http://ellib.gpntb.ru/subscribe/web.php
http://220.135.213.248/aspnet_client/system_web/JAVA/index.htm
this is a trojan/Downloader, which after being run downloads files from:
http://www.neslhk.com/fotogalerie/images/writable_false_up.gif (89.187.133.101)
http://ellib.gpntb.ru/subscribe/array.gif
http://ellib.gpntb.ru/subscribe/corporate.gif