The virus has signed to <removed> as TR/Proxy.gen
/applications/core/interface/file/attachment.php?id=19825" data-fileExt='zip' data-fileid='19825'>4990fd6c.zip.zip
new virus
/applications/core/interface/file/attachment.php?id=4448" data-fileid="4448" rel="">card.zip
The file is detected as: Trojan.Waledac.H