false alarm?

i always get the red pop up while opening hxxp://gamexeon.com/forum/ . This is a clean site, the techs from that site said this might be a false alarm from Avast…

since it is a forum (see the url on the avast warning) i guess it is alarming on something someone have posted in the forum ?

sucuri
http://sitecheck.sucuri.net/results/gamexeon.com/forum/

There really is no such thing as a clean site any longer, the most common cause of infection coming from the internet is from hacked sites.

There appears to be a compressed file (possibly a javascript file) being loaded when you try to visit that page (the {gzip} bit at the end of the URL, as the html:Script-inf detection usually relates to an injected/obfuscated script tag that tries to redirect to a malicious site.

well…only avast detect

https://www.virustotal.com/file/da71ef2548107e3d322c609617c983f5d0646ac7968e4e86fb0ef79d9d7aed42/analysis/1340819226/

but not when doing the URL scan at URLVoid…
http://vscan.novirusthanks.org/analysis/7797f63755f13663bcbd82775cc59117/Zm9ydW0=/

Update: there is a connection made to cms-bin.com gate.php and this is what I believe avast is alerting on, see http://urlquery.net/report.php?id=76927 and you will see a GET for gate.php, image1. This also mentions gzip deflate so again is probably what the {gzip} is about in the detection.

We have seen this before in the forums and this site avast alerts on image2.

thank you. i’ll contact the forum techs ASAP.

i’ll let you know if theres reply from them

It would be interesting to know if the loading of this gzip/compressed file is legit, but more so the connection to cms-bin.com as it isn’t only avast that doesn’t like this site http://sitecheck.sucuri.net/results/www.cms-bin.com.

There are a whole slew of new detections pointing to an IP address that includes this domain and many others all with this same commonality the gate.php

hello… sorry for the late response

the admin’s forum has fixed the problem. now i can open the forum without any warning popups from avast.

anyway, thank you for your support. :wink:

You’re welcome.

Now you know why we say there is no such thing as a clean site any longer ;D