GW2 main page (not forum) contains a call to page at address d.xp1.ru4.com. This address redirects to xplusone.com
This is a known address silently distributing malware according to Google, OpenDNS, WoT.
proof:
http://img13.imageshack.us/img13/6327/malware1.png
This is what Google has to say about the domain:
http://www.google.com/safebrowsing/diagnostic?site=AS:53563
quote: "Of the 5 site(s) we tested on this network over the past 90 days, 1 site(s), including, for example, xplusone.com/, served content that resulted in malicious software being downloaded and installed without user consent.
The last time Google tested a site on this network was on 2012-12-28, and the last time suspicious content was found was on 2012-12-28."
:edited to better hide my lack of good manners
