The malware in question is PHP/Small.C and PHP/Loader.9852, both scanned here"
hxtp://vscan.urlvoid.com/analysis/86f409382dec5b861f8cd13b87cae2a5/amMtanBn/
the link scan flags PHP:Shell-AS [Trj]
and the avast Web Shield scanner on hxtp://gala-tiefbau-podlesch.de/cache/.etc/9991.jpg?? flags: {HP.PBot-U[Trj]
and on htxp://gala-tiefbau-podlesch.de/cache/.etc/jc.jpg?? the avast Web Shield flags PHO;Shell-AS[Trj]
polonus