The javascript mentioned is being described here as URLs and sub domains distributing the malware or acting as a redirector:
Read: http://labs.sucuri.net/?details=www.liveinternet.ru
But blacklist status has been removed: http://labs.sucuri.net/?blacklist=www.liveinternet.ru
pol