The malware comes from here: hxtp://classicomobile.com/shops/images/images/atual=iToken.php
Scanned against virustotal here: http://www.virustotal.com/url-scan/report.html?id=45c2bc4c591be6eb0f82c44bb4f51969-1300493926
Detection rate 13 /42 (31.0%): http://www.virustotal.com/file-scan/report.html?id=de7e311f1d0cf57b80cbb4baf07798e8587079d2a922f7dcc58d27e6380cb699-1300542572
W32SelfStarterInternetTrojan!Maximus
See: htxp://jsunpack.jeek.org/dec/go?report=98560bb42714e11e4e088ca4b2ffd9dd62b56b98
See malware download in malzilla attached:
Also see wepawet scan: http://wepawet.iseclab.org/view.php?hash=45c2bc4c591be6eb0f82c44bb4f51969&t=1300546154&type=js
Anubis report: http://anubis.iseclab.org/?action=result&task_id=1973aa51309f28124550db73888d67c74
detected is Trojan.Banker.Itau (Sig-Id:1468303), source: Ikarus
polonus