Is this an undetected Virut alias aka variant of Win32/FlyStudio?
A variant of Win32.FlyStudio application is a broad category of malicious software that can include adware, spyware, viruses, trojans, backdoors, and worms. All of these programs are designed to thwart computer security and force unwanted system behavior, activities, or damage.
See: https://www.virustotal.com/nl/url/b01d2e9a6b728b51704526e073b41ec75a57cb1bbdd909ba25c5d61b82bc651b/analysis/1416059152/
and
https://www.virustotal.com/nl/file/ce9a85b1c691e9517181b67c84b5114a9457d57577626c79b5b37aa25c67c5bb/analysis/1416046670/
Listed and flagged here: http://urlquery.net/report.php?id=1416003033789
Also consider here the IDS alerts here: Recent reports on same IP/ASN/Domain
polonus
Last 6 reports on IP: 123.57.37.211 IDS for “ET POLICY Unsupported/Fake Windows NT Version 5.0”, just faking UA’s without much 8)