Author Topic: Still blocked by Avast (only) yet site is testing clean  (Read 6864 times)

0 Members and 1 Guest are viewing this topic.

Elle1971

  • Guest
Still blocked by Avast (only) yet site is testing clean
« on: September 13, 2013, 05:36:53 PM »
Ok... second time of typing as my "captcha" didn't match.

My website has been blocked by a large number of Avast users for over a week. I have been right through the files via FTP. I have also run it through online scanners, both of which (Sucuri and webinspector) agree that it is clean.

No other virus/malware checkers seem to be flagging anything.

I have messages Avast twice now via http://www.avast.com/contact-form.php?loadStyles  but have received no reply, or any form of acknowledgement.

I am now spending a considerable amount of time defending my hardearned business reputation across various social networks against trolls who have nothing better to do than slate people and things they know nothing about.

My website is spainbuddy dot com

Can someone please please PLEASE help!

One desperate lady

Elle x

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #1 on: September 13, 2013, 05:56:41 PM »
Sucuri: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fspainbuddy.com Clean
URLQuery: http://urlquery.net/report.php?id=5234176
Quettra: http://www.quttera.com/detailed_report/spainbuddy.com Clean
Zulu:http://zulu.zscaler.com/submission/show/98e5401479006605cdc45b41e64c51bd-1379087638 Benign
Virustotal scan is clean.

I will notify polonus about this. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Elle1971

  • Guest
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #2 on: September 13, 2013, 06:00:19 PM »
Steven - thank you for giving me the first positive response I've had in a while.

Very much appreciated.

Elle xx

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #3 on: September 13, 2013, 06:00:38 PM »
polonus is notified, he will look over the site and the scansi run, and will run scans himself maybe.

But he is offline now, so please wait some time.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6699
  • Trust only what you test yourself!
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #4 on: September 13, 2013, 06:02:46 PM »
When I scanned using Quttera I found nine suspicious files. http://quttera.com/detailed_report/www.spainbuddy.com  ???
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #5 on: September 13, 2013, 06:05:46 PM »
My search is for htxp://spainbuddy.com, yours is for htxp://www.spainbuddy.com

I think that is the point. ;D
« Last Edit: September 13, 2013, 06:42:38 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #6 on: September 13, 2013, 06:07:32 PM »
probably a IP Block....

if you looke here  http://urlquery.net/report.php?id=5234176  and scroll Down to Recent reports on same IP/ASN/Domain

you find this domains using same IP that have alerts on it, see here detected Detected RedKit exploit kit URL pattern     http://urlquery.net/report.php?id=5234545
Sucuri report  http://sitecheck.sucuri.net/results/www.dailycruisebargains.com/


Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #7 on: September 13, 2013, 06:10:33 PM »
And this is why it is being blocked i think...................

Thats like bad Advertisements which carry Scripts or something like that.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #8 on: September 13, 2013, 06:58:26 PM »
We have to check on these redirects from that site:
URLs that redirect found in: http://spainbuddy.com/

1: htxp://www.gandy-draper.com/openx/www/delivery/avw.php?zoneid=24&cb=INSERT_RANDOM_NUMBER_HERE&n=ab826f56 -> htxp://www.gandy-draper.com/openx/www/images/46c3fd36def631da4ac2480821857606.jpg
2: htxp://www.booking.com/?aid=357636&tmpl=searchbox&width=685&calendar=1& -> htxp://www.booking.com/
and this in line 07:shr.src = 'htxps://dsms0mj1bbhn4.cloudfront.net/assets/pub/shareaholic.js?ver=7.0.3.6';
flagged as potentially suspicious by Quttera's  -> htxps://shareaholic.com")}.call(this),/*! as
dsms0mj1bbhn4.cloudfront.net/assets/pub/shareaholic.js?ver=7.0.3.6
Severity:    Potentially Suspicious
Reason:    Detected procedure that is commonly used in suspicious activity.
Details:   Too low entropy detected in string [['=%26=%26=%260=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=']] of length 344 which may point to obfuscation or shellcode.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Elle1971

  • Guest
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #11 on: September 13, 2013, 07:25:28 PM »
Thanks Pondus - IP Blocking I can get around - I can pay my hosts for a dedicated IP on that server. I shall look into that in the morning. Alternatively, if I flag that site up to the hosts... they may be able to do something at their end to it.

Thanks for the feedback Polonus.

I don't understand how the ads are bad in openx? Gandy-Draper is our own company by the way... and that's where the openx is hosted. .com is the website and .net is the hosting account. We've been using it for organising our advertising for a few years now, and never with any issues until recently.

  • The first one is a banner that invites people to advertise on the same website

  • The second one - Booking.com is well... booking.com - a vacation booking website. Well established respected etc etc etc

  • The line 7 is a Shareaholic plugin... which although have been causing issues for many of us this week... are standard sharing tools on 100,000s of websites. Mind you after this week, they can go jump of a tall building. Their plugin has stopped working in Firefox. I'm looking for a decent alternative as we speak.

So... if I delete those 3 items from my site - will that mean it is clean for Avast purposes? Even though it's testing clean anyway? Or does Avast simply dislike the way that openx redirects links?

Oh God I'm so confused... and so frustrated and upset after all the hassles. I do appreciate the help and time you are putting into this - so thank you all so much... Pondus, Polonus and Steven.

Elle x


Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #13 on: September 13, 2013, 07:40:01 PM »
So actually Booking.com is safe.

These alerts should be gone when these things will be removed, but please wait for polonus reply. ;)

These banners could have a bad advertiser or the websites that they are linking to could be hacked or infected.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Still blocked by Avast (only) yet site is testing clean
« Reply #14 on: September 13, 2013, 07:55:57 PM »
Polonus is not online now.

You can check back later if you want.

Just save the Thread to your favorites in your browser.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10