Hi chertenok,
The now closed malware came from IP 176.9.118.22, also hosting hxtp://load-rar2.ru/ via which domain malware has been launched. Skodna.ArchSMS.P stayed active for 159.8 hrs before it was killed, and Win32:Malware-gen stayed on for 74.8 hrs.
Your site seems to be secure. You could remove the "X-Powered-By" HTTP Header, which gives away that content is being generated dynamically.
Spamcheck and Safebrowsing secure. Web rep:
http://www.webutation.net/go/review/kit-iphone.ruIf you experience new blocks because of the hosting server being abused,
you could reconsider hosting your site somewhere else, but that is up to you.
The AS has 3098 blacklisted URLs, re:
http://sitevet.com/db/asn/AS24940From your side on everything seems hunky-dory,
polonus