See: http://urlquery.net/report.php?id=111323 has MSIL/Solimba.C application
See: http://zulu.zscaler.com/submission/show/2292c7999fe8555d6ad7f962aa8e6e3c-1343909740
See: http://www.scumware.org/report/d3uetqjthbb4x1.cloudfront.net
More from that address: >htxp://d2z2aknbd2eebd.cloudfront.net/2.1.816/2630354/gps%20utility.exe/dmgr.exe contains an advertising software Adware.Downware.349 redirecting to:
http://d2z2aknbd2eebd.cloudfront.net/2.1.816/2629465/google%20earth.exe/dmgr.exe contains an advertising software Adware.Downware.349
htxp://d2z2aknbd2eebd.cloudfront.net/2.1.816/2625284/mu%20online.exe/dmgr.exe contains an advertising software Adware.Downware.349
and many more, see on http://badmalweb.com/?p=live
This search from one of the IPs used: htxp://www.google.nl/search?hl=nl&output=search&sclient=psy-ab&q=http%3A%2F%2Fderkfheewe.tk%2F98765.pdf&btnK=
is being blocked by avast Web Shield as leading to JS:ScriptPE-inf[Trj] also see: http://urlquery.net/report.php?id=95279 (and IDS alerts),
polonus