download/v924?product_namehappilyeverafter.ex- detected as PUP!

avast! detects: https://www.virustotal.com/nl/file/004ae52890468783608d9ca270356d28f390ef54e599a181f5e5382ce8048f2b/analysis/1389538247/
file comes from: https://www.virustotal.com/nl/url/fe2c83ec48a6b3ea384b0377be818369362d48f2d3acba3f9dc98025e9d536cb/analysis/1389538242/
DrWeb’s URL checker flags it twice as blacklisted and as Adware.
htxp://www.zilliontoolkitusa.info/download/v924?product_namehappilyeverafter.exe is in Dr.Web malicious sites list!
htxp://www.zilliontoolkitusa.info/download/v924?product_namehappilyeverafter.exe contains an advertising software Adware.Downware.1541
IDS alerted here with two instances: http://urlquery.net/report.php?id=8789829 (unknown.ex-)

polonus

is does not show on VT, but also Detected by Norman as PUA (possible Unwanted Apllication) Installer.Rex.H

v924?product_namehappilyeverafter.exe