unknown_html_RFI_shell malware on site, but what?

What = Trojan.HTML.Agent.GD and alas avast does not detect!
This is a FraudTool and may frequently pop up advertising messages to interrupt computer users and slow down computer fuction,
the malware might be cleansed from the registry by a qualified removal expert.

Nothing at the moment: http://urlquery.net/report.php?id=7042585
2 detect: https://www.virustotal.com/nl/url/abe945415e5dba1f1f3b3ffe3aa1ccd198028811f8dc90940c58674c0b3aa0c0/analysis/
and here 7: https://www.virustotal.com/nl/file/1c118a6a857419b859682d3457c4251183dad3e6b6a5dabaadb832c806e91c96/analysis/
Well some reasons for suspicion: http://www.mywot.com/en/scorecard/sulaiman.itgo.com
Sucuri comes up with: Unable to properly scan your site. Site returning error (40x): HTTP/1.1 404 Not Found
On the same IP domain exploit kit was found: http://urlquery.net/report.php?id=4257779
ET CURRENT_EVENTS Embedded Open Type Font file .eot seeing at Popads Exploit Kit
and various other issues: https://www.virustotal.com/nl/ip-address/64.136.20.41/information/
understandably so, because of this 339 sites on one and the same IP: http://sameid.net/ip/64.136.20.41/
quite some up and alive according to: http://support.clean-mx.de/clean-mx/viruses.php?review=64.136.20.41&sort=id%20DESC

pol

This could be a newer variant of Popads Exploit Kit: http://doc.emergingthreats.net/bin/view/Main/2016065 → Magnitude EK
exploit abused: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2551 (also java exploits)
The specific researcher for this type of malcode is “kafeine” → https://twitter.com/kafeine/status/387027354293264385
also see contributions here: http://www.malwaresigs.com/?s=popads & http://www.malwaresigs.com/2013/06/14/dotcachef/
& http://www.malwaresigs.com/?s=popads links author = Kuluoz

polonus