I found it (not through reloading, just by scouring and blanket emailing all ad partners) and have contacted the provider. They found it (they believe) and think they've completely purged it from the system. These changes sometimes take a couple hours to propagate, so let's say that if anyone sees a new browser window pop for mediaplayer-download888.net (does that look right, colo?) after 3pm ET, please let me know here ASAP. Sounds like it was set (by the slimebags responsible for it) to show to a VERY small portion of the population, and very rarely at that. So I hope and expect it won't be a problem between now and when it's gone (and it's possible it's gone already).
The good news is this appears to have been a headache rather than a threat. That domain pings clean at Sucuri, Google, Norton, and SiteAdvisor. Doesn't mean it wasn't trying to do something bad, just means that if it was then it likely would have taken more than just visiting it.
Thanks for the report!