I am a new owner countbiz.com, and Avast blocking my site. Please remove my site from black list.
WOT
http://www.mywot.com/en/scorecard/countbiz.com
http://ddanchev.blogspot.com/2009/05/gaztranzitstroyinfo-fake-russian-gas.html
The fake codec at video-info .info (AS29371 - gaztranzitstroyinfo LLC) is in fact downloaded from kir-fileplanet .com - 91.212.65.54 (AS48841; EUROHOST-NET) where more malicious activity is easily detected at:downloadmax .org - 91.212.65.19
hd-codec .com
shotgol .com
kauitour .com
coecount .com
countbiz .com
videoaaa .net
7stepsmedia .net
ispartof .net
amoretour .net
browardcount .nettrucount3000 .com - 91.212.65.10; 91.212.65.29
trucount3001 .com
trucount3002 .com
antivirus-xppro-2009.com
onlinescanxppp .com
onlinescanxpp .com
onlinescanxp .com
free-webscaners .comIn cybercriminals I don’t trust.
urlquery - Suspicious - http://urlquery.net/report.php?id=15562
Wha can I do?
Hi shurokan,
The following malware that came from that domain are now dead:
virus name: mdl_Jahlav was found at:
-http://countbiz.com/download/3575375651673d3dfe4e941820090516/VideoCodec.dmg
virus name: mdl_DNSChanger was found at:
-http://countbiz.com/download/3575375651673d3dfe4e941820090516/VideoCodec.exe
and virus name mdl_Trojan-Dropper.NSIS was found at:
http://countbiz.com/download/536f455566673d3d1092304b20090516/s-movie.exe
This was once reported here: http://www.siteadvisor.com/sites/countbiz.com/msgpage
The fake codec at video-info .info (AS29371 - gaztranzitstroyinfo LLC) was in fact downloaded from -kir-fileplanet .com - 91.212.65.54 (AS48841; EUROHOST-NET) where more malicious activity was easily detected at that site downloaded from -downloadmax .org - 91.212.65.19
But that incident was back in May of 2009.
The AS you are on AS4645 gives this report and there are some bad apples there:
AS Name: ASN-HKNET-AP HKNet Co. Ltd
IPs allocated: 245248
Blacklisted URLs: 196
Hosts…
…malicious URLs? Yes
…badware? Yes
…botnet C&C servers? Yes
…exploit servers? No
…Zeus botnet servers? No
…Current Events? Yes
…phishing servers? No
…spam servers? No
…spam bots? No
…spam activity? Yes That is what has been going on there.
Site is given suspicious here: http://urlquery.net/report.php?id=15566
If you think your website is free of malware report it using the http://www.avast.com/contact-form.php?loadStyles link and give a link back to this topic. Could be the blacklist will be lifted with some coming update.
polonus