(The IP address) was last detected at 2015-02-22 03:00 GMT (+/- 30 minutes), approximately 4 days, 22 hours, 30 minutes ago.
This IP address is infected with, or is NATting for a machine infected with Torpig, also known by Symantec as Anserin.
If you are running a newer Windows operating system, Torpig has been likely dropped by a second Trojan such as Andromeda/Gamarue or similar malware droppers.
With Mebroot or any other rootkit that installs itself into the MBR, you will either have to use a “MBR cleaner” or reformat the drive completely - even if you manage to remove Torpig, the MBR infection will cause it to be reinfected again.
The best way to find the machine responsible for this listing is to look for connections to the Torpig C&C sinkhole. This detection was made through a connection to “108.61.18.43” on port “80” TCP. This detection corresponds to a connection at 2015-02-22 03:14:06 (GMT - this timestamp is believed accurate to within one second).
You can try Kaspersky’s TDSSKiller Antirootkit Utility to get this infection detected/removed. However, we strongly recommend you to do completely re-install your operation system to get this infection removed permanently.
These infections are rated as a “severe threat” by Microsoft. It is a trojan downloader, and can download and execute ANY software on the infected computer.
You will need to find and eradicate the infection before delisting the IP address.
Hoping for a little help.
Logs attached