Author Topic: suspicious warnings  (Read 7219 times)

0 Members and 1 Guest are viewing this topic.

glennk

  • Guest
suspicious warnings
« on: September 06, 2013, 09:16:16 PM »
Hi guys,

Users of my site have told me that AVAST virus scanner is highlighting a problem with my domain www.whitbyseaanglers.co.uk

The domain houses 2 installations of wordpress and 1 smf forum at

http://www.whitbyseaanglers.co.uk/

http://www.wcsa.whitbyseaanglers.co.uk/

http://www.whitbyseaanglers.co.uk/forum/index.php

The malware alert says infection url : mal

This shows for every page on each site across the domain.

Google webmaster tools, avg and norton do not show any issue. Ive run the site through several security scanners and they say its clean.

Obviously Im concerned, but Im wondering if this may be an avast false positive ? I want to investigate as I dont want to ignore it an the problem get worse and I get deliested by Google as that will be expensive to me.

Any advise greatly appreciated.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: suspicious warnings
« Reply #1 on: September 06, 2013, 09:42:17 PM »
if you think this is wrong....

You can upload and report FP to avast  here: http://www.avast.com/contact-form.php
you may add a link to this topic in case they reply here


glennk

  • Guest
Re: suspicious warnings
« Reply #2 on: September 06, 2013, 09:47:06 PM »
I have no proof either way really but am concerned. I was inquiring to see if anyone could offer any adice to swing me either way as I dont want to jump in and spend endless hours on the server and site if its a false positive, but conversely I dont want to be band by Google if I ignore the warning.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: suspicious warnings
« Reply #3 on: September 06, 2013, 09:52:01 PM »
URL:mal means it is on a block list ..... for whatever reason

VirusTotal url scan and urlvoid.com say not listed....




glennk

  • Guest
Re: suspicious warnings
« Reply #4 on: September 06, 2013, 09:57:47 PM »
sorry for sounding thick. But what does that mean ?


glennk

  • Guest
Re: suspicious warnings
« Reply #6 on: September 06, 2013, 10:36:01 PM »
sorry, does that mean Avast may have it wrong ??

glennk

  • Guest
Re: suspicious warnings
« Reply #7 on: September 09, 2013, 01:59:36 AM »
So what happens when you submit a false posive report ? I submitted a few days back now and it still appears Im blacklisted. No other anti virus or search engine inclusiding google is blocking my site. Avast is makeing me loose customers and income.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: suspicious warnings
« Reply #8 on: September 09, 2013, 02:19:42 AM »
They will investigate it. But they are getting probaply millions of Websites and Files to check every day.
So this can take some time.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

glennk

  • Guest
Re: suspicious warnings
« Reply #9 on: September 12, 2013, 01:35:04 PM »
Ok guys, Here is the current state of play  :'(

Avast came back to me and said Quote - "It's detected due to this: whitbyseaanglers.co.uk /wp-includes/wp-mail.php%7c%3e%7bgzip%7d"

So I have checked my files on the server and wp-mail.php is not there. Below are 2 screen shots of what is there.

Could someone please advise on what to do next as I am loosing customers and much needed income.




Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: suspicious warnings
« Reply #10 on: September 12, 2013, 05:17:43 PM »
I notified polonus about this, he will check this for you.

He is an website analyst from the forum. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

glennk

  • Guest
Re: suspicious warnings
« Reply #11 on: September 12, 2013, 06:32:18 PM »
Thankyou so much for your help, Im sure you appreciate that times like this can be rather stressfull when your site income depends on all possible customers reaching your site.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: suspicious warnings
« Reply #12 on: September 12, 2013, 09:35:48 PM »
The avast alert was for hxtp://www.whitbyseaanglers.co.uk/wp-includes/wp-mail.php
Code hick-up
ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js?ver=3.6.1 benign
[nothing detected] (script) ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js?ver=3.6.1
     status: (referer=wXw.whitbyseaanglers.co.uk/wp-includes/wp-mail.php)saved 92629 bytes ae49e56999d82802727455f0ba83b63acd90a22b
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     suspicious:
Read how your site might have been infected: http://digwp.com/2009/06/xmlrpc-php-security/
Core code from WP is mostly secure and updated regularly against insecurities and vulnerabilities,
but there are many plug-ins and extemsions for WP that are less secure and may be vulnerable.
The xmlrpc-php-security issues should be taken up with your hoster as these are web server attacks.
See code
46:< link rel="EditURI" type="application/rsd+xml" title="RSD" href="htxp://www.whitbyseaanglers.co.uk/xmlrpc.php?rsd" />
47:< link rel="wlwmanifest" type="application/wlwmanifest+xml" href="htxp://www.whitbyseaanglers.co.uk/wp-includes/wlwmanifest.xml" />
There is also an issue with this backlink: https://www.eff.org/https-everywhere/atlas/domains/vimeocdn.com.html
see:
GET /p/flash/moogaloop/5.5.0b29/moogaloop.swf?clip_id=62537288 HTTP/1.1
Host: a.vimeocdn.com
HTTP/1.1 200 OK
Content-Type: application/x-shockwave-flash

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

glennk

  • Guest
Re: suspicious warnings
« Reply #13 on: September 12, 2013, 10:37:39 PM »
Sorry but I am not understanding what you are saying. Are you saying my site IS ? or Is Not ? affected ?

Surely the screen dumps above show that the file does not exist ??

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: suspicious warnings
« Reply #14 on: September 12, 2013, 11:09:29 PM »
Hi glennk,

If you cannot trace this: administrator/plugins/system/pc_includes/ajax_1 2.js%7C%3E%7Bgzip%7D|>{ gzip} then you are not affected by what avast flags,
else your site was maliciously hacked and infested with an image hack. If you are free of this you can file a FP report,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!