My site is detected as virus (but it isn't)
#1

Hello,

This problem is really annoying me. My site is being detected as virus, but I know it is not. It's on paid host (GTA Multi) and paid domain (bought in cactus.ee). If you got an antivirus, check out this ->><link removed>. I don't want to advertise or something, but just check. Why is it detected as virus, while it's clean? Firefox says: The connection has been re-initialized while loading the page. It's clearly the Firewall of Norton/AVG is blocking.

Anyone know how to fix? I know my site doesn't have a virus.

Jochem
Reply
#2

Its most likely something inside the index.php, My friend had it, I'll see if he knows how to fix

Edit: I friend told me he changed the domain, to fix it, so ask gta-multi
Reply
#3

My anti-virus says it's because of a JS-Redirect which is probably a javascript redirect, you should just use html or php to redirect people when they enter your site.
Reply
#4

Works fine for me (F-Secure)
Reply
#5

Lol if i go to the homepage -> It's good
But if i go to the forum of the website:



yeah
Reply
#6

It's due to XSS attack on your site. Try to verify all your forum/site java and php scripts.

Edit: One of your .js script is injected with exploit. Remove them and use ****** CDN.
Reply
#7

Well same for me.

ScreenShot:


If you can post your index.php/html code in a pastebin I could try to help you out.

Edit: as xFlawless said, I also have a feeling that it is something to do with the javascripts that the site uses.
Reply
#8

Only 7 of 43 anti-viruses detects your problem (according to virustotal.com)
http://www.virustotal.com/file-scan/...679-1308153368
Reply
#9

http://www.symantec.com/connect/blogs/blackhole-theory

Basically, you weren't careful with your installation or there's a flaw in SMF which was exploited to implement the 'Blackhole Toolkit' which is a trojan (according to the Symantec website).
Reply
#10

I've removed the .js scripts, but I can't still enter it. How? х_Х
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)