Malicious defacement detected by Avast as infested with JS:Iframe-XL [Trj]

Defacement going on for 8 days, now known as 48 hrs ago infested, as was 1 sec.ago.
See: https://www.virustotal.com/nl/url/0fd96e0668e2c9ce12683f47ab1521036c8af7f9e37f41fcfd002925235bc664/analysis/
and https://sitecheck.sucuri.net/results/www.littlelightfilms.com
efacement MW:DEFACED:01 htxp://www.littlelightfilms.com
Defacement MW:DEFACED:01 http://www.littlelightfilms.com/404javascript.js
Web site defaced. Details: http://sucuri.net/malware/entry/MW:DEFACED:01


<title>---==[ Hacked By MoHaMaD VakeR ]==---</title><link rel="shortcut icon" href="htxp://sole-sad.persiangig.com/image/peace-and-love.jpg" /><body text="#000000" bgcolor="#000000"><center><style type="text/css">#sole {  font: 60px impact;  color:#0f0;  </style><table height=100% width=100%><td align=center><table height=100% width=100%><td align=center>

https://yandex.com/infected?
l10n=en&url=www.littlelightfilms.com&redircnt=1438275975.1
See for detection: http://killmalware.com/littlelightfilms.com/

Blocked for me inside Google Chrome by uMatrix: uMatrix has prevented the following page from loading:
htxp://www.littlelightfilms.com/

polonus

html scan
https://www.virustotal.com/en/file/a09313daa8c827a840aaaa6925d34cbdbf5f094e5fd2e584f96203f3599742de/analysis/1438276523/

Hi Pondus,

This is why I put these scan results fot defacements as Virustotal seems to keep missing them.
I now only get suspicious results for that scan.
There still is this"
Website blacklisted by Yandex.
Defacement check: ext/html —==[ hacked by mohamad vaker ]==—<link rel=“shortcut icon” href="htxp://sole-sad.pers…
Side wide check: Suspicious

eu5mvdz2hw0m3aew1zxzrsnqtn-a">hacked by mohamad vaker

<

But the chunk of code delivering the JS:Iframe-XL[Trj} that still was there a couple of hours ago, now seems cleansed.

polonus