I saw at least one of the websites that hosts this malware was posted on here, so I thought I'd pull together a quick laundry list of related hosts/domains.
onlinevideosoftex.com
onlinesoftwarexchange.net
softwaredestributiononlinecorp.com
globalsoftwareagreement.com
ieantiavdownload.com
malwarebellagreement.com
ieantivirus.com
files-secure.com
"drv32.data" is typically the same or a similar piece of malware that is generally grabbed to make sure the trojan is up-to-date. The following URLs serve drv32.data:
hxxp://58.65.238.34/drv32.data
hxxp://onlinevideosoftex.com/drv32.data
hxxp://onlinesoftwarexchange.net/drv32.data
hxxp://softwaredestributiononlinecorp.com/drv32.data
hxxp://78.129.166.25/drv32.data
hxxp://globalsoftwareagreement.com/drv32.data
hxxp://ieantiavdownload.com/drv32.data
hxxp://malwarebellagreement.com/drv32.data
Some longer paths to the same or similar files:
hxxp://ieantivirus.com/download.php -> hxxp://ieantiavdownload.com/ieav.exe = hxxp://ieantiavdownload.com/drv32.data
hxxp://files-secure.com/d.php -> hxxp://malwarebellagreement.com/mb.exe
These hosts are primarily spread out over these IPs:
78.129.158.225
78.129.166.25
78.129.166.35
89.149.227.195
There are some other related domains for the affiliate program such as:
stable2.com
ruler-cash.com
spy-partners.com
These things are spread in a number of ways. Many of them involve a fake video codec error. Others attempt to sell products or memberships to sites music, pornography, etc.