ChongLuaDao False Positive Removal: Get Your Site Delisted
By Glenn Lyvers · Updated · 6 min read
If ChongLuaDao (“Chong Lua Dao” on VirusTotal) is flagging your website as malicious or phishing, you can ask for removal through its official complaint form at chongluadao.vn/en/report/reportmistake, giving the flagged URL, a contact email and a clear reason. Before you do, make sure the site really is clean — a request against a live infection won’t hold, and ChongLuaDao frequently flags the same sites other engines are already catching.
Who ChongLuaDao is
ChongLuaDao — Vietnamese for “scam fighters” — is a non-profit anti-fraud project founded in Vietnam in December 2020 by a group of security specialists. It maintains a database of scam and phishing websites and publishes it through a browser extension for the major browsers, mobile apps and an API, and it contributes as a URL-scanning engine on VirusTotal. It lists partnerships with a range of large platforms and security companies.
The practical upshot for a site owner: most people outside Vietnam never see a ChongLuaDao warning in their browser. You usually find out from a VirusTotal URL report, from a client’s security team that aggregates VirusTotal results, or from downstream tools that consume its feed.
Why it flags websites
ChongLuaDao’s focus is scams and phishing, so its verdicts react to what those look like: login and payment forms, pages imitating banks or well-known brands, redirect chains, and domains or hosting that share infrastructure with known scam sites. It also takes reports from the public, which means a listing can start with one complaint.
In my experience the two most common situations are:
- A real compromise. A phishing kit dropped into a folder on your site, or injected JavaScript sending visitors through a scam redirect. If that’s the case, several other engines usually agree. Phishing pages on your website explains what to look for.
- A lone, stale or over-broad flag. ChongLuaDao is the only red row on VirusTotal, often next to a Gridinsoft “Suspicious”. That pairing comes up a lot in the searches that bring people here, and I’ve explained the Gridinsoft side in Gridinsoft verdicts explained.
Step 1 — Confirm the site is clean
Don’t skip this because you’re sure it’s a false positive. Check it two ways:
- Run a VirusTotal URL scan, press rescan, and note every engine that flags you, not just ChongLuaDao. My website blacklist check lists the lookup tools for the others.
- Run my free site scan, then load the site from a phone and from a search result. Scam redirects commonly hide from logged-in owners and desktop browsers — see redirects that only happen on mobile.
If anything real turns up, get it cleaned first, including the backdoor or weak point that let it in. Otherwise the listing will come straight back.
Step 2 — Submit the complaint to ChongLuaDao
- Open the ChongLuaDao complaint form (the English version of their “report a mistake” page).
- Enter your email address, the exact flagged URL, and the reason.
- In the reason, be concrete: what the site is, who owns it, that you’ve checked it, and — if there was an infection — what you removed and when. Mention that it appears as a ChongLuaDao detection on VirusTotal.
- Agree to their policy and submit. Keep a copy of what you sent.
The same page lists info@chongluadao.vn as a contact address. If you get no response to the form, a short follow-up to that address with the same details is reasonable.
Good to know: ChongLuaDao doesn’t publish a review timeframe, and site owners report that replies can be slow or never arrive. Submit once, complete, and follow up once — repeated submissions don’t help. Check your VirusTotal result every few days with a fresh rescan to see whether the verdict has changed.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
Step 3 — If the flag keeps coming back
A listing that returns after you’ve been cleared almost always means something is still on the site: a phishing folder you didn’t find, a script loaded from a suspicious domain in your code, or a backdoor re-adding either. Why sites keep getting reinfected covers the usual culprits. That’s the point where I’d stop filing forms and find the cause — which is exactly what I do: clean the site completely, submit the delisting requests on your behalf, and harden it so it stays off the lists.
Flagged by other vendors too?
Each engine keeps its own list and its own removal route, and clearing ChongLuaDao does nothing for the others. The common companions are covered here: the Gridinsoft false positive report steps, CyRadar (another Vietnamese engine), PhishTank and Google Safe Browsing. For everything else, the all vendor removal routes directory lists the official form for over a hundred engines.
Common questions
What is Chong Lua Dao on VirusTotal?
Chong Lua Dao, or ChongLuaDao, is a Vietnamese non-profit anti-scam project founded in 2020 that maintains a database of scam and phishing websites. It contributes that data to VirusTotal as a URL-scanning engine, which is where most site owners outside Vietnam first see its verdict.
How do I remove my website from ChongLuaDao?
Confirm the site is clean, then submit the official complaint form at chongluadao.vn/en/report/reportmistake with your email, the exact flagged URL and a concrete reason. The page also lists info@chongluadao.vn as a contact address for a follow-up if you hear nothing back.
How long does ChongLuaDao take to review a false positive?
ChongLuaDao does not publish a timeframe, and owners report that responses can be slow. Submit one complete request, follow up once by email if needed, and rescan on VirusTotal every few days to see whether the verdict has changed.
Why do ChongLuaDao and Gridinsoft both flag my site?
Both lean heavily on reputation and heuristic signals for URLs, so they often react to the same things: new or shared hosting, redirect chains, login forms or a past infection. When they are the only two flags, a stale or heuristic verdict is likely, but check the site before assuming so.
Is a ChongLuaDao warning a sign my site is hacked?
Sometimes. If Google Safe Browsing or several other engines agree, treat it as a real compromise, typically a phishing kit or scam redirect. If ChongLuaDao is the only flag and the site checks out clean from several angles, it is more likely a false positive worth disputing.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.