See: http://www.virustotal.com/url-scan/report.html?id=b9069a50a29eb0e636e2b833c5e49b42-1303139678
See: htxp://jsunpack.jeek.org/dec/go?report=dcfdc6a32f646217018db6664add78946b2afbfc *
(go there only if security aware, sandboxed and with full script protection in browser)
detection, see: http://www.virustotal.com/file-scan/report.html?id=fd3aa2bd89191f3b750d6d842046e7abccb3e77692f042e1c5f9de8bb7188220-1303146880 5 /42 (11.9%)
Not detected here: http://wepawet.iseclab.org/view.php?hash=b9069a50a29eb0e636e2b833c5e49b42&t=1303147181&type=js
and here:
http://www.garyshood.com/virus/results.php?r=096c525658e27e6e191377e54c2949d7
Filesize 901 bytes linked to "hxtp://www.arama1.tk * associated with cloaked malware:
http://info.prevx.com/aboutprogramtext.asp?PX5=21D82879298B84628B6900ED1508AC0068BCD349
mailed to virus AT avast dot com
polonus