If the site/server was hacked then anything could be installed. Doing a quick scan of your source I don't see any of the common ones however. Any particular page they receive the malware warnings?

On the second one, any idea what browser?