See: htxp://112.185.254.215/loader/cclub11.exe unknown execuletable?
Re: https://www.virustotal.com/en-gb/url/684904e4debed1d98f7944b04a4f769be4f1262f3d354a2d05c9ed4c7d9ffc99/analysis/1434308828/
Consider: http://7feeds.com/listfeed-malc0de.com_el_rss_el_-1401884028
Malware - detected → http://urlquery.net/report.php?id=1434308949312 → application/octet-stream
Quttera → Quttera Labs - domain is Malicious.
Site risk 9 red out of 10: http://toolbar.netcraft.com/site_report?url=http%3A%2F%2F112.185.254.215
It is a Zusy variant Avast should detect as Win32:Malware-gen!
polonus