The problem was an external link to: GET /1905253.js HTTP/1.1
Host: js dot users dot 51dot la going to 117.21.191.223
Check whether that external link is still there!
Seems that malcode has been closed, according to http://support.clean-mx.de/clean-mx/viruses.php?review=117.21.227.34&sort=first%20desc
But links to 117.21.191.223 could mean trouble for the future because of insecurities and badness history on IP and for that specific domain.
This from there still alive and kicking malcode: https://www.virustotal.com/nl/file/e354be86cf91d2a81f817a56ecffd199f84f5a789afe1c1a0f8b86df28dacc38/analysis/
or this one: https://www.virustotal.com/nl/file/e9985f40da420533f1cf0bf5ceeb6a086a693b0cfbfa57a1eb706e5c6acdff39/analysis/
Badness history of IP: https://www.virustotal.com/nl/ip-address/117.21.191.223/information/
Badness history of external link domain: https://www.virustotal.com/nl/domain/js.users.51.la/information/
polonus