I detected this piece a while ago, but didn't have time to get deeper into it. The detections of the malware sample are quite generic, so for the purpose of this post I'll name it "n3nmtx", based on the mutex it creates at the beginning of the execution. More details on the name at the end of the post.
more here...............http://blog.badtrace.com/post/analysis-of-win32-n3nmtx-trojan/
more here...............http://blog.badtrace.com/post/analysis-of-win32-n3nmtx-trojan/