Avast found the malware to be Win32:Akan, see: htxp://vscan.urlvoid.com/analysis/6f08a80787e4c7abe12698fa444c88a0/MS1leGU=/
1.ex- is packed by FLY-CODE;
Also see: hxtp://urlquery.net/queued.php?id=26339
Great avast has detection for this, see also the analysis: htxp://anubis.iseclab.org/?action=result&task_id=15e97498467265df401a9ad098b897696&format=html
polonus