Author Topic: Avast marking web page as virus - why  (Read 12467 times)

0 Members and 4 Guests are viewing this topic.

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #30 on: August 20, 2015, 10:45:48 PM »

Where did you find this code?

Why is this in the code there
Code: [Select]
179 \t\t\t\t\t\t\t\t····var·ip·=·'91.201.55.91';································\r\n
\r\n
See: https://www.virustotal.com/nl/ip-address/91.201.55.91/information/

polonus

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marking web page as virus - why
« Reply #31 on: August 20, 2015, 10:50:33 PM »
Should be ok in the next update :-)

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: Avast marking web page as virus - why
« Reply #32 on: August 20, 2015, 10:55:53 PM »
Code is given in the Russian Low Level Site Explorer, just the code from that webpage, line 179
Code: [Select]
································function·trackSearch(env,·txt)·\r\n
································{\r\n
\t\t\t\t\t\t\t\t····var·ip·=·'91.201.55.91';································\r\n
\r\n
\t\t\t\t\t\t\t\t····$.ajax({\r\n
\t\t\t\t\t\t\t\t\t····url:·'GownsWS.asmx/SearchTracking',\r\n

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marking web page as virus - why
« Reply #33 on: August 21, 2015, 10:20:18 AM »
Btw several subdomains still point to malicious IPs, for example:

Name:    acknowledges.ellecouturegowns.net
Address:  85.143.216.53

and many more:
acknowledges.ellecouturegowns.net
automatic.ellecouturegowns.com
strongest.ellecouturegowns.com
democratic.ellecouturegowns.info
depreciation.ellecouturegowns.net
fight.ellecouturegowns.org
ingres.ellecouturegowns.net
jean.elledancestudio.com
recognized.ellecouturegowns.org
staff.ellecouturegowns.org
analysis.ellecouturegowns.net
plains.ellecouturegowns.org

If this does not stop immediately, the domains will be blocked again!

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #34 on: August 21, 2015, 11:35:33 AM »
We are not using ellecouturegowns.net domain at all for our webs, although we have it registered. We use only .com suffix.
85.143.216.53 was generic (*) godaddy DNS entry for any subdomain on ellecouturegowns class of domains (net,org,com...).
I have removed "*" DNS entries, please check now. It will take some time for DNS to get propagated.

Regards,
Drazen

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: Avast marking web page as virus - why
« Reply #35 on: August 21, 2015, 12:40:35 PM »
This has a Netcraft Risk Rating of 7 red out of 10: http://toolbar.netcraft.com/site_report?url=http://85.143.216.53
bulk registering.
You are out on left AS -> http://bgp.he.net/AS201848 -> as-block:       AS201216 - AS202239
This AS number doesn't appear to exist right now, and so we are unable to generate a report.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marking web page as virus - why
« Reply #36 on: August 21, 2015, 02:58:21 PM »
Thanks for the info, Drazen!

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #37 on: August 22, 2015, 09:38:49 PM »

HonzaZ, ellecouturegowns.com is still blocked, please check.

Regards,
Drazen

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marking web page as virus - why
« Reply #38 on: August 22, 2015, 10:42:48 PM »
I can access the website without any warning - can you post the printscreen? What does the warning say?

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #39 on: August 22, 2015, 10:55:05 PM »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast marking web page as virus - why
« Reply #40 on: August 22, 2015, 10:56:42 PM »
No problems with IE11 or Edge here

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: Avast marking web page as virus - why
« Reply #41 on: August 22, 2015, 11:04:05 PM »
Using Internet Explorer 11 and Firefox 40.02
tested in both load normally there is no problem.

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #42 on: August 23, 2015, 09:12:17 AM »
Same with freshly installed Firefox 40.02, virus definition version 150822-0
https://www.dropbox.com/s/uk6q5ha1p5anyv4/Screenshot%202015-08-23%2009.11.11.png?dl=0
HonzaZ, please check.

Regards,
Drazen

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marking web page as virus - why
« Reply #43 on: August 23, 2015, 09:20:30 AM »
I have no idea why it appears as malicious. The URL is definitely not blocked now. Perhaps it is still in the cache somewhere? Did you try restarting your PC?
Rest assured that your visitors do not see any warnings now, as Essexboy and Jefferson confirmed :-)

REDACTED

  • Guest
Re: Avast marking web page as virus - why
« Reply #44 on: August 23, 2015, 09:35:24 AM »
It should not be in any cache since this is fresh install of Firefox 40.02.
Restarting the PC helped :)

Regards,
Drazen