Hi spg SCOTT,

Thank you for that additional information but most of the malware that resided there with no response now, so dead, it had two unknown executables and an some EXP/Pidief.W malware.
in resp.

-http://213.182.197.42/swf.php,
-http://213.182.197.42/load.php,
-http://213.182.197.42/pdf.php

also see: http://www.spamhaus.org/sbl/sbl.lasso?query=SBL75831

polonus