Avast aborts connection with my website and acuses hin to have a malware

Hi, my urls are www.agimovel.com.br and www.agimovel.com.br/acesso3.6/login.php

On both URL’s Avast says theres a malware named HTML:ChaseBank-A[Pish], I already ran a few tools to check my website and everything is ok, including McAFEE online scanner.

I also downloaded the file and opened with notepad and check everyline, it’s all normal.

Several customers are calling me and worried about the safety of they info. Can you help me?

Hello Marcelo, você conseguiu alguma solução para o seu problema? acabou de acontecer o mesmo problema comigo se tiver alguma luz e te agradeço, valeu.

English Please. :slight_smile:

Hello,

I have this problem too.

It started today.

Sorry, I’m having the same problem on two different servers, it follows the errors that are returning HTML: Framer-inf and HTML: ChaseBank-A. thanks

I have this problem as well. I hope Avast fixes this soon!

Eu descobri o motivo da mensagem…

Remova o conteudo do action do form.

Ex.:

Mude para:

Aparentemente o problema é quando o action esta preenchido. :frowning:

I discovered the reason for the message …

Remove the content from the form’s action.

Ex.:

Change to:

Apparently the problem is when the action is filled. :frowning:

Thanks but we can’t do that…we have an entire CRM that’s being blocked without any code change…

PS> this foruns captcha is killing me…

I`am facing the same problem.
Avast is acusing the URL of Phishing.
How to proceed to solve this problem ASAP?

Regards

Hello Avast? Any position?
The loss is great !!!
I have 2 servers with several sites with the same problem, all checked by Google, Sucuri, etc.

I have already made the false positive notice on the avast website https://www.avast.com/false-positive-file-form.php, but so far I have clients saying that my CRM is with viruses

Can confirm this is the issue.

No, this is not the problem!

may not be the problem you are seeing but if it is the one where they care complaining about chase phishing attack simply changing the action= value on the form tag from login.php to something else say login.phtml or blanking it as the other guy did makes the issue go away.

This has been acknowledged as an FP and has had a fix added to the virus definitions update.

is this a false positive? has there been an official statement somewhere from avast on this that isn’t in a backwaters forum?

fix your catcha too FFS

Hello Marcelo314.

I still see the detection and created in area portuguese and other topics related.

Breno27, bmeneses86,Talisson.What is URL?

Reported to Vírus Lab~

https://forum.avast.com/index.php?topic=222744.msg1480753#msg1480753

PS: Captcha is only needed for your first 3 posts. (Spam protection)

Is this fixed after users updates?

This put me in a lot of trouble, real lost of money and credibility. Can you picture customers being block for getting into my website?

You reposted my question in “portuguese” area? Can you pass me the link or topic? I’v searched and didn’t found anything.