Oops.. it wasn't my intention to lead people to virus infected sites. I understand why the URL was removed from my post, and I agree to it. I suggest we keep it this way until we have figured out what is going on here (e.g. until the virus is removed from the site).
WARNING: other links on orbiter-forum.com (and on other Orbiter community sites) link to the same website! You can find another example in this very same thread!
Does anyone know whether the virus on the site targets Linux machines? I know most virus writers aren't interested in targeting Linux, and I keep my Firefox up-to-date, but I also know Linux isn't invulnerable.
I found information about "Trojan.Malscript.B" that it redirects the browser to another site with potentially harmful content, presenting it as fake anti-virus software. Also, virus scanners use 'heuristics' to detect it, so this could be a false positive.
Maybe (I'm just guessing here) it was triggered by the 'av' in the domain name, which sounds like 'antivirus'? Google suggests that 'frieslandav' stands for Friesland Audio/Video. AFAIK, McDuck lives in Friesland, so maybe he is connected to the Friesland AV company.
I couldn't find useful information on JS:Illredir-C [Trj]. Maybe it's another name for the same thing?
If I can find the time, I think I'm going to do some HTML/JS 'hacking'. Trying to be smarter than the virus...