<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google Code Project Abused by Spammers</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2009/01/07/google-code-project-abused-by-spammers/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/google-code-project-abused-by-spammers</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: carey</title>
		<link>http://blogs.mcafee.com/mcafee-labs/google-code-project-abused-by-spammers/comment-page-1#comment-21227</link>
		<dc:creator>carey</dc:creator>
		<pubDate>Wed, 28 Jan 2009 13:10:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=779#comment-21227</guid>
		<description>Do a search for Hunt&#039;s Point within Google video,
and then click on the hit entitled,
Hunts Point Pimps And Hookers @ kooldvd.com
page redirects, foisting fake Flash installer upon.
Reverse traces to Latvia.IP Address: 94.247.2.34
Location: RIGA (56.944N,  24.117E)
Network: 94-RIPE
domain:       zlkon.lv
admin-c:      86617-LUMII
tech-c:       86617-LUMII
nserver:      ns1.zlkon.lv
nserver:      ns2.zlkon.lv
changed:      dns-reg@nic.lv 20081121
source:       LUMII

person:
address:      none
phone:        +371 26330593
e-mail:       arkadzi.daniyelian@zlkon.lv
nic-hdl:      86617-LUMII
source:       LUMII

File Info Description
Report Generated 25.1.2009 at 0.32.30 (GMT 1)
Time for scan: 31 seconds
Filename: FlashPlayer.v3.181.exe
File size: 110 KB
MD5 Hash: D3EE381464C72DA4671C1B8F15A8281B
SHA1 Hash: B48EA7824B3DFC130FBF200BE7AB5D1D7ED96484
CRC32: 3376619150
Application Type: Executable (EXE) 32bit
Packer detected: Nullsoft PiMP Stub [Nullsoft PiMP SFX] *
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
ASCII Strings: View
Detection Rate: 3 on 24 (12,5 %)

Antivirus Sig Version Result
a-squared 25/01/2009 Nothing found!
Avira AntiVir 7.1.1.173 Nothing found!
Avast 090124-0 NSIS:Fasec [Trj]
AVG 270.10.7/1893 Nothing found!
BitDefender 25/01/2009 Nothing found!
ClamAV 25/01/2009 Nothing found!
Comodo 944 Nothing found!
Dr.Web 25/01/2009 Nothing found!
Ewido 25/01/2009 Nothing found!
F-PROT 6 20090124 Nothing found!
G DATA 19.2579 Packed.Win32.Tdss.a A
IkarusT3 24/01/2009 Nothing found!
Kaspersky 25/01/2009 Packed.Win32.Tdss.a
McAfee 17/01/2009 Nothing found!
MHR (Malware Hash Registry) 25/01/2009 Nothing found!
NOD32 v3 3796 Nothing found!
Norman 2009/01/23 Nothing found!
Panda 21/01/2009 Nothing found!
QuickHeal 24 January, 2009 Nothing found!
Solo Antivirus 25/01/2009 Nothing found!
Sophos 25/01/2009 Nothing found!
TrendMicro 791(579100) Nothing found!
VBA32 25/01/2009 Nothing found!
VirusBuster 10.100.37 Nothing found!


