Clean web site is still blacklisted with Avast

The site had a malware infection few months ago (favicon.ico). Now it clean, but avast still blocks the site. Can you exclude the site from avast’s blacklist?
The site is hxxp://ideluxe.net/

VirusTotal (webscan) 0/6
http://www.virustotal.com/url-scan/report.html?id=a4984599993fa0a5e18d56eaf2bf0f89-1324730671

VirusTotal (index.html) 0/ 43
http://www.virustotal.com/file-scan/report.html?id=c50088bc9ce8e809e6822bfe95c75e32df43c69aa04fb14dff679a2958cc8b3c-1324734336

Hi undeluxer,

Sucuri gives your site as clean, not blacklisted.
Wepawet also: http://wepawet.iseclab.org/view.php?hash=a4984599993fa0a5e18d56eaf2bf0f89&t=1324748110&type=js
urlQueryNet still has problems: http://urlquery.net/report.php?id=13352
This here is suspicious:
-ideluxe.net/engine/classes/min/index.php?charset=windows-1251&f=-engine/classes/highslide/highslide.js&5 suspicious
[suspicious:2] (ipaddr:184.22.116.28) (script) -ideluxe.net/engine/classes/min/index.php?charset=windows-1251&f=-engine/classes/highslide/highslide.js&5
status: (referer=ideluxe.net/)saved 48952 bytes d4ce8ee9e4534d5c26aa044d22aec5639a9bc14d
Rogue malware…
Weprep is bad http://www.mywot.com/en/scorecard/ideluxe.net
& http://www.webutation.net/go/review/ideluxe.net
Site has illegal content

polonus

I replaced highslide.js to a new version from the official site.
But still responds to the avast site as if there virus

[url=http://www.avast.com/ru-ru/lp-security-information-fp2?p_ext=0&utm_campaign=Virus_alert&utm_source=prg_fav_60_0&utm_medium=prg_systray&utm_content=.%2Ffa%2Fru-ru%2Fvirus-alert-challenger2&p_vir=al&p_prc=file://C:\Program Files (x86)\SEO PowerSuite\WebSite Auditor\bin\websiteauditor.exe&p_obj=http://ideluxe.net/&p_var=.%2Ffa%2Fru-ru%2Fvirus-alert-default2&p_pro=0&p_vep=6&p_ves=0&p_lqa=0&p_lsu=24&p_lst=0&p_lex=300&p_lng=ru&p_lid=ru-ru&p_elm=7&p_vbd=1367]www.avast.com/ru-ru/lp-security-information-fp2?p_ext=0&utm_campaign=Virus_alert&utm_source=prg_fav_60_0&utm_medium=prg_systray&utm_content=.%2Ffa%2Fru-ru%2Fvirus-alert-challenger2&p_vir=al&p_prc=file://C:\Program Files (x86)\SEO PowerSuite\WebSite Auditor\bin\websiteauditor.exe&p_obj=http://ideluxe.net/&p_var=.%2Ffa%2Fru-ru%2Fvirus-alert-default2&p_pro=0&p_vep=6&p_ves=0&p_lqa=0&p_lsu=24&p_lst=0&p_lex=300&p_lng=ru&p_lid=ru-ru&p_elm=7&p_vbd=1367[/url]

New reports
http://antivirus-alarm.ru/proverka/?url=ideluxe.net&again=1
http://www.virustotal.com/url-scan/report.html?id=a4984599993fa0a5e18d56eaf2bf0f89-1324778074

What is al infection: al, and why she reacts to my site when other anti-virus software is completely silent, including your avast silent for online verification. Reacts only when you come to the site.
Please Explain the situation

Hi undeluxer,

If you think your website is free of malware report it using the http://www.avast.com/contact-form.php?loadStyles link and give a link back to this topic. Could be the blacklist will be lifted with a coming update.

polonus

A month went by as I wrote in support of your problem, but none so I did not answer my problem is not solved. Add only new challenges, avast changed the form of infections in the url: mal and now not only swears by favicon (which incidentally has been removed as a month) and a bunch of other pictures that are in the template and have added new pictures. I downloaded the pictures and information on each check virustotale, not one picture has not been infected by viruses, including avast showed that the images are clean, even at a local scan.
Responds not only to pictures but also for all kinds of addresses from BBB, http, and just domain name.
How much can you tolerate bezolabernuyu down your anti-virus?
I ask you on a human, remove my site from the blacklist Vast

Did you report it yet…?? (See Reply #3 from polonus…!)

I am a month waiting for an answer, which nebylo that I have yet to report, even if they do not come to the correspondence. And on the forum though as a responsible

Sorry, not sure what you mean…!?

@ Asyn
I guess he is hoping that simply reporting on the forums would be enough.

@ undeluxer
It isn’t as you hope that one of the developers will see your post amongst the thousands of topics posted each week. The people who have viewed and commented in this topic are avast users just like you and that is why they suggested the contact form.

That is why we give the link given the day after your first post (http://www.avast.com/contact-form.php?loadStyles) to the contact form, so that it can be reported directly. Where it is likely to get the attention it requires, when reported it can be reviewed and corrected as required, avast is normally quick to correct these when they are reported using this contact form.

All that is known to be bad is out on that autonomous system.
Sitevet report is obvious.
AS Name: NOC - Network Operations Center Inc.
IPs allocated: 281088
Blacklisted URLs: 2713

Hosts…
…malicious URLs? Yes
…badware? Yes
…botnet C&C servers? Yes
…exploit servers? Yes
…Zeus botnet servers? Yes
…Current Events? Yes
…phishing servers? Yes

Lifting the blocking is not to us, but the developers of avast. Do as DavidR tells you
and report.
Also consider this domain lock report: http://www.ipillion.com/site/ideluxe.net

polonus

Well, I thought that somebody will answer me from the administration of Avast, I thank you for the answer, but I already wrote in the feedback form after answering polonus. I waited for a month but no reply was received, and of the result remains the same. Wrote again, hopefully not have to wait very long.

Hi undeluxer,

If the site is not infected, after reporting to avast the blocking could be lifted with the next update, that is up to the avast team members responsible for that blocking. If the site is still infected there will be no change at all as the malware has to be removed first. If the cleansing is beyond you, you are barking up the wrong tree and have to contact the abuse department at your hoster to have the malware there removed or make it will no longer respond or infect. For 2713 URLs they have not done that yet and several issues may be long overdue,

polonus

Hello,
this detection was disabled in the lates virus definition update.