Author Topic: Avast have blacklisted our website which is now clean  (Read 11213 times)

0 Members and 1 Guest are viewing this topic.

Sarah Rushton

  • Guest
Avast have blacklisted our website which is now clean
« on: May 16, 2013, 02:34:48 PM »
Our website is www.hobbytronics.co.uk.
We discovered a malware apache intrusion yesterday that has now been resolved. The website 'Yandex' had blacklisted us but have resubmitted our site and it now reports our site as 'Clean'.
Can the blacklist be removed as this is having a serious effect to our visitors.
Thank you  :'(

Offline JuninhoSlo

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 849
Re: Avast have blacklisted our website which is now clean
« Reply #1 on: May 16, 2013, 03:15:58 PM »
Check your website with:

-virustotal.com
-securi.net
-unmaskparasites.com

Contact Avast team:
http://www.avast.com/contact-form.php

Thank you.

Bye :)

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48598
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast have blacklisted our website which is now clean
« Reply #2 on: May 16, 2013, 03:16:04 PM »

Our website is www.hobbytronics.co.uk.
We discovered a malware apache intrusion yesterday that has now been resolved. The website 'Yandex' had blacklisted us but have resubmitted our site and it now reports our site as 'Clean'.
Can the blacklist be removed as this is having a serious effect to our visitors.
Thank you  :'(
The following should help you accomplish that task:
http://forum.avast.com/index.php?topic=7779.msg62586#msg62586
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Sarah Rushton

  • Guest
Re: Avast have blacklisted our website which is now clean
« Reply #3 on: May 16, 2013, 05:33:57 PM »
Thanks for the link but this deals with infected files on websites. As I said, I think we have cleared the infection and are getting clean reports from a multitude of checker. Just want avast to update the status.
Thanks

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: Avast have blacklisted our website which is now clean
« Reply #4 on: May 16, 2013, 07:31:43 PM »
Site apparently clean: Checking:http://www.hobbytronics.co.uk/catalog/view/javascript/jquery/tab.js
File size:545 bytes
File MD5:28e93d3989dde04a06c719374adba692

htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/tab.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.easing-1.3.js
File size:5565 bytes
File MD5:747222608476f823d43ef81b5eaaadc0

htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.easing-1.3.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.easing-1.3.js/JSFile_1[0][15bd] - Ok
htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.easing-1.3.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/common.js
File size:698 bytes
File MD5:48c56f290f23ad3efa164caabd07218d

htxp://www.hobbytronics.co.uk/catalog/view/javascript/common.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/common.js/JSFile_1[0][2ba] - Ok
htxp://www.hobbytronics.co.uk/catalog/view/javascript/common.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/header.js
File size:1822 bytes
File MD5:77b01cf556a95196a73a9fbfdc965043

htxp://www.hobbytronics.co.uk/catalog/view/javascript/header.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/header.js/JSFile_1[0][71e] - Ok
htxp://www.hobbytronics.co.uk/catalog/view/javascript/header.js - Ok

Checking:hxtp://www.hobbytronics.co.uk/catalog/view/javascript/bookmark.js
File size:411 bytes
File MD5:f251a2c324e26263a4aab9ed643ae244

htxp://www.hobbytronics.co.uk/catalog/view/javascript/bookmark.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/bookmark.js/JSFile_1[0][19b] - Ok
htxp://www.hobbytronics.co.uk/catalog/view/javascript/bookmark.js - Ok

Checking:hxtp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/ajax_add.js
File size:1016 bytes
File MD5:da5d817e57229f29682451b1cb5aaa08

htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/ajax_add.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/ajax_add.js/JSFile_1[0][3f8] - Ok
hxtp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/ajax_add.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.fancybox-1.3.4.js
File size:26.72 KB
File MD5:a82904ccd5244d58c35f247a2c2d2975

htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.fancybox-1.3.4.js - archive JS-HTML
htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/fancybox/jquery.fancybox-1.3.4.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/jquery-1.3.2.js
File size:117.68 KB
File MD5:a450a51b5ee72fc00a371183477c41be

htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/jquery-1.3.2.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/jquery-1.3.2.js/JSTag_1[60d1][175e4] - Ok
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/jquery-1.3.2.js/JSTag_2[15a1b][7c9a] - Ok
htxp://www.hobbytronics.co.uk/catalog/view/javascript/jquery/jquery-1.3.2.js - Ok

Checking:htxp://www.hobbytronics.co.uk/catalog/view/javascript/fancybox.js
File size:665 bytes
File MD5:108c16b2434d838bf3f879b5eab6799f

htxp://www.hobbytronics.co.uk/catalog/view/javascript/fancybox.js - archive JS-HTML
>htxp://www.hobbytronics.co.uk/catalog/view/javascript/fancybox.js/JSFile_1[0][299] - Ok
hxtp://www.hobbytronics.co.uk/catalog/view/javascript/fancybox.js - Ok

