system
1
Hello
avast make report at my site
please check where this virus link?
rh.net.sa
Pondus
2
what does avast say?
attach a screenshot of the avast warning please
Eddy
3
Pondus
4
See: rh.net.sa,162.222.212.26,bob.ns.cloudflare.com,Parked/expired,
Well both domain and IP are being blocked by avast! as URL:Mal, rgar is a general detection.
Appears on this list: http://www.cloudflare-watch.org/domains/rba-rhe.html
See potentially suspicious files here: http://quttera.com/detailed_report/rh.net.sa (like Eddy reported)
which may point to obfuscation or shellcode. (unknown html rfi-eval adware code)
See: http://jsfiddle.net/3TG9n/
polonus
Milos
6
Hello,
it looks that there was hosted Sality. Can you confirm that it is clean now? I suggest to change all passwords and update all systems. Then contact us through http://www.avast.com/contact-form.php
Milos
system
7
Hello
im delete all files can you check now
Pondus
8
system
9
hello
check via your self
http://www.rh.net.sa/webstyles/default/lib/jquery-1.9.0.min.js
it’s empty
and another file delete and make 404
Eddy
11
You should use at least jQuery version 1.11.0
http://blog.jquery.com/2014/01/24/jquery-1-11-and-2-1-released/
Wondering why a site with the SA TLD is in Arabic(?) though.
system
12
Offline Steven Winderlich
im sure i empty the file
it’s cache at avast
–
Eddy
my site is arabic saudi arabia site ,
and i remove the jQuery file ,
please check again
http://upload.3rby.net/uploads/13960989851.png
Eddy
13
Little mix-up.
Thought SA was South Africa, but that is ZA 
Hello Steven,
avast! is blocking the connection, not the website content itself. As the OP states, it is indeed empty.
@anassatef Based on my analysis, the Quttera results are false positive.
~!Donovan
To see what !Donovan means: http://jsfiddle.net/pU338/
polonus