Author Topic: Falsely reporting malware  (Read 2076 times)

0 Members and 1 Guest are viewing this topic.

WebmastahP

  • Guest
Falsely reporting malware
« on: February 28, 2012, 10:53:08 AM »
Greetings,

I don't use your particular software but some of the readers of our site do and have been getting warnings that we're serving malware.  We were temporarily infected with malware a few weeks ago and have since cleaned out the offending page/files causing the infection.  We were flagged by google and have since been rescanned and removed from the malware list however some of our users using your service are unable to visit our page because of your malware warnings.  What do we need to do to resolve this?  The site is www.kisforkinky.com

Thanks in advance,
Webmaster P

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Falsely reporting malware
« Reply #1 on: February 28, 2012, 10:57:36 AM »
Malware found in the URL:
hxxp://www.kisforkinky.com/

Known javascript malware.
http://sitecheck.sucuri.net/results/http://www.kisforkinky.com/
Details: http://sucuri.net/malware/malware-entry-mwjs6525
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33915
  • malware fighter
Re: Falsely reporting malware
« Reply #2 on: February 28, 2012, 04:26:41 PM »
The foillowing code is alos given as suspicious: wXw.kisforkinky.com/wp-content/plugins/portfolio-slideshow/js/portfolio-slideshow.min.js?ver=1.3.5 suspicious
[suspicious:2] (ipaddr:69.89.31.205) (script) wXw.kisforkinky.com/wp-content/plugins/portfolio-slideshow/js/portfolio-slideshow.min.js?ver=1.3.5
     status: (referer=wXw.kisforkinky.com/)saved 3750 bytes 5ec2f731ba21190c5f2879111b8b46b9ef12402a
     info: [decodingLevel=0] found JavaScript
     error: undefined variable jQuery
     error: undefined variable a.fn
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var a.fn = 1;
          error: line:1: ....^
     suspicious:
Reported as suspicious here: hxtp://wepawet.iseclab.org/view.php?hash=e3107604a9dd173782db90bff870410e&t=1330442225&type=js
But avast shield does not flag at the moment, there is a hidden iFrame redirect to 2.36.210.254 tags.bluekai.com trojan Mal/EncPk-JY
via htxp://tags.bluekai.com/site/2312?ret=html (probably not responsive?),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!