Unknown html or false positive, avast! Webshield blocks!

Given clean here: http://sitecheck.sucuri.net/results/78136.beatsmy.com/#sitecheck-details
Two solutions flag here: https://www.virustotal.com/nl/url/5d34202506b8a1598d78ce9be4ad26e4f18881c0a9603f0a3918c87098ae675b/analysis/1406140996/
see: http://linkeddata.informatik.hu-berlin.de/uridbg/index.php?url=78136.beatsmy.com&useragentheader=&acceptheader=
I get: 78136.beatsmy.com,192.200.206.93,Parked/expired,
Errors and warnings here: https://asafaweb.com/Scan?Url=78136.beatsmy.com
Excessive header info proliferation: Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET, PHP/5.2.17
X-AspNet-Version: 1.1.4322
See: http://fetch.scritch.org/%2Bfetch/?url=78136.beatsmy.com&useragent=Fetch+useragent&accept_encoding=
This uri is being blocked by avast as with URL:Mal: htxp://78136.beatsmy.com/style/default/images/banner.jpg

So we are being protected, folks, while Sucuri missed the banner malcode.

polonus

html scan
https://www.virustotal.com/nb/file/579532bae69682ad8fceef5d7fbe8bc35ea9492ee874a85b805cd988a92144a3/analysis/1406141634/

killmalware http://killmalware.com/78136.beatsmy.com/

detection correct, confirmed by Norman/BlueCoat lab 78136.beatsmy.com.htm: Script.BG

Hi Pondus,

Thank you for confirming. Malvertised banners are always an item to be on the look-out for, even Zeus now can infest via banner malcode.
So banners on a site should always be checked whether they do not come with an unsuspected payload.
Read from link author Lenny Zeltser here: http://www.infosecisland.com/blogview/14371-Malvertising-The-Use-of-Malicious-Ads-to-Install-Malware.html

polonus