Found to be here: datatesttools.in/New-Video-Addon.48563.exe See: http://www.virustotal.com/url-scan/report.html?id=e48ba42d53cdc558b17b32f8a4f0ab82-1302605289 and http://wepawet.iseclab.org/view.php?hash=e48ba42d53cdc558b17b32f8a4f0ab82&t=1302512038&type=js also accompanying Anubis report: http://anubis.iseclab.org/?action=result&task_id=1e84deb01c1f4719401c4744bf790ebf5
an older version of this malware was detected by 11% of the scanners at http://virscan.org/report/5137b9555d254c68b2010bc9f4be6560.html as Mal/FakeAV-CX also see this http://www.prevx.com/filenames/751568666640838057-X1/NEW-VIDEO-ADDON.48134.EXE.html found W32FakeAlert.IV.gen!Eldorado also discussed here: http://forum.malekal.com/trojan-renos-trojan-fakealert-dropper-t26785-615.html
Have sent this info to virus AT avast dot com for evaluation,
polonus
Scan yesterday
VirusTotal - 12/42 http://www.virustotal.com/file-scan/report.html?id=4d219b50d41b5d403b31cbf5993259e95130323ac65b312f9ff64e4e9b182c23-1302511731