Checking:htxp://www.hobbytronics.co.uk/
Engine version:7.0.4.9250
Total virus-finding records:4012529
File size:44.84 KB
File MD5:798a744243beb724fc7b161f17f7cdbd

htxp://www.hobbytronics.co.uk/ - archive JS-HTML
>htxp://www.hobbytronics.co.uk//JSTAG_1[58c][58] - Ok
>htxp://www.hobbytronics.co.uk//JSTAG_2[5d89][39e] - Ok
>htxp://www.hobbytronics.co.uk//JSTAG_3[ad36][1b7] - Ok
>htxp://www.hobbytronics.co.uk//JSTAG_4[b17d][1cb] - Ok
>htxp://www.hobbytronics.co.uk//JSTag_5[5d8e][399] - Ok
>hxtp://www.hobbytronics.co.uk//JSEvent_6[77] - Ok
>htxp://www.hobbytronics.co.uk//JSEvent_7[56] - Ok
>htxp://www.hobbytronics.co.uk//JSEvent_8[56] - Ok
>htxp://www.hobbytronics.co.uk//JSEvent_9[56] - Ok
htxp://www.hobbytronics.co.uk/ - Ok

Apparently site was attacked 7 months ago and just beyond 1 week ago.
These general PHP vulnerabilities should be checked: http://www.cvedetails.com/version/36749/PHP-PHP-5.1.6.html
with this as a likely candidate: http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-36749/year-2013/opbyp-1/PHP-PHP-5.1.6.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: Avast have blacklisted our website which is now clean
« Reply #5 on: May 16, 2013, 08:23:49 PM »
Thanks for the link but this deals with infected files on websites. As I said, I think we have cleared the infection and are getting clean reports from a multitude of checker. Just want avast to update the status.
Thanks

The first link given by JuninhoSlo is capable of dealing with false positives in regard to websites, you just need give more information in the report.

Use the on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.

- If you are reporting an FP, then you get another input field open, enter the web URL for the site you wish to submit for review (Network Shield), etc. A link to this topic also wouldn't hurt.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Sarah Rushton

  • Guest
Re: Avast have blacklisted our website which is now clean
« Reply #6 on: May 17, 2013, 11:07:53 AM »
Thanks for the file check showing the site is clean.

I used the contact form yesterday to report the false positive but haven't heard anything. I will retry but with a link to this arrticle.  Is there a way on the avast website to check a website link to see if they have it blacklisted currently? Don't know how long it takes to clear the block.

Thanks also for the links on how to stop further intrusions. Checking those out. I think it is worth mentioning we are now using md5deep to run a check on the files on our website every few hows and report any changes. Almost impossible to stop intrusions in practice but this should help us clean up an intrusion quickly.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: Avast have blacklisted our website which is now clean
« Reply #7 on: May 17, 2013, 01:46:06 PM »
The easiest way to check is to try to visit the site again and currently avast still alerts on it.

Usually avast are quick to correct something like this when/if confirmed to be an FP.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline SugarD-x

  • Full Member
  • ***
  • Posts: 190
  • Proud Avast! User
    • Clan Xperience
Re: Avast have blacklisted our website which is now clean
« Reply #8 on: May 17, 2013, 01:51:28 PM »
The easiest way to check is to try to visit the site again and currently avast still alerts on it.
Just checked it for you guys. It's still blacklisted.
~SugarD-x~

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: Avast have blacklisted our website which is now clean
« Reply #9 on: May 17, 2013, 02:05:43 PM »
You will see from the text that you quoted I already confirmed that ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline SugarD-x

  • Full Member
  • ***
  • Posts: 190
  • Proud Avast! User
    • Clan Xperience
Re: Avast have blacklisted our website which is now clean
« Reply #10 on: May 17, 2013, 02:18:41 PM »
You will see from the text that you quoted I already confirmed that ;D
Shh! :-[
~SugarD-x~

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: Avast have blacklisted our website which is now clean
« Reply #11 on: May 17, 2013, 02:51:33 PM »
Site found might have (had) hidden iFrame malware, blacklisted at: http://yandex.ru/infected?l10n=en&url=http://hobbytronics.co.uk/
and http://www.avgthreatlabs.com/sitereports/domain/hobbytronics.co.uk
Must be connected somewhere to activities of a malicious packer find from a link to "upfront.thefind.com"
http://www.threatexpert.com/report.aspx?md5=63e2dd0079ac63a3fe75eeb51451bb4b
see: http://forum.opencart.com/search.php?author_id=13286&sr=posts  compromise...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Avast have blacklisted our website which is now clean
« Reply #13 on: May 17, 2013, 04:02:43 PM »
Our website is www.hobbytronics.co.uk.
We discovered a malware apache intrusion yesterday that has now been resolved. The website 'Yandex' had blacklisted us but have resubmitted our site and it now reports our site as 'Clean'.
Can the blacklist be removed as this is having a serious effect to our visitors.
Thank you  :'(
Hello,
it will be unblocked.

Milos

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48598
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast have blacklisted our website which is now clean
« Reply #14 on: May 17, 2013, 04:40:06 PM »
http://www.hobbytronics.co.uk/
No longer blocked. :)   Thanks Milos
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet