<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
	<channel>
		<title>clean-mx realtime database</title>
		<link>http://support.clean-mx.de/clean-mx/rss?scope=viruses</link>
		<description><![CDATA[Live information from clean-mx.de 954 items in this issue]]></description>
		<item>
			<title><![CDATA[http://13.duote.com.cn/ones1.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11332582</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TROJ_SPNR.0BLS11]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11332582</guid>
			<pubDate>2013-05-23T01:50:01+02:00</pubDate>
			<description><![CDATA[id:	11332582<br />first:	1369266601<br />last:	0<br />md5:	3afd50b662646871ef1e04bc8ad47c4e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3afd50b662646871ef1e04bc8ad47c4e<br />vt_score:	16/36 (44.4%)<br />scanner:	trendmicro<br />virusname:	TROJ_SPNR.0BLS11<br />url:	http://13.duote.com.cn/ones1.zip<br />recent:	up<br />response:	alive<br />ip:	59.51.114.238<br />as:	AS4134<br />review:	59.51.114.238<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	59.51.0.0 - 59.51.127.255<br />netname:	CHINANET-HN<br />descr:	CHINANET Hunan province networkChina TelecomNo1,jin-rong StreetBeijing 100032<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://simultaneoussin2112.blogspot.co.at]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11330940</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bbk]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11330940</guid>
			<pubDate>2013-05-23T01:40:04+02:00</pubDate>
			<description><![CDATA[id:	11330940<br />first:	1369266004<br />last:	0<br />md5:	352a98dde35b1c217094ed0e7398b12b<br />virustotal:	<br />vt_score:	<br />scanner:	avira<br />virusname:	JS/iFrame.bbk<br />url:	http://simultaneoussin2112.blogspot.co.at<br />recent:	up<br />response:	alive<br />ip:	173.194.70.132<br />as:	AS15169<br />review:	173.194.70.132<br />domain:	blogspot.co.at<br />country:	US<br />source:	ARIN<br />email:	arin-contact@google.com<br />inetnum:	173.194.0.0 - 173.194.255.255<br />netname:	GOOGLE<br />descr:	Google Inc. GOGL 1600 Amphitheatre Parkway Mountain View CA 94043<br />ns1:	ns1.google.com<br />ns2:	ns4.google.com<br />ns3:	ns3.google.com<br />ns4:	ns2.google.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://11.duote.com.cn/wyjsq.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11330939</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.420864.I]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11330939</guid>
			<pubDate>2013-05-23T01:40:02+02:00</pubDate>
			<description><![CDATA[id:	11330939<br />first:	1369266002<br />last:	0<br />md5:	9188f7bdd97073d4a7422462cfba168d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9188f7bdd97073d4a7422462cfba168d<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	TR/Agent.420864.I<br />url:	http://11.duote.com.cn/wyjsq.exe<br />recent:	up<br />response:	alive<br />ip:	61.164.109.143<br />as:	AS4134<br />review:	61.164.109.143<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@wz.zj.cn<br />inetnum:	61.164.108.0 - 61.164.111.255<br />netname:	RUIAN-TELECOM<br />descr:	Ruian Telecom<br />ns1:	dns2.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns1.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wowbug.info/_ld/0/85_85_WPE_PRO.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11328019</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Tool.WpePro]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11328019</guid>
			<pubDate>2013-05-22T23:30:02+02:00</pubDate>
			<description><![CDATA[id:	11328019<br />first:	1369258202<br />last:	0<br />md5:	ffe1d642cccaaed7bd8978f3553b3c3c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ffe1d642cccaaed7bd8978f3553b3c3c<br />vt_score:	30/35 (85.7%)<br />scanner:	avira<br />virusname:	SPR/Tool.WpePro<br />url:	http://wowbug.info/_ld/0/85_85_WPE_PRO.rar<br />recent:	up<br />response:	alive<br />ip:	195.216.243.121<br />as:	AS41947<br />review:	195.216.243.121<br />domain:	wowbug.info<br />country:	GB<br />source:	RIPE<br />email:	abuse@compubyte.vg<br />inetnum:	195.216.243.0 - 195.216.243.255<br />netname:	COMPUBYTE-NET<br />descr:	Compubyte LimitedCompubyte Ltd.<br />ns1:	ns2.ucoz.net<br />ns2:	ns1.ucoz.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wai-not.org/nb/2008/sep/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11327042</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BIC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11327042</guid>
			<pubDate>2013-05-22T23:00:27+02:00</pubDate>
			<description><![CDATA[id:	11327042<br />first:	1369256427<br />last:	0<br />md5:	c5a9e1d191ca9049c3401ce7fd2daa55<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c5a9e1d191ca9049c3401ce7fd2daa55<br />vt_score:	16/35 (45.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.BIC<br />url:	http://wai-not.org/nb/2008/sep/index.html<br />recent:	up<br />response:	alive<br />ip:	178.208.53.57<br />as:	AS34762<br />review:	178.208.53.57<br />domain:	wai-not.org<br />country:	BE<br />source:	RIPE<br />email:	abuse@combell.com<br />inetnum:	178.208.53.0 - 178.208.53.255<br />netname:	COMBELL<br />descr:	Combell Cloud NetworkBrussels, Belgium<br />ns1:	ns3.combell.net<br />ns2:	ns4.combell.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://usuaris.tinet.org/scervell/gossos/credits.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11327041</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Script-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11327041</guid>
			<pubDate>2013-05-22T23:00:27+02:00</pubDate>
			<description><![CDATA[id:	11327041<br />first:	1369256427<br />last:	0<br />md5:	7f808284f84fe513c6fb3a017dc005be<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7f808284f84fe513c6fb3a017dc005be<br />vt_score:	10/36 (27.8%)<br />scanner:	Avast<br />virusname:	HTML:Script-inf<br />url:	http://usuaris.tinet.org/scervell/gossos/credits.htm<br />recent:	up<br />response:	alive<br />ip:	195.77.216.137<br />as:	AS3352<br />review:	195.77.216.137<br />domain:	tinet.org<br />country:	ES<br />source:	RIPE<br />email:	ebadia@oasi.org<br />inetnum:	195.77.216.0 - 195.77.216.255<br />netname:	FUT<br />descr:	Organisme Autonom per a la Societat de la Informació (OASI)Internet Public AddressesTelefonica Data Espan~a<br />ns1:	nil.fut.es<br />ns2:	milu.fut.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://silmarautomazioni.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11322333</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.N]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11322333</guid>
			<pubDate>2013-05-22T20:00:21+02:00</pubDate>
			<description><![CDATA[id:	11322333<br />first:	1369245621<br />last:	0<br />md5:	a0cd5cdbb487d96ad934d3e2c318dc45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a0cd5cdbb487d96ad934d3e2c318dc45<br />vt_score:	13/46 (28.3%)<br />scanner:	avira<br />virusname:	JS/Kryptik.N<br />url:	http://silmarautomazioni.it/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.163<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	silmarautomazioni.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mostwatched.ws/sporting-goods/martial-arts.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11307493</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11307493</guid>
			<pubDate>2013-05-22T13:40:04+02:00</pubDate>
			<description><![CDATA[id:	11307493<br />first:	1369222804<br />last:	0<br />md5:	a64432050373ad4e8be3c5719ebdfad9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a64432050373ad4e8be3c5719ebdfad9<br />vt_score:	10/45 (22.2%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://mostwatched.ws/sporting-goods/martial-arts.html<br />recent:	up<br />response:	alive<br />ip:	208.109.46.211<br />as:	AS26496<br />review:	208.109.46.211<br />domain:	mostwatched.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns43.domaincontrol.com<br />ns2:	ns44.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mfi.pl/%7Ejacek/menu.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11306228</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11306228</guid>
			<pubDate>2013-05-22T13:00:08+02:00</pubDate>
			<description><![CDATA[id:	11306228<br />first:	1369220408<br />last:	0<br />md5:	526992a3cf31e723ccb6f4aa26b673f7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=526992a3cf31e723ccb6f4aa26b673f7<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://mfi.pl/%7Ejacek/menu.js<br />recent:	up<br />response:	alive<br />ip:	91.211.101.114<br />as:	AS34494<br />review:	91.211.101.114<br />domain:	mfi.pl<br />country:	PL<br />source:	RIPE<br />email:	biuro@bait.pl<br />inetnum:	91.211.100.0 - 91.211.103.255<br />netname:	PL-BAIT-A<br />descr:	BAIT Sp. z o.oBAIT (PL)<br />ns1:	ns1.mfi.pl<br />ns2:	ns2.mfi.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://itagramar.com.br/index/Cliente.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11291977</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.acn.321]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11291977</guid>
			<pubDate>2013-05-22T10:00:18+02:00</pubDate>
			<description><![CDATA[id:	11291977<br />first:	1369209618<br />last:	0<br />md5:	ec032a5413951b666bb2cf1afac1040f<br />virustotal:	<br />vt_score:	31/47 (66%)<br />scanner:	avira<br />virusname:	TR/Spy.Banker.acn.321<br />url:	http://itagramar.com.br/index/Cliente.zip<br />recent:	up<br />response:	alive<br />ip:	174.122.19.91<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.122.19.91<br />domain:	itagramar.com.br<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-16<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1.linelinux.com.br<br />ns2:	ns2.linelinux.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://indiantravelagents.in/jquery-latest.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11289827</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.P]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11289827</guid>
			<pubDate>2013-05-22T09:40:05+02:00</pubDate>
			<description><![CDATA[id:	11289827<br />first:	1369208405<br />last:	0<br />md5:	20fcc935602322a0d75a5bb7a4651605<br />virustotal:	<br />vt_score:	26/45 (57.8%)<br />scanner:	avira<br />virusname:	JS/Blacole.P<br />url:	http://indiantravelagents.in/jquery-latest.js<br />recent:	up<br />response:	alive<br />ip:	209.217.226.226<br />as:	AS3595<br />review:	209.217.226.226<br />domain:	indiantravelagents.in<br />country:	US<br />source:	ARIN<br />email:	greg@jaguarpc.com<br />inetnum:	209.217.224.0 - 209.217.239.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns1-win3.nswebhost.com<br />ns2:	ns2-win3.nswebhost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fotoszym.pl/kwiaty/album/index4.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11286248</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/SrcInject.N]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11286248</guid>
			<pubDate>2013-05-22T07:30:04+02:00</pubDate>
			<description><![CDATA[id:	11286248<br />first:	1369200604<br />last:	0<br />md5:	8d4079386a44b730e4bd774358733c98<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8d4079386a44b730e4bd774358733c98<br />vt_score:	11/35 (31.4%)<br />scanner:	avira<br />virusname:	JS/SrcInject.N<br />url:	http://fotoszym.pl/kwiaty/album/index4.html<br />recent:	up<br />response:	alive<br />ip:	62.129.237.252<br />as:	AS12824<br />review:	62.129.237.252<br />domain:	fotoszym.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.224.0 - 62.129.239.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enduropage.de/zettisch/DSCF1305.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11284443</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11284443</guid>
			<pubDate>2013-05-22T05:50:06+02:00</pubDate>
			<description><![CDATA[id:	11284443<br />first:	1369194606<br />last:	0<br />md5:	f44b6b10d34ede3dffe337074abf56cb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f44b6b10d34ede3dffe337074abf56cb<br />vt_score:	23/35 (65.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://enduropage.de/zettisch/DSCF1305.html<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	enduropage.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns3.de<br />ns2:	dns.dns1.de<br />ns3:	dns.dns2.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enduropage.de/zettisch/DSCF1281.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11284442</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11284442</guid>
			<pubDate>2013-05-22T05:50:06+02:00</pubDate>
			<description><![CDATA[id:	11284442<br />first:	1369194606<br />last:	0<br />md5:	c45b849d792a45152e4d1627c1a59224<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c45b849d792a45152e4d1627c1a59224<br />vt_score:	29/45 (64.4%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://enduropage.de/zettisch/DSCF1281.html<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	enduropage.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns3.de<br />ns2:	dns.dns1.de<br />ns3:	dns.dns2.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enduropage.de/zettisch/DSCF1157.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11284441</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11284441</guid>
			<pubDate>2013-05-22T05:50:06+02:00</pubDate>
			<description><![CDATA[id:	11284441<br />first:	1369194606<br />last:	0<br />md5:	8560f78c0b1ac54234ab64ea7f67c006<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8560f78c0b1ac54234ab64ea7f67c006<br />vt_score:	23/35 (65.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://enduropage.de/zettisch/DSCF1157.html<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	enduropage.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns3.de<br />ns2:	dns.dns1.de<br />ns3:	dns.dns2.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://damaexpress.it/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11277294</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.K.43]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11277294</guid>
			<pubDate>2013-05-22T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	11277294<br />first:	1369186805<br />last:	0<br />md5:	38ba23053bea8a521cd624b6ad88e475<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7f72819e3ea53c7488aaa94bcf023c5d<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	JS/Agent.K.43<br />url:	http://damaexpress.it/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	217.64.204.51<br />as:	AS12637<br />review:	217.64.204.51<br />domain:	damaexpress.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@seeweb.it<br />inetnum:	217.64.203.16 - 217.64.204.255<br />netname:	SEEWEB-CLOUD<br />descr:	Seeweb Cloud Servers customers<br />ns1:	ns3.misterdomain.eu<br />ns2:	mrddns002.misterdomain.eu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cool-monkey.de/cX_DLL_scanner103.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11277291</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.7464460]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11277291</guid>
			<pubDate>2013-05-22T03:20:03+02:00</pubDate>
