A
A
Alexander Balya2014-02-03 12:23:58
Malware
Alexander Balya, 2014-02-03 12:23:58

Why does Kaspersky Anti-Virus recognize a virus on the site, although it obviously cannot be?

Kaspersky Anti-Virus, when you try to access the site, issues a warning that the site is blocked and there is a virus on it. Moreover, the virus is defined in the site icon file favicon.ico, before that there was an icon in the .png format, which was also defined as a virus.

favicon.ico	Запрещено: http://xxxxxxx.ru/favicon.ico (проверка по базе подозрительных веб-адресов)	03.02.2014 11:42:39

Checking with other online scanners ( antivirus-alarm.ru , sitecheck.sucuri.net , urlvoid.com ) shows that the site is clean.
In the webmaster tools of Yandex and Google , the site is also defined as safe.
As far as I understand, the virus cannot be in the graphic .ico file, in addition, the results of checking other services show that there is no virus on the site. It turns out that there is a clear error of Kaspersky Anti-Virus and probably the site address was included in some kind of black list.
I did not find any information about the principles of getting a site into the black list of Kaspersky and the procedure for removing it from there in case of an error. On the Kaspersky website, technical support can only be obtained by Kaspersky Lab customers and there are no contacts for addressing such issues.
Has anyone come across something similar? How to force Kaspersky to remove a site from the blacklist?

Answer the question

In order to leave comments, you need to log in

6 answer(s)
A
Alexander Balya, 2014-02-03
@Balya

In general, the solution to the problem is as follows: you need to send a link to the site to [email protected] marked "False positive".
You can also send a request to the Kaspersky Virus Lab using this form (you will need to register): https://my.kaspersky.com/en/support/viruslab
Here is a forum thread with a similar problem: forum.kaspersky.com/index.php ?showtopic=141392

A
Andrew, 2014-02-03
@OLS

1) Download the ico file and give it to virustotal.com
2) Check if other content is given instead of the ico file if you connect from Android or any other platform (I have observed it many times, though not in relation to ico).

N
Nikolai Vasilchuk, 2014-02-03
@Anonym

Write to Kaspersky support
https://my.kaspersky.com/en/support/helpdesk

B
Baleskin1, 2014-02-03
@Baleskin1

Give the ico somewhere for verification, because the virus may well be there (yes, Kaspersky does not always lie).

A
Alexander Balya, 2014-02-03
@Balya

Here, if anyone is curious, the same .ico file: https://dl.dropboxusercontent.com/u/8962724/favicon.ico

K
Kop3t3, 2014-02-12
@Kop3t3

check the .htaccess file
it was an infected site, there was a substitution of favicon for a script when entering from search engines

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question