What is unknown_file_$COMMON_APPDATA/Common/LuaRT/wlua.exe?

See: https://www.virustotal.com/en/url/c0202db794f9960ffd8e9d74c70535b3aa3d157858b4d8c6754c747bc5600e12/analysis/1368701048/
2 detections
Consider: https://www.virustotal.com/en/ip-address/46.28.209.34/information/
File seems safe: http://www.isthisfilesafe.com/sha1/42C54EBEBB83B372C44D4EF3B9A281D5EB889C08_details.aspx
also see: http://support.clean-mx.de/clean-mx/viruses.php?id=9916356
TrendMicro detects as TrendMicro-HouseCall TROJ_GEN.F47V0329 and Symantic as WS.Reputation.1

WS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec’s community of users and therefore are likely to be security risks. Detections of this type are based on Symantec’s reputation-based security technology. Because this detection is based on a reputation score, it does not represent a specific class of threat like adware or spyware, but instead applies to all threat categories.

The reputation-based system uses “the wisdom of crowds” (Symantec’s tens of millions of end users) connected to cloud-based intelligence to compute a reputation score for an application, and in the process identify malicious software in an entirely new way beyond traditional signatures and behavior-based detection techniques.

(Quote taken from link → http://community.norton.com/t5/Norton-Internet-Security-Norton/Clarification-on-WS-Reputation-1-detection/td-p/232155
link author = Tony Weiss Norton Forums Global Community Manager).

polonus

And another pup detection: https://www.virustotal.com/en/url/276ccfff99d76d375d463c03da94d614c5a79e32c818ef63207d702bec2f1d67/analysis/1368702123/
See: http://www.scumware.org/report/222.186.13.107
= Win32/FlyStudio potentially unwanted application

polonus

For https://www.virustotal.com/en/url/c0202db794f9960ffd8e9d74c70535b3aa3d157858b4d8c6754c747bc5600e12/analysis/1368701048/
I aslo scanned for an Anubis analtsis: http://anubis.iseclab.org/?action=result&task_id=14cbe0812a17b848465185cbd1f7fe73c&format=html#chapter1
See what it does with IE’s security settings described here: http://technet.microsoft.com/en-us/library/bb463181.aspx
http://technet.microsoft.com/en-us/library/bb463181.aspx (is added by the installation of third party software).
MSCTF.Shared.MUTEX.IFG. typical in malbot Tracker finds

polonus