Unknown google malware loading code from a blacklisted domain!

Suspicious Javascript check:
Suspicious
ascript" src="http://b.kavanga.ru/exp?sid=6941&bt=5&bn=1&bc=3&ct=2&pr=’ + math.round(math.random()*100000) + ‘&pt=b&pd=’ + addate.getdate() + ‘&pw=’ + addate.getday() + ‘&pv=’ + ad…
See: https://www.virustotal.com/nl/url/7d516a3ae1a0fa692788f97377d97187f70d01a12f32bc76431c9923a0f0812c/analysis/1415197189/
See: http://antivirus-alarm.ru/proverka/?url=www.fayloobmennik.net
ISSUE DETECTED DEFINITION INFECTED URL
Website Malware malware-entry-mwblacklisted35 htxp://www.fayloobmennik.net
Website Malware malware-entry-mwblacklisted35 htxp://www.fayloobmennik.net/404testpage4525d2fdc
Website Malware malware-entry-mwblacklisted35 htxp://www.fayloobmennik.net/uploadmanager.html
Website Malware malware-entry-mwblacklisted35 htxp://www.fayloobmennik.net/faq.html
Website Malware malware-entry-mwblacklisted35 htxp://www.fayloobmennik.net/public/news.html
Suspicious domain detected. Details: http://sucuri.net/malware/malware-entry-mwblacklisted35
document.write(‘’);

System Details:
Running on: Apache/2.2.22
Powered by: PHP/5.4.6-1ubuntu1.8
Outdated Web Server Apache Found: Apache/2.2.22

js/jquery.dd.js
Severity: Potentially Suspicious
Reason: Detected potentially suspicious content.
Details: Detected potentially suspicious initialization of function pointer to JavaScript method eval __tmpvar900873540 = eval;
Threat dump: http://jsunpack.jeek.org/?report=debd8aea0a7d368b3b6b656c4a4b5a4e9559beb2
Threat dump MD5: D6FA56768F872C24050625599774AB1B
File size[byte]: 13011
File type: ASCII
Page/File MD5: 93051B8855B609D89ED37D08D3F080A2
Scan duration[sec]: 0.531000

Abuse Address does not accept at abuseATfayloobmennik.net
: http://www.dnsinspect.com/fayloobmennik.net/1415197619

external link would not resolve: The requested URL /  -->  ‘фотохостинг’ was not found on this server.

Apache/2.2.22 (Ubuntu) Server at wXw.fotolink.su Port 80

pol

Update the adware seemingly still there: https://www.mywot.com/en/scorecard/b.kavanga.ru?utm_source=addon&utm_content=popup
malware details, blacklisted at Sucuri’s: http://labs.sucuri.net/?details=b.kavanga.ru
Page blocked by Dr.Web Link Checker

Dr.Web has blocked following the advertising link to ensure your privacy. If you still want to follow this link, click the «Open incognito»button, in this case the link will be opened in incognito mode in your browser. If you do not want to receive such warnings, you can change the lock level settings Dr.Web Link Checker.

polonus