I think it's coming from something on the user's computer because there's nothing in the threads at all.
That's possible, as the images were the same that the POS sent in PMs. It generated a Russian re-direct address which I copied, but lost as I quickly rebooted before saving it.
I hope the POS dies a horrible death involving pliers, bamboo and HV electrodes.
This problem seems to originate from users clicking on links in Private Messages, which then has infected the users computer.
I've never had PMs that did that and I still got that link redirection when clicking on a forum. I don't think it's caused by PMs and I'm pretty sure it's not a virus or trojan. Sounds more like users links are being redirected to that russian site with some something embedded in a thread or the site.
Since the last time, I have begun using VM image to access this site. Very easy to set up (either windows or linux), keep it simple (no attached drives, etc) and if it gets hit, just delete the image and start anew.
It's not worth the trouble becoming a accidental voyeur to cold's delusion's.
(BTW, I hope the authorities have been on this and not taking their sweet ass time.)