F-Secure says my site is harmful!

6 replies
Ugh. Take this as a rant, a warning, or whatever, but I am so frustrated right now.

We use F-Secure as our internet security system, and have for years without any problems.

Yesterday, they prompted us to download the new 2010 version, upgrading us free (at least till our licence renews in November).

All went well... it added (without asking me, which was a little annoying) a toolbar to firefox AND IE, with a shield, site monitor and a report button. (So now it takes more space on my toolbars... but I'll not rant about that one too much).

Anyway, today I went to log into one of my sites to do a mailing to my affiliates regarding a new site I just announced.

F-Secure *blocked* my access, telling me the site was harmful!

:confused:

So I tried not to panic, figured I'd look further to see if someone managed to hack through and place javascript or something on there. (It happened to one of my clients when she let another designer in to update her site, but ALL of our sites were totally clean).

I FTP'd in, viewed the code, and nothing was there that shouldn't be. No, I don't even use adsense there, so no geo tracking or anything is on there, just a getresponse subscribe form.

So I clicked to allow it, and sent feedback into the company complaining, because there's no reason for it.

Of course, then the checkmark changed to green in the toolbar because I allowed it... but I clicked the botton to see its "security review"... and it still said "this site is harmful!"

FIVE years ago, we had a toolbar system that people could install, which yes it was adware technically in that the buttons linked to member's affiliate sites (it was all paid for by members if they wanted their site there), there was no stuff being installed without people's permissions, etc.

When it had a lot of bugs, we switched to a private mail reader, which alerted members at the bottom right of their screen (just like outlook does when you get a new email!) to notify you that a new message is there.

What kills me?

This was like five years ago!

We totally changed the system and put everything online into the member pages instead, and removed the toolbars, pmr, etc.

So why on EARTH are these systems STILL flagging the site as being harmful??

I logged in and totally deleted all zip files in the download area just to 100% ensure there was nothing online anymore, but it hasn't been linked anywhere in years.

It just totally ticks me off, that F-Secure and probably other antivirus or malware or WHATEVER systems claim that a site could be "harmful" without even offering WHY! (And not justified).

So as a warning to everyone: While its important to pay attention to when your antivirus system says a site is harmful (to prevent viruses and phishing), it COULD also give false-positives, and in this instance, it really burns me, because it can COST me members and visitors, and for no reason! (Okay really, 5 years ago someone went off the deep end on toolbars with ads???)



F-Secure is one of *the best* for catching viruses and malware that Norton and Mcafee never found - but this side of things is really aggrivating, especially since I don't think I can turn it off... and even if I do - what about others who see this and panic and leave for no reason?

Anyone else experienced this with their sites and this or other security software?

I'm SO frustrated right now (obviously)

Amber
#anti-virus #false positives #fsecure #harmful #site
  • Profile picture of the author handyman
    Some part of a particulat javascript file may match a malware signature => red alert. Its not just someone hacked and placed a js there, your own js, say, for menus may be the problem.
    {{ DiscussionBoard.errors[1198495].message }}
  • Profile picture of the author Amber Jalink
    Thanks handymanon... but there isn't anything there. check it out - keyboardcash.com, you'll see that its really just a splash page. And I don't use javascript menus, that's why I can't figure it out
    {{ DiscussionBoard.errors[1198577].message }}
    • Profile picture of the author Tony Dean
      Just thinking out loud - is your ip address blacklisted at all?
      Signature

      {{ DiscussionBoard.errors[1198683].message }}
      • Profile picture of the author Karen Blundell
        hey Amber...how's it going?

        I have a theory...and it's just a slight possibility that this might work...

        I looked at the source code on that page and it might be because the doctype is missing...off the walll I know..but worth a shot...

        so replace line 1
        Code:
        <html>
        with

        Code:
        <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
        and then check to see if you still get that security warning

        I can confirm that there is nothing in there that would cause a security threat..you only have have a few minor HTML warnings according to my Firefox addon-HTML Tidy...but that's it (nothing to fuss about):

        Result: 0 errors / 8 warnings

        line 1 column 1 - Warning: missing <!DOCTYPE> declaration
        line 37 column 1 - Warning: <p> unexpected or duplicate quote mark
        line 71 column 1 - Warning: <style> isn't allowed in <blockquote> elements
        line 31 column 4 - Info: <blockquote> previously mentioned
        line 88 column 1 - Warning: inserting implicit <p>
        line 71 column 1 - Warning: <style> inserting "type" attribute
        line 19 column 2 - Warning: <table> proprietary attribute "bordercolor"
        line 37 column 1 - Warning: <p> attribute "align" has invalid value "left""
        line 88 column 1 - Warning: trimming empty <p>
        Info: Document content looks like HTML Proprietary
        Signature
        ---------------
        {{ DiscussionBoard.errors[1198834].message }}
  • Profile picture of the author Amber Jalink
    no, not that I know of.

    I just did some searches/checks, and no, the IP is not on any blacklists at all.

    Hopefully F-Secure will remove their alert after they read my email.
    {{ DiscussionBoard.errors[1198838].message }}
  • Profile picture of the author Amber Jalink
    Hi Karen - long time no talk

    Thanks, I did add the doctype as you suggested.

    Racking my brain. The only thing I can think of is if some hackers took the old toolbar and did something to it, leaving it claimed as us.

    Unfortunately I'm not about to go to some of those hacker sites (which do have warnings) to tell them to remove it.

    Might have to do some further checking on what I can do though.

    Amber
    {{ DiscussionBoard.errors[1198843].message }}

Trending Topics