See: https://www.virustotal.com/nl/url/cc8fc6753ab9a0447b9e14cf6a6a1c5fb64b697b71d96c104c616f7a4b401fd8/analysis/1425563761/
Had malware here: http://urlquery.net/report.php?id=1425338934705
from -go.oclaserver.com/apu.php?zoneid=64720
Not vulnerable here: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fgallerynova.se%2Fdemo%2Findex
But for the now cleansed malware link: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fgo.oclaserver.com%2Fapu.php%3Fzoneid%3D64720
See: https://www.virustotal.com/nl/ip-address/78.140.191.72/information/
http://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
This detected: http://www.herdprotect.com/domain-ad.propellerads.com.aspx
See my tracker tracker analysis attached / first row.
Avast PUP detection flags this as Win32:Amonetize-DJ [PUP].
polonus