotography . com

Thanks in advance for any advice

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: false positive malicious URL warning on photography site
« Reply #1 on: September 09, 2011, 09:50:09 AM »
welcome to the forum. look like a false threat acording to the virustotal report here.

http://www.virustotal.com/url-scan/report.html?id=9ff3156ba6a1ff3767ccf9323a1b1e96-1315540934 only bitdefender seems to react on it.

check this site to report your site as a false url detection

http://www.avast.com/contact-form.php?loadStyles

good luck
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89701
  • No support PMs thanks
Re: false positive malicious URL warning on photography site
« Reply #2 on: September 09, 2011, 02:24:33 PM »
I was trying to investigate and reply to this last night, but was having problems with the forum.

One of the sites I use to check these things reports your wordpress is out of date and currently there are a huge amount of sites having problems with vulnerabilities in out of date wordpress versions. One related to themes, timthumb I believe.

Since there have been a number of alerts by the web shield (image1), this has effectively passed on the the network shield which is blocking the site right now.

I believe the problem is your jquery.js script (image2) may be infected/hacked.

manddphotography.com/wp-includes/js/jquery/jquery.js

There was a similar post about this jquery.js file (try a forum search for the file name) and they replaced the jquery.js file and that resolved the problem, but id doesn't resolve the reason why, so you need to keep wordpress up to date.

####
There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Press (Media), issues.

- If you are reporting an FP, then you get another input field open (image3), click Browse button and navigate to the file or enter the web URL for the site you wish to submit for review (network shield and web shield), etc.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

manddd

  • Guest
Re: false positive malicious URL warning on photography site
« Reply #4 on: September 09, 2011, 10:50:08 PM »
thank you all for your feedback and advice.  I have verified the site is running WordPress 3.2.1 and I continue to have potential clients tell me they are unable to access.

I've submitted a second inquiry to Avast through the link provided.  Is there typically a good turnaround of such requests/investigations if legitimate?
 
Thanks again, very much appreciated

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89701
  • No support PMs thanks
Re: false positive malicious URL warning on photography site
« Reply #5 on: September 09, 2011, 10:52:14 PM »
The turn around time is usually quite fast, if confirmed a false detection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89701
  • No support PMs thanks
Re: false positive malicious URL warning on photography site
« Reply #7 on: September 12, 2011, 02:00:59 PM »
Since GData uses avast as one of its two engines and the signature is the same, effectively it is only avast that is alerting.

However, signature detections in the index page may not be all of the story, if the jquery.js file in the script tag that is the problem, which is why it needs to be investigated by avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: false positive malicious URL warning on photography site
« Reply #8 on: September 12, 2011, 02:17:39 PM »
Hi DavidR,

Is this the code that should be checked according to you?
See attached gif

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89701
  • No support PMs thanks
Re: false positive malicious URL warning on photography site
« Reply #9 on: September 12, 2011, 02:44:34 PM »
No it is in my image2 above the script tag pointing to the jquery.js file, which has appeared a lot recently, in relation to this wordpress hacking issue.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security