Blocking false malware

Hello there guys

Why is avast blocking my ip : 94.249.189.185 and my website : ngcmta.com and it hadn’t got any virus or any malware :\

I need to unblock it cause it makes many problems to my business

You can report a possible FP here: http://www.avast.com/contact-form.php

Aysn I reported it before but no thing happened

How did you report it…?

http://www.websicherheit.at/en/security-tools/web-security-test-scan-results/
Suspicious
http://www.game-state.com/iframe.php?ip=94.249.189.185&port=22003&bgcolor=000000&bordercolor=474747&
Google / Browser Difference
Not identical
Google: 47215 bytes Firefox: 51074 bytes
Diff: 3859 bytes
First difference:
/index.php?phpsessid=0pknufo2iafiq6q26dhfb1nqm2&"; var smf_iso_case_folding = true; var smf_charset = “iso-8859-1”; var ajax_notification_text = “loading…”; var …

http://zulu.zscaler.com/submission/show/79f2f6e9a6b0280c84b20a5036ba1ca1-1414584715
http://urlquery.net/report.php?id=1414585083618
http://dnscheck.pingdom.com/?domain=ngcmta.com
http://www.ipvoid.com/scan/94.249.189.185/
https://www.ssllabs.com/ssltest/analyze.html?d=ngcmta.com

I reported it as false malware

I checked the most sites you posted and no virus / malware detected

Sure, but how…? Did you use the form…?

There are more reasons to block a IP/Domain besides malware.

ps:
Each virus is malware, but not the other way around.

@Eddy I hadn’t got any virus and this is avast results it’s a false block

@Asyn which form ? just told them to unblock it cause it’s false malware / virus

avast doesn’t say that there is malware.
URL:Mal means it is blocked, most likely a IP block.

Asyn means:
www.avast.com/contact-form.php

@Eddy ok what to do now ?

@Asyn which form ? just told them to unblock it cause it's false malware / virus
How did you report it ...means = did you phone avast?, did you send a mail to avast?, did you use the online form on there website? http://www.avast.com/contact-form.php

IP address history https://www.virustotal.com/nb/ip-address/94.249.189.185/information/

https://www.virustotal.com/nb/url/6d07fdfaf5d7a8e8ea983781ffdfb81e57502696dc47bfe7670ba3af22d02c25/analysis/
https://www.virustotal.com/nb/url/aad1be5abdb68221288fc61b9c91b72cfd162a83ddf06d14e2f9642f1cd34948/analysis/

Ik pondus now it 100% clear so ?

Errors here: http://dnscheck.pingdom.com/?domain=+ngcmta.comhttp://dnscheck.pingdom.com/?domain=+ngcmta.com&timestamp=1414594823&view=1
Warnings: https://asafaweb.com/Scan?Url=ngcmta.com
Probably IP block because of other domains on IP infested: https://www.virustotal.com/nl/ip-address/94.249.189.185/information/
Request a IP block domain exclusion.

polonus

P.S.
Site stays vulnerable because of: htxp://ngcmta.com/index.php?PHPSESSID=0vb24747oa7srt76adg8o98c04&action=login
XSS vulnerabilities:
->: hxtp://ngcmta.com/index.php?PHPSESSID=0vb24747oa7srt76adg8o98c04&action=login
Number of sources found: 3
Number of sinks found: 72
and
->: htxp://ngcmta.com/Themes/default/scripts/sha1.js
Number of sources found: 94
Number of sinks found: 4
and
→ URL: htxp://ngcmta.com/Themes/default/scripts/sha1.js
Number of sources found: 16
Number of sinks found: 37

iFrame xss vuln for: Results from scanning URL: htxp://www.game-state.com
Number of sources found: 3
Number of sinks found: 609 vuln. to hades-exploit

D

So what to do?

https://forum.avast.com/index.php?topic=158460.msg1142848#msg1142848

You have told several times already what to do.
One of the times is in reply #15

Ok reported it as a false malware