See: http://evuln.com/tools/malware-scanner/www.annudroit.eu/
Web application version:
Joomla Version 1.0.12 to 1.0.15 for: htxp://www.annudroit.eu/mambots/editors/tinymce/jscripts/tiny_mce/plugins/flash/editor_plugin.js
Joomla version outdated: Upgrade required.
http://sitecheck.sucuri.net/results/www.annudroit.eu
Suspicious domain detected: Location: htxp://Location: htxp://new.wikaba.com
URL resolves to a invalid IP address (new.wikaba.com).
Was here: http://www.senderbase.org/senderbase_queries.detailip?search_string=204.16.173.15
Might have been taken down: http://evuln.com/labs/new.wikaba.com/
Read more about this auto malware iframe in Joomla 25 here: http://forum.joomla.org/viewtopic.php?f=615&t=786814 (poster radat)
Also interesting to look at for Joomla users: http://docs.joomla.org/Vulnerable_Extensions_List#Kunena
polonus