See: https://www.virustotal.com/nl/url/03ecebad513f291373f02193292fe8e450345efe1e44d019bced14230d35b8a6/analysis/1422812529/
Suspicious file: www.jscripts.org/ncontrol.php?cid=3515&ext=offerswizard&s1=8ae23c009edb0b1a2ed0d1aea7f9e480
Severity: Suspicious
Reason: Detected encoded JavaScript code commonly used to hide suspicious behaviour.
Details: Generic suspicious HEX encoder
Offset: 202
Threat dump: View code hex code translates to offers dot byc
Read on malware pop-up ad infection: http://malwaretips.com/blogs/remove-offers-by-context-com/
Threat dump MD5: 35D25B8DED3F8AEA50B0446BD5B00E03
File size[byte]: 6003
File type: ASCII
Page/File MD5: 4245FB945FCD47E0635746AC5974C7A0
Scan duration[sec]: 0.006000
Phish: http://safeweb.norton.com/report/show?url=naptienthe.net
polonus