Blacklisted?
Start here: step-by-step removal guides for every blacklist & antivirus, plus a free Is My Site Hacked? checker. If your website has been blacklisted and visitors are receiving warnings, DrGlenn has some self-help for you. If the blacklist is in the list below, use the contact info to reach out and get yourself delisted. If not, please come back and report the blacklist and how to remove it using the form on this page. Be sure to include all the links and details so DrGlenn can help others that have the same issue. Blacklists are very frustrating. Together, we can clean it up and get you back on track.
Report NEW Blacklist Removal Links
BlackList Name |
How to Report False Positive to the Blacklist |
| 360 | kefu@360.cn |
| AhnLab | https://global.ahnlab.com/site/support/virusreport/virusReport.do |
| Cyberoam | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Avira |
| Acronis | https://kb.acronis.com/content/62189 |
| Ad-Aware | https://www.adaware.com/report-false-positives |
| AegisLab | support@aegislab.com |
| Agnitum | trojans@agnitum.com |
| Ahnlab | e-support@ahnlab.com, samples@ahnlab.com |
| AhnLab-V3 | v3sos@ahnlab.com |
| Alibaba | virustotal@list.alibaba-inc.com |
| Alyac (Estsoft) | esrc@estsecurity.com |
| Antivir | cleanset@avira.com, virus_malware@avira.com, virus@avira.com |
| Antiy | avlsdk_support_vt@antiy.cn |
| Antiy-AVL | https://www.antiy.net/contacts/ |
| Arcabit | virus@arcabit.com |
| Ashampoo | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Emsisoft https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Bitdefender |
| Auslogics | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Bitdefender |
| Avast | virus@avast.com https://www.avast.com/false-positive-file-form.php |
| AVG | http://www.avg.com/submit-sample https://www.avg.com/en-us/false-positive-file-form http://samplesubmit.avg.com/us-en/false-detection |
| Avira | https://www.avira.com/en/analysis/submit |
| Avira AntiVir | https://analysis.avira.com/en/submit |
| AVZ | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Kaspersky |
| Babable | obu@babable.com |
| Baidu | bav@baidu.com, gaoyingchun@baidu.com |
| BitDefender | virus_submission@bitdefender.com https://www.bitdefender.com/consumer/support/answer/40673/ http://www.bitdefender.com/site/Main/automaticSampleUploader/ |
| Bkav | fpreport@bkav.com bkav@bkav.com bkav@bkav.com.vn |
| BluePoint Security | fp@bluepointsecurity.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| BullGuard | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Bitdefender |
| ByteHero | bytehero@163.com |
| CAT-QuickHeal | https://www.quickheal.com/submitticket/ |
| Certego | https://www.certego.net/en/contatti/ |
| ClamAV | http://www.clamav.net/reports/fp https://www.immunet.com/false_positive |
| Clean-MX | abuse@clean-mx.de |
| CMC | vulambang@cmcinfosec.com, support.is@cmclab.net |
| Comodo | malwaresubmit@avlab.comodo.com https://www.comodo.com/home/internet-security/submit.php falsepositive@avlab.comodo.com https://www.comodo.com/home/internet-security/submit.php |
| Constant Guard/xfinity | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Symantec |
| CrowdStrike | VTscanner@crowdstrike.com |
| CrowdStrike Falcon | VTscanner@crowdstrike.com |
| Cybereason | vt-feedback@cybereason.com |
| Cylance | cylancefilesubmit@cylance.com https://web.archive.org/web/20190929165253/https://home-support.cylance.com/hc/en-us/articles/360026236014-FAQ-VirusTotal-Inquiry |
| CyRadar | virustotal@cyradar.com |
| Cyren | https://www.cyren.com/support/reporting-av-misclassifications |
| DNS8 | dns8@layer8.pt |
| Dr. Web | https://vms.drweb.com/sendvirus/ |
| DrWeb: | vms@drweb.com |
| eGambit | https://tehtris.com/en/false-positive-negative-requests/ |
| eGambit (Tehtris) | https://tehtris.com/egambit_fp.php |
| Elastic | https://discuss.elastic.co/t/submitting-false-positives/232322 |
| Emco | malware@emcosoftware.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Emsisoft | submit@emsisoft.com fp@emsisoft.com |
| Endgame | info@endgame.com |
| eScan | fp@escanav.com http://support.mwti.net/support/index.php |
| ESET | https://support.eset.com/kb141/?page=content&id=SOLN141 |
| ESET-NOD32 | https://support.eset.com/en/kb141-submit-a-virus-website-or-potential-false-positive-sample-to-the-eset-lab#SubmitFile |
