Author Topic: website is being blocked by avast users  (Read 5583 times)

0 Members and 1 Guest are viewing this topic.

vitordt

  • Guest
website is being blocked by avast users
« on: October 02, 2012, 10:02:00 PM »
Hello guys,

I administer a website (xww.idealegc.com.br) and it has been blocked for only avast users.

When they are trying to access the website, the following message is displayed: URL:mal Blocked...

Could you please help me with it?

Thanks
« Last Edit: October 03, 2012, 09:44:43 AM by Milos »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: website is being blocked by avast users
« Reply #1 on: October 02, 2012, 10:11:11 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: website is being blocked by avast users
« Reply #2 on: October 02, 2012, 10:37:23 PM »
Hi vitordt,

Break that live link to your site like with wXw, please. Wordpress version from source: 3.4.2 is outdated and needs updating...
Site infected through WP hack...ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP suspicious -> htxp://www.idealegc.com.br/xmlrpc.php?rsd
This "xmlrpc.php?rsd"was hacked through a hidden txt in the code, you have to clean up the WordPress header...

polonus

P.S. The link to hxtp://www.adorodesign.com.br/ is going to a site also with outdatred WP version...Wordpress internal path: /home/adorodesign/www/wp-content/themes/imbalance/index.php
WordPress version outdated: Upgrade required!

D
« Last Edit: October 02, 2012, 11:03:03 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

vitordt

  • Guest
Re: website is being blocked by avast users
« Reply #3 on: October 03, 2012, 03:04:32 AM »
Hi vitordt,

Break that live link to your site like with wXw, please. Wordpress version from source: 3.4.2 is outdated and needs updating...
Site infected through WP hack...ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP suspicious -> htxp://www.idealegc.com.br/xmlrpc.php?rsd
This "xmlrpc.php?rsd"was hacked through a hidden txt in the code, you have to clean up the WordPress header...

polonus

P.S. The link to hxtp://www.adorodesign.com.br/ is going to a site also with outdatred WP version...Wordpress internal path: /home/adorodesign/www/wp-content/themes/imbalance/index.php
WordPress version outdated: Upgrade required!

D

Hi Polonus,
Thanks for your feedback.

Isn't it better for me to clear all files in the ftp and re-install wordpress from scratch?

Regards,
Vítor

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: website is being blocked by avast users
« Reply #4 on: October 03, 2012, 09:46:36 AM »
Hi vitordt,

Yep, that should be better, do not forget to update and change log-in password also see: http://weblogtoolscollection.com/archives/2008/04/26/reset-wp-password-manually/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

vitordt

  • Guest
Re: website is being blocked by avast users
« Reply #5 on: October 03, 2012, 12:21:57 PM »
Hi vitordt,

Yep, that should be better, do not forget to update and change log-in password also see: http://weblogtoolscollection.com/archives/2008/04/26/reset-wp-password-manually/

polonus

Polonus,

Again, thanks for the feedback !

It came up another 2 questions though. If I am going to start from scratch:
1) it means I will have to erase the mysql database as well, haven't I?
2) can I export current posts and pages, delete all files in ftp and do I a clean install of wordpress and import posts and pages again? Or this posts and pages also contains links suspicious etc?

:)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: website is being blocked by avast users
« Reply #6 on: October 03, 2012, 09:18:50 PM »
Hi vitordt,

You can reset the the mysql database, restore root privileges...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

vitordt

  • Guest
Re: website is being blocked by avast users
« Reply #7 on: October 04, 2012, 12:20:26 AM »
Hi vitordt,

You can reset the the mysql database, restore root privileges...

polonus

Hi Polonus, thanks :)

I have deleted ALL files in FTP, also deleted entire database (mysql) and ran the test.  At this point, there is nothing on the ftp, but it is still showing as suspicious.

Please see: http://zulu.zscaler.com/submission/show/0c20fbc30e48fe1562af8952025f297d-1349302706

Any thoughts?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: website is being blocked by avast users
« Reply #8 on: October 04, 2012, 12:40:04 AM »
Hi vitordt,

There can be links to sub-domains that are still considered as suspicious. The link to:  hxtp://www.adorodesign.com.br/ could also make the main site is considered suspicious stil, but I cannot trace that anymore.. Avast Network shield still flags. I see nothing there in the code. Report a FP to avast.
On http://www.kinghost.com.br site there is content after the html tag wgich is suspicious: 574: < !-- 1349303673 -->
The following link  there is also suspicious, with a bad WOT rep: htxp://s.clicktale.net/WRd.js'%20type='text/javascript'%3E%3C/%20sc%E2%80%8Bript%20%3E
tracking code
See: http://www.mywot.com/en/scorecard/s.clicktale.net?utm_source=addon&utm_content=warn-viewsc
Contains: Hijackers, Unwanted Adware/Spyware programs and s listed in OpenDNS's Block Tool,

polonus
« Last Edit: October 04, 2012, 12:45:05 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

vitordt

  • Guest
Re: website is being blocked by avast users
« Reply #9 on: October 04, 2012, 02:45:32 AM »
Hi vitordt,

There can be links to sub-domains that are still considered as suspicious. The link to:  hxtp://www.adorodesign.com.br/ could also make the main site is considered suspicious stil, but I cannot trace that anymore.. Avast Network shield still flags. I see nothing there in the code. Report a FP to avast.
On http://www.kinghost.com.br site there is content after the html tag wgich is suspicious: 574: < !-- 1349303673 -->
The following link  there is also suspicious, with a bad WOT rep: htxp://s.clicktale.net/WRd.js'%20type='text/javascript'%3E%3C/%20sc%E2%80%8Bript%20%3E
tracking code
See: http://www.mywot.com/en/scorecard/s.clicktale.net?utm_source=addon&utm_content=warn-viewsc
Contains: Hijackers, Unwanted Adware/Spyware programs and s listed in OpenDNS's Block Tool,

polonus

Hi Polonus,
What is "report FP to avast"?
How long does it take to clean via avast network shields?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: website is being blocked by avast users
« Reply #10 on: October 04, 2012, 07:57:44 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0