Author Topic: False positive. Site http://slil.ru/  (Read 3007 times)

0 Members and 1 Guest are viewing this topic.

SoloRom

  • Guest
False positive. Site http://slil.ru/
« on: September 14, 2009, 01:15:27 PM »
Hello! Today has found a false positive antivirus Avast! Avast! reacts to this site and does not go to him. But this site is very popular and most importantly clean for viruses. I checked the scripts of this site, they are clean. This is a false positive. Site http://slil.ru/
Correct the antivirus database, because it is impossible to enter the site.
Thank you!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positive. Site http://slil.ru/
« Reply #1 on: September 14, 2009, 01:29:02 PM »
Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Maybe you could contact its webmaster.

Also, please, check if there are infected gif images (resolved as infected server generated messages): http://forum.avast.com/index.php?topic=45658.0

Please, edit the links to not-live ones (change http for hxxp, for instance or add spaces between the url).

Quote
The vast majority of malware today is distributed over the web, mostly by means of hacked (otherwise legitimate) sites. The attacker usually injects malicious some scripts into some (or all) pages on the site, waiting for an unsuspecting user to visit the site and possible infect his/her machine.

And this is where avast’s detection capabilities really excel. Its abilities to detect these web-based malicious scripts are second to none, and thanks to the Web Shield and Script Blocking providers, they are used exactly when needed, doing an excellent job stopping the web-based malware right on the entry point.
The best things in life are free.

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: False positive. Site http://slil.ru/
« Reply #2 on: September 14, 2009, 02:13:24 PM »
Hello,

This looks to be a false positive. It’s the file storage server and we were starting to block it because there were many hits on malware files. The block will be removed in next vps update.

Regards