New scan:

Malware Scanner report for myfifthclass.ucoz.ru

Malicious/Suspicious/Total urls checked
6/0/16
6 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/6
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://myfifthclass.ucoz.ru/news/2011-02-17
200 OK
Content-Length: 28008
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://s105.ucoz.net/src/jquery-1.7.2.js
200 OK
Content-Length: 94840
Content-Type: text/javascript
clean
http://s105.ucoz.net/src/ulightbox/ulightbox.js
200 OK
Content-Length: 22097
Content-Type: text/javascript
clean
http://s105.ucoz.net/src/uwnd.js?2
200 OK
Content-Length: 228554
Content-Type: text/javascript
clean
http://myfifthclass.ucoz.ru/widget/?44;650|300|0
200 OK
Content-Length: 812
Content-Type: text/javascript
clean
http://myfifthclass.ucoz.ru/news/rss/
200 OK
Content-Length: 27767
Content-Type: text/xml
clean
http://myfifthclass.ucoz.ru/test404page.js
404 Not Found
Content-Length: 6869
Content-Type: text/html
clean
http://myfifthclass.ucoz.ru/
200 OK
Content-Length: 43892
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://myfifthclass.ucoz.ru/register
200 OK
Content-Length: 30054
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://myfifthclass.ucoz.ru/photo
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Connection: close
Date: Thu, 23 Jul 2015 12:36:03 GMT
Location: http://myfifthclass.ucoz.ru/photo/
Server: uServ/3.2.2
Content-Type: application/octet-stream
Set-Cookie: 0myfifthclassuCoz=; path=/; expires=Tue, 23-Jul-2013 12:36:03 GMT; domain=.myfifthclass.ucoz.ru;
clean
http://myfifthclass.ucoz.ru/photo/
200 OK
Content-Length: 41971
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://s105.ucoz.net/src/photopage.js
200 OK
Content-Length: 18520
Content-Type: text/javascript
clean
http://s105.ucoz.net/src/entriesList.js
200 OK
Content-Length: 639
Content-Type: text/javascript
clean
http://myfifthclass.ucoz.ru/photo/rss/
200 OK
Content-Length: 6680
Content-Type: text/xml
clean
http://myfifthclass.ucoz.ru/index/video_programmy_galileo/0-6
200 OK
Content-Length: 33916
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC

http://myfifthclass.ucoz.ru/photo/my/3
200 OK
Content-Length: 62114
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

<!--
function Decode(){var temp="",i,c=0,out="";var str="60!97!32!116!97!114!103!101!116!61!34!95!98!108!97!110!107!34!32!104!114!101!102!61!34!104!116!116!112!58!47!47!103!97!109!101!110!101!119!46!110!101!116!46!114!117!47!34!62!60!105!109!103!32!115!114!99!61!34!104!116!116!112!58!47!47!111!114!97!110!103!101!98!111!120!46!109!111!121!46!115!117!47!95!108!100!47!48!47!53!50!46!112!110!103!34!62!60!47!97!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++;out=out+String.fromCharCode(temp);temp="";}document.write(out);}

Antivirus reports:

AntiVir
HTML/IFrame.adh
Avast
JS:Iframe-AMU [Trj]
nProtect
Trojan.JS.Agent.ENC
K7AntiVirus
Riskware
Emsisoft
Trojan.JS.Agent.ENC (B)
Comodo
TrojWare.JS.Agent.jg
DrWeb
SCRIPT.Virus
Kaspersky
HEUR:Trojan.Script.Iframer
Microsoft
VirTool:JS/Obfuscator.CC
Jiangmin
Trojan/Script.Gen
F-Secure
Trojan.JS.Agent.ENC
VIPRE
Trojan-Clicker.HTML.IFrame.fh (v)
F-Prot
JS/Dccrypt.H.gen
AVG
HTML/Framer
GData
Trojan.JS.Agent.ENC
Commtouch
JS/Dccrypt.H.gen
ESET-NOD32
JS/Kryptik.BP
BitDefender
Trojan.JS.Agent.ENC


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: myfifthclass.ucoz.ru

Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Cache-Control: no-store
Cache-Control: private
Connection: close
Date: Thu, 23 Jul 2015 12:36:01 GMT
Pragma: no-cache
Server: uServ/3.2.2
Content-Type: text/html; charset=UTF-8
Set-Cookie: 0myfifthclassuCoz=; path=/; expires=Tue, 23-Jul-2013 12:36:01 GMT; domain=.myfifthclass.ucoz.ru;
Set-Cookie: 0myfifthclassuzll=1437654961; path=/; expires=Fri, 22-Jul-2016 12:36:01 GMT; domain=.myfifthclass.ucoz.ru;
Set-Cookie: 0myfifthclassuCoz=; path=/; expires=Tue, 23-Jul-2013 12:36:01 GMT; domain=.myfifthclass.ucoz.ru;
Second query (visit from search engine):
GET / HTTP/1.1
Host: myfifthclass.ucoz.ru
Referer: http://www.google.com/search?q=myfifthclass.ucoz.ru

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=myfifthclass.ucoz.ru

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://myfifthclass.ucoz.ru/

Result: myfifthclass.ucoz.ru is not infected or malware details are not published yet.