Author Topic: Information on Flagged Site Removal  (Read 2068 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Information on Flagged Site Removal
« on: December 04, 2015, 06:03:27 PM »
Hi Everyone, hoping to get some info here.   

We have a rather large and popular website that is being flagged as containing malicious content on systems protected with Avast. The website has been cleaned and is not on any of the popular blacklists. My question is, does Avast use 3rd party blacklists, maintain it's own blacklists and/or use other scanning techniques.

Basically we were unable to find anything online about having this warning removed. Most other security entities have routes of removal posted on their sites. We called customer service and they told us to open an account and start a ticket. Just wondering if we could get some basic info here.

Thank you

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: Information on Flagged Site Removal
« Reply #1 on: December 04, 2015, 06:34:29 PM »
Two items that can help to analyse is the URL (change http to hXXp, so the link isn't active) and attach an image of the avast alert (or post the avast alert info).

You are more likely to get a faster response on the forums than generating a support ticket.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: Information on Flagged Site Removal
« Reply #2 on: December 04, 2015, 08:31:19 PM »
Thank you so much for the helpful response. It basically says "HTML:Script-ref"   http://screencast.com/t/yjKthBVwXqo

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: Information on Flagged Site Removal
« Reply #3 on: December 04, 2015, 09:49:26 PM »
Since you have obscured the URL in your image, no one can attempt to analyse it.

Please modify the URL of the alert as I mentioned so it isn't active/clickable to avoid exposure and post it in your next post.

The HTML:Script-ref is normally associated with script injection, but that can't be checked without the URL.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33914
  • malware fighter
Re: Information on Flagged Site Removal
« Reply #4 on: December 05, 2015, 12:23:43 AM »
Like DavidR says this detection comes from particular embedded javascript code that is alerted.
There were cases however where it was a false positive.
Contact Avast Team here with the full url where the alleged detection was found: https://www.avast.com/contact-form.php
When indeed a FP Avast Team Members are found to react quicly  and sometimes with a next update of the AV.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!