I am using AIS 6.0.1289 and it started to block one of my favorite website (forum).
And I cannot find anyplace to add this site to whitelist as trusted.
There is no such thing as a trusted web site now, as the most common form of infection is from hacked web sites.
Since you give zero information on the alert, web shield or network shield or the web site, specific URL of the alert and the malware name, it is somewhat difficult to help you.
So if you can expand on the information required, hopefully someone can help as it is 2:20am here and I’m calling it a night.
When posting a URL, change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites, thanks.
Thank you for your prompt reply.
It is the network shield which blocks bbs.pediy.com
Report 2011-11-01 09:39:55 (GMT 1)
Website bbs.pediy.com
Domain Hash 9a91d02acee567e2facbc7b68ec20087
IP Address 219.232.241.55 [SCAN]
IP Hostname -
IP Country CN (China)
AS Number 4808
AS Name CHINA169-BJ CNCGROUP IP network China169 Beij…
Detections 0 / 23 (0 %)
Status CLEAN
Report 2011-11-01 10:52:43 (GMT 1)
IP Address 219.232.241.55
IP Hostname -
IP Country CN
AS Number N/A
AS Name N/A
Detections 0 / 26 (0 %)
Status CLEAN
web site: bbs.pediy.com
status: Verified Clean
web trust: Not Blacklisted
Security report (No threats found):
check Blacklisted: No
check Malware: No
check Malicious javascript: No
check Malicious iFrames: No
check Drive-By Downloads: No
check Anomaly detection: No
check IE-only attacks: No
check Suspicious redirections: No
check Spam: No
Whilst Asyn give the details of the scan at URLVoid, there is more information, see http://www.urlvoid.com/scan/bbs.pediy.com as there also appears to be other things hosted on that IP (bbs.kanxue.com).
So I don’t know if that may also have an effect or if the bbs.pedly.com has been infected/hacked before ?
This site checker http://sitecheck.sucuri.net/scanner/ also finds it clean.
URLQuery also finds it clean - Report on bbs.pedly.com - hXXp://urlquery.net/report.php?id=6815:
NOTE: - avast alerts on the actual report scripting file, hXXp://urlquery.net/js_update.php [L] JS:ScriptPE-inf [Trj] used during the compilation of the report (this happens on some other analysis sites). Interestingly this php page in isolation, scanned at VirusTotal (VT) doesn’t get any detection, VT Results on js_update.php scan, so it must be its association with the other site, redirection, touching it, etc.
####
There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for: * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.
- If you are reporting an FP, then you get another input field open, click Browse button and navigate to the file or enter the web URL for the site you wish to submit for Network Shield review, etc. A link to this topic also wouldn’t hurt.
False, fixed, sorry.
Not yet resolved in the latest virus definitions (VPS), 111102-0 version, hopefully it will be resolved in the next VPS update.
Thank you very much for your help.
Yes, confirmed no alert on the site now.