Trojan.DNSChanger.Gen is a generic class of trojans that reconfigure DNS
(Domain Name Server) settings on compromised machines in order to ensure
that all network requests from those PCs are directed to servers and
networks controlled by malicious parties, who can then inject malicious
content into otherwise legitimate web pages or even redirect requests for
standard web sites to bogus, malicious web sites.</description>
		<content:encoded><![CDATA[<p>Do a search for Hunt&#8217;s Point within Google video,<br />
and then click on the hit entitled,<br />
Hunts Point Pimps And Hookers @ kooldvd.com<br />
page redirects, foisting fake Flash installer upon.<br />
Reverse traces to Latvia.IP Address: 94.247.2.34<br />
Location: RIGA (56.944N,  24.117E)<br />
Network: 94-RIPE<br />
domain:       zlkon.lv<br />
admin-c:      86617-LUMII<br />
tech-c:       86617-LUMII<br />
nserver:      ns1.zlkon.lv<br />
nserver:      ns2.zlkon.lv<br />
changed:      <span id="emoba-6714"><span class="emoba-em">dns-reg<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />nic<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />lv</span></span><script type="text/javascript">emobascript('%64%6E%73%2D%72%65%67%40%6E%69%63%2E%6C%76','&lt;span class="emoba-em">dns-reg&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />nic&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />lv&lt;/span>','emoba-6714','','','0'); </script> 20081121<br />
source:       LUMII</p>
<p>person:<br />
address:      none<br />
phone:        +371 26330593<br />
e-mail:       <span id="emoba-6861"><span class="emoba-em">arkadzi<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />daniyelian<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />zlkon<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />lv</span></span><script type="text/javascript">emobascript('%61%72%6B%61%64%7A%69%2E%64%61%6E%69%79%65%6C%69%61%6E%40%7A%6C%6B%6F%6E%2E%6C%76','&lt;span class="emoba-em">arkadzi&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />daniyelian&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />zlkon&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />lv&lt;/span>','emoba-6861','','','0'); </script><br />
nic-hdl:      86617-LUMII<br />
source:       LUMII</p>
<p>File Info Description<br />
Report Generated 25.1.2009 at 0.32.30 (GMT 1)<br />
Time for scan: 31 seconds<br />
Filename: FlashPlayer.v3.181.exe<br />
File size: 110 KB<br />
MD5 Hash: D3EE381464C72DA4671C1B8F15A8281B<br />
SHA1 Hash: B48EA7824B3DFC130FBF200BE7AB5D1D7ED96484<br />
CRC32: 3376619150<br />
Application Type: Executable (EXE) 32bit<br />
Packer detected: Nullsoft PiMP Stub [Nullsoft PiMP SFX] *<br />
Self-Extract Archive: Nothing found<br />
Binder Detector: Nothing found<br />
ASCII Strings: View<br />
Detection Rate: 3 on 24 (12,5 %)</p>
<p>Antivirus Sig Version Result<br />
a-squared 25/01/2009 Nothing found!<br />
Avira AntiVir 7.1.1.173 Nothing found!<br />
Avast 090124-0 NSIS:Fasec [Trj]<br />
AVG 270.10.7/1893 Nothing found!<br />
BitDefender 25/01/2009 Nothing found!<br />
ClamAV 25/01/2009 Nothing found!<br />
Comodo 944 Nothing found!<br />
Dr.Web 25/01/2009 Nothing found!<br />
Ewido 25/01/2009 Nothing found!<br />
F-PROT 6 20090124 Nothing found!<br />
G DATA 19.2579 Packed.Win32.Tdss.a A<br />
IkarusT3 24/01/2009 Nothing found!<br />
Kaspersky 25/01/2009 Packed.Win32.Tdss.a<br />
McAfee 17/01/2009 Nothing found!<br />
MHR (Malware Hash Registry) 25/01/2009 Nothing found!<br />
NOD32 v3 3796 Nothing found!<br />
Norman 2009/01/23 Nothing found!<br />
Panda 21/01/2009 Nothing found!<br />
QuickHeal 24 January, 2009 Nothing found!<br />
Solo Antivirus 25/01/2009 Nothing found!<br />
Sophos 25/01/2009 Nothing found!<br />
TrendMicro 791(579100) Nothing found!<br />
VBA32 25/01/2009 Nothing found!<br />
VirusBuster 10.100.37 Nothing found!</p>
<p>Trojan.DNSChanger.Gen is a generic class of trojans that reconfigure DNS<br />
(Domain Name Server) settings on compromised machines in order to ensure<br />
that all network requests from those PCs are directed to servers and<br />
networks controlled by malicious parties, who can then inject malicious<br />
content into otherwise legitimate web pages or even redirect requests for<br />
standard web sites to bogus, malicious web sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: McAfeeï¼šGoogleé–‹ç™¼è€…ç¶²ç«™è¢«ç”¨ä¾†æ•£ä½ˆæƒ¡æ„è»Ÿé«”</title>
		<link>http://blogs.mcafee.com/mcafee-labs/google-code-project-abused-by-spammers/comment-page-1#comment-21224</link>
		<dc:creator>McAfeeï¼šGoogleé–‹ç™¼è€…ç¶²ç«™è¢«ç”¨ä¾†æ•£ä½ˆæƒ¡æ„è»Ÿé«”</dc:creator>
		<pubDate>Thu, 15 Jan 2009 05:00:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=779#comment-21224</guid>
		<description>[...] McAfee Avert Labså®‰å…¨ç ”ç©¶ä¸»ä»»Dave MarcusæŒ‡å‡ºï¼ŒGoogle Codeæ˜¯ç‚ºç¨‹å¼è¨­è¨ˆå¸«ä»£ç®¡é–‹ç™¼è¨ˆç•«å’Œç¨‹å¼ç¢¼çš„ç¶²ç«™ã€‚é™¤äº†åˆæ³•çš„ç¨‹å¼ä¹‹å¤–ï¼Œé‚„æœ‰å¼•å°Žä½¿ç”¨è€…ä¸‹è¼‰éºç¼ºç·¨ç¢¼çš„å‡å½±éŸ³é€£çµã€‚ä½†é€™äº›ç¨‹å¼ç¢¼ç«Ÿæ˜¯å·å–å¯†ç¢¼å’Œé‡‘èžå€‹è³‡çš„æœ¨é¦¬è»Ÿé«”ã€‚ [...]</description>
		<content:encoded><![CDATA[<p>[...] McAfee Avert Labså®‰å…¨ç ”ç©¶ä¸»ä»»Dave MarcusæŒ‡å‡ºï¼ŒGoogle Codeæ˜¯ç‚ºç¨‹å¼è¨­è¨ˆå¸«ä»£ç®¡é–‹ç™¼è¨ˆç•«å’Œç¨‹å¼ç¢¼çš„ç¶²ç«™ã€‚é™¤äº†åˆæ³•çš„ç¨‹å¼ä¹‹å¤–ï¼Œé‚„æœ‰å¼•å°Žä½¿ç”¨è€…ä¸‹è¼‰éºç¼ºç·¨ç¢¼çš„å‡å½±éŸ³é€£çµã€‚ä½†é€™äº›ç¨‹å¼ç¢¼ç«Ÿæ˜¯å·å–å¯†ç¢¼å’Œé‡‘èžå€‹è³‡çš„æœ¨é¦¬è»Ÿé«”ã€‚ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SHAN</title>
		<link>http://blogs.mcafee.com/mcafee-labs/google-code-project-abused-by-spammers/comment-page-1#comment-21218</link>
		<dc:creator>SHAN</dc:creator>
		<pubDate>Sun, 11 Jan 2009 09:58:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=779#comment-21218</guid>
		<description>Thanks for the infor but can u tell me if the antivirus softwares can block such web sites</description>
		<content:encoded><![CDATA[<p>Thanks for the infor but can u tell me if the antivirus softwares can block such web sites</p>
]]></content:encoded>
	</item>
</channel>
</rss>