| Faronics | support@faronics.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| FireEye | virustotal@fireeye.com |
| Forcepoint (websense) | suggest@forcepoint.com |
| Fortinet | submitvirus@fortinet.com |
| Fortinet/FortiGuard | submitvirus@fortinet.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| FortKnox SpyEmergency/Netgate | mailto:research@spy-emergency.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| F-Prot | viruslab@f-prot.com |
| F-Prot/FRISK | http://support.f-prot.com/index.php?/Tickets/Submit/RenderForm/7 |
| F-Secure | spyware-samples@f-secure.com, vsamples@f-secure.com https://www.f-secure.com/en/business/support-and-downloads/submit-a-sample https://www.f-secure.com/us-en/business/support-and-downloads/submit-a-sample |
| G Data | https://su.gdatasoftware.com/us/sample-submission/ https://www.gdatasoftware.com/faq/consumer/submit-a-suspicious-file-app-or-url |
| Gridinsoft | https://anti-malware.gridinsoft.com/false-detect/ |
| Hacksoft | virus@hacksoft.com.pe |
| Hauri | viruslab@hauri.co.kr |
| Hitman Pro | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Bitdefender https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Kaspersky https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Emsisoft |
| HomePage | support@aegislab.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Ikarus | fp@ikarus.at, samples@ikarus.at probe@ikarus.at |
| Immunet Protect | http://www.immunet.com/contact/index.html |
| Invincea | info@invincea.com |
| Jiangmin | support@jiangmin.com shaojia@jiangmin.com |
| K7 | reportfp@labs.k7computing.com k7viruslab@labs.k7computing.com reportfp@k7computing.com <reportfp@k7computing.com>; |
| K7AntiVirus / K7GW | support@k7computing.com |
| Kaspersky | https://opentip.kaspersky.com/ https://my.kaspersky.com/?logonSessionData=MyAccount&returnUrl=en%2fkpc%2fsupport%2fviruslab |
| Kaspersky: | newvirus@kaspersky.com |
| Kingsoft (Cheetah) | operation@cmcm.com |
| Lavasoft Ad-Aware | http://lavasoft.com/support/securitycenter/report_false_positives.php |
| Lionic | https://www.lionic.com/reportfp/ |
| Lumension | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Norman |
| Malwarebytes | https://forums.malwarebytes.org/index.php?/forum/42-file-detections/ |
| MAX (SaintSecurity) | root@malwares.com |
| MaxSecure | tech@maxpcsecure.com |
| McAfee | virus_research@avertlabs.com https://mysupport.mcafee.com/Eservice/Default.aspx virus_research@mcafee.com?subject=FALSE%3A%20This%20Sample%20Is%20A%20False%20Positive&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected virus_research@mcafee.com?subject=FALSE%3A%20This%20Sample%20Is%20A%20False%20Positive&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| McAfee-GW | virus_research_gateway@avertlabs.com |
| Microsoft | mmpc@submit.microsoft.com |
| Microsoft Security Essentials | https://www.microsoft.com/security/portal/Submission/Submit.aspx |
| Microworld | samples@escanav.com |
| Moon Secure | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Immunet_Protect |
| Msecure | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Ikarus |
| Nod32/ESET | samples@eset.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| NoraScan | support@noralabs.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Norman: | analysis@norman.no, support@norman.com |
| nProtect (Inca) | virus_info@inca.co.kr |
| Palo Alto | vt-pan-false-positive@paloaltonetworks.com |
| Panda | falsepositives@pandasecurity.com, virussamples@pandasecurity.com https://www.pandasecurity.com/usa/homeusers/support/contact.htm?ts=1 https://pandasecurity.com/usa/homeusers/support/contact.htm?ts=1 falsepositives@pandasecurity.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Phising Database | https://github.com/mitchellkrogza/Phishing.Database#please-remove-my-domain-from-this-list- |
| Preventon | sample@preventon.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Qihoo-360 | https://www.360totalsecurity.com/en/suspicion/false-positive/ |
| QuickHeal | viruslab@quickheal.com |
| Rising | http://mailcenter.rising.com.cn/filecheck_en/ |
| Roboscan/ALYac | http://www.roboscan.com/support/virus_report.aspx |
| Sangfor Engine Zero | save@sangfor.com.cn |
| SecureAge APEX | https://uav.secureage.com/falsepositive/ |
| Sentinel One | report@sentinelone.com |
