Author Topic: Remove my site from Avast Blacklist  (Read 2878 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Remove my site from Avast Blacklist
« on: August 26, 2016, 10:33:22 AM »
Hello,

Could you help me to remove my site from your blacklist?

http://www.aplusoassociates.com/ was infected, but it's all clean now.

Scaned by virustotal.com:

This URL was last analysed by VirusTotal on 2016-08-02 16:34:31 UTC
Detection ratio: 0/68

Unblock it, please.

Thank you!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Remove my site from Avast Blacklist
« Reply #1 on: August 26, 2016, 10:46:00 AM »
« Last Edit: August 26, 2016, 11:00:58 AM by Eddy »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Remove my site from Avast Blacklist
« Reply #2 on: August 26, 2016, 11:39:18 AM »
Hoster insecurety: Name Servers Versions
WARNING: Name servers software versions are exposed:
192.241.152.201: "9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1"
95.85.28.55: "9.8.2rc1-RedHat-9.8.2-0.30.rc1.el6_6.3"
Exposing name server's versions may be risky, when a new vulnerability is found your name servers may be automatically exploited by script kiddies until you patch the system. Learn how to hide version.

Malicious phishing from IP. Moziila Observatory Scan: https://observatory.mozilla.org/analyze.html?host=www.aplusoassociates.com
meagre F-status.

pol
« Last Edit: August 26, 2016, 12:07:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


REDACTED

  • Guest
Re: Remove my site from Avast Blacklist
« Reply #4 on: August 26, 2016, 05:34:54 PM »
Hoster insecurety: Name Servers Versions
WARNING: Name servers software versions are exposed:
192.241.152.201: "9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1"
95.85.28.55: "9.8.2rc1-RedHat-9.8.2-0.30.rc1.el6_6.3"
Exposing name server's versions may be risky, when a new vulnerability is found your name servers may be automatically exploited by script kiddies until you patch the system. Learn how to hide version.

This server configuration, and I can not change them

https://observatory.mozilla.org/analyze.html?host=www.aplusoassociates.com - this general information on the standard of safety, there is no evidence that the site has a virus.

REDACTED

  • Guest
Re: Remove my site from Avast Blacklist
« Reply #5 on: August 26, 2016, 05:38:13 PM »
http://www.aplusoassociates.com/ This site has been cleaned by the web security company.

They have removed all malicious code on the site.

Re-scan and delete it from your blacklist please.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Remove my site from Avast Blacklist
« Reply #6 on: August 26, 2016, 05:53:27 PM »
Quote
https://www.virustotal.com/en/ip-address/138.201.31.212/information/ - this report is old and does not contain any relevant information
Guess you haven't looked at the date of the detections. Latest one is  2016-08-26 08:11:51

Quote
These two libraries are contained in the original version of wordpress and do not contain malicious code
It still need to be fixed.
If you don't, the site will be vulnerable to infections/abuse.

Quote
http://urlquery.net/report.php?id=1472201470880 - this link is not malicious scripts loadable
It very clearly shows that malware is present on that IP/ASN.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Remove my site from Avast Blacklist
« Reply #7 on: August 29, 2016, 09:50:38 AM »
aplusoassociates[.]com was indeed infected, most probably by nuclear EK. I am unblocking it now, but please do pay attention to insecurities/vulnerabilities others pointed out, or your domain might be blocked again in the future.