| ShawSecure | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#McAfee |
| SmartCOP | support@s-cop.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Sophos | samples@sophos.com https://secure.sophos.com/support/samples |
| Spybot Search & Destroy | http://www.safer-networking.org/contact/detections/ |
| SRN/Solo Antivirus | vlab@srnmicro.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Symantec | https://submit.symantec.com/false_positive/ avsubmit@symantec.com https://symsubmit.symantec.com/ |
| Tachyon | isarc@inca.co.kr (include detection name) |
| Tencent | TAVfp@tencent.com |
| TheHacker | virus@hacksoft.com.pe, falsopositivo@hacksoft.com.pe |
| thirtyseven4 | analyze@thirtyseven4.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Trapmine | fp@trapmine.com |
| TrendMicro | https://www.trendmicro.com/en_us/about/legal/detection-reevaluation.html virus@trendmicro.com, virus_doctor@trendmicro.com http://esupport.trendmicro.com/solution/en-us/1037634.aspx |
| Trojan Remover/Simply Super Software | support@simplysup.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Trustlook | bd@trustlook.com |
| TrustPort | support@trustport.com?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| Trustwave | ADavidi@trustwave.com |
| Untangle | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Immunet_Protect |
| VBA32 | feedback@anti-virus.by |
| Verizon Internet Security | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#McAfee |
| VIPRE | https://www.vipre.com/support/submit-false-positive/ |
| Vipre/Sunbelt/Threattrack | https://www.vipreantivirus.com/support/submissions/false-positive.aspx |
| Vir.IT | http://www.tgsoft.it/english/file_sospetti_eng.asp |
| VirIT | https://www.tgsoft.it/clienti/inviaFile.asp |
| ViRobot | viruslab@hauri.co.kr |
| VirusBlokAda/VBA32 | feedback@anti-virus.by?subject=False%20Positive%20Submission&body=The%20sample%20is%20in%20a%20password%20protected%20zip%20file%0A%0AThe%20password%20for%20the%20attachment%20is%20infected |
| VirusDie | partners@virusdie.com |
| VIRUSfighter | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Sophos |
| Webroot | https://www.webroot.com/us/en/business/support/vendor-dispute-contact-us https://www.webrootanywhere.com/servicewelcome.asp |
| Xvirus | http://xvirus.net/submit.html |
| Yandex | yandex-antivir@support.yandex.ru |
| Yomi | yomi-false-positives@yoroi.company |
| Zemana | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Emsisoft https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#G_Data https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Ikarus https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Dr._Web |
| Zillya | virus@zillya.com antivirus@zillya.com |
| ZoneAlarm | zonealarm_VT_reports@checkpoint.com https://opentip.kaspersky.com/ |
| ZoneAlarm/Check Point | https://www.techsupportalert.com/how-to-report-malware-or-false-positives-to-multiple-antivirus-vendors/#Kaspersky |
| Zoner | false@zonerantivirus.com |
How to Remove a False Positive From Popular Antivirus Vendors
Each antivirus and blacklist service has its own process for clearing a false detection. Here are the ones people ask about most:
Gridinsoft False Positive
If Gridinsoft Anti-Malware is flagging your website or file by mistake, submit it for re-review through Gridinsoft’s official false-detection form at anti-malware.gridinsoft.com/false-detect/. Include your URL and the exact detection name so their team can clear the Gridinsoft false positive quickly.
VIPRE False Positive
To report a VIPRE false positive, use VIPRE’s submission form at vipre.com/support/submit-false-positive/ and provide the flagged URL or file so it can be re-evaluated.
AegisLab Blacklist Removal
For an AegisLab false positive or blacklist removal, email support@aegislab.com with your site URL and the detection details to request delisting.
Not sure if it is really a false positive? Sometimes the warning is real. If your site is genuinely infected, DrGlenn offers fast, expert WordPress malware removal — read client reviews or order a cleanup to get your site clean and delisted.
Not a False Positive? Your Site May Really Be Hacked.
If the warning is real and your WordPress site is infected, you do not have to fight it alone. DrGlenn removes real malware, clears the blacklist, and hardens your site so it does not happen again.