			<description><![CDATA[id:	11277291<br />first:	1369185603<br />last:	0<br />md5:	9387438e0d2ab190a5a092c1ae02098a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9387438e0d2ab190a5a092c1ae02098a<br />vt_score:	26/47 (55.3%)<br />scanner:	avira<br />virusname:	TR/Rogue.7464460<br />url:	http://cool-monkey.de/cX_DLL_scanner103.zip<br />recent:	up<br />response:	alive<br />ip:	82.165.212.143<br />as:	AS8560<br />review:	82.165.212.143<br />domain:	cool-monkey.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.208.0 - 82.165.215.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGSCHLUND-PA-4<br />ns1:	ns65.1und1.de<br />ns2:	ns66.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://baxa.hu/k%E9pek/B%26W/lightbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11273026</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.DC.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11273026</guid>
			<pubDate>2013-05-22T00:40:24+02:00</pubDate>
			<description><![CDATA[id:	11273026<br />first:	1369176024<br />last:	0<br />md5:	d18c9125fd1a3ca83a5c20b9b17e6f87<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d18c9125fd1a3ca83a5c20b9b17e6f87<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/Redirector.DC.5<br />url:	http://baxa.hu/k%E9pek/B%26W/lightbox.js<br />recent:	up<br />response:	alive<br />ip:	80.64.65.30<br />as:	AS20742<br />review:	80.64.65.30<br />domain:	baxa.hu<br />country:	hu<br />source:	RIPE<br />email:	abuse@ahol.com<br />inetnum:	80.64.64.0 - 80.64.67.255<br />netname:	AHOL-NET<br />descr:	Internet4U LTDBudapest<br />ns1:	plesk.zerotco.com<br />ns2:	ns2.zerotco.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://22.duote.com.cn/tupian.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11269217</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Blackhole.cvcs]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11269217</guid>
			<pubDate>2013-05-21T22:00:02+02:00</pubDate>
			<description><![CDATA[id:	11269217<br />first:	1369166402<br />last:	0<br />md5:	769c6c7c7cb895f4c4a8267210f9d2e1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=769c6c7c7cb895f4c4a8267210f9d2e1<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	BDS/Blackhole.cvcs<br />url:	http://22.duote.com.cn/tupian.zip<br />recent:	up<br />response:	alive<br />ip:	58.211.23.175<br />as:	AS4134<br />review:	58.211.23.175<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	ip@jsinfo.net<br />inetnum:	58.208.0.0 - 58.223.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	dns3.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vzlomaemvse.at.ua/_ld/0/7___css_v34.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11263815</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Horse.KI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11263815</guid>
			<pubDate>2013-05-21T17:30:08+02:00</pubDate>
			<description><![CDATA[id:	11263815<br />first:	1369150208<br />last:	0<br />md5:	156bfd358772a890582f2b8781828273<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=156bfd358772a890582f2b8781828273<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	TR/Horse.KI<br />url:	http://vzlomaemvse.at.ua/_ld/0/7___css_v34.rar<br />recent:	up<br />response:	alive<br />ip:	193.109.247.56<br />as:	ASNA.193.109.246.0 - 193.109.247.255<br />review:	193.109.247.56<br />domain:	vzlomaemvse.at.ua<br />country:	VG<br />source:	RIPE<br />email:	abuse@compubyte.vg<br />inetnum:	193.109.246.0 - 193.109.247.255<br />netname:	UCOZ-NET<br />descr:	Compubyte Limited<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ic-intracom.at/newsletter/alt/KW20/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11223717</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.JA.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11223717</guid>
			<pubDate>2013-05-20T21:50:05+02:00</pubDate>
			<description><![CDATA[id:	11223717<br />first:	1369079405<br />last:	0<br />md5:	fd90d9fe2697fb8a989bf11b84a88785<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fd90d9fe2697fb8a989bf11b84a88785<br />vt_score:	7/35 (20%)<br />scanner:	avira<br />virusname:	HTML/IFrame.JA.1<br />url:	http://ic-intracom.at/newsletter/alt/KW20/<br />recent:	up<br />response:	alive<br />ip:	85.125.61.14<br />as:	AS8514<br />review:	85.125.61.14<br />domain:	ic-intracom.at<br />country:	AT<br />source:	RIPE<br />email:	abuse@inode.at<br />inetnum:	85.124.0.0 - 85.127.255.255<br />netname:	AT-INODE-20050223<br />descr:	UPC Austria GmbH<br />ns1:	ns2.graz.inode.at<br />ns2:	ns1.graz.inode.at<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://home1.stofanet.dk/leif-ch/GALLERI/GALLERI.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11219610</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AV.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11219610</guid>
			<pubDate>2013-05-20T21:20:03+02:00</pubDate>
			<description><![CDATA[id:	11219610<br />first:	1369077603<br />last:	0<br />md5:	4d39bf1d5183c47733530fc96a8f2c3e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d39bf1d5183c47733530fc96a8f2c3e<br />vt_score:	33/43 (76.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.AV.1<br />url:	http://home1.stofanet.dk/leif-ch/GALLERI/GALLERI.html<br />recent:	up<br />response:	alive<br />ip:	212.10.10.17<br />as:	AS3308<br />review:	212.10.10.17<br />domain:	stofanet.dk<br />country:	DK<br />source:	RIPE<br />email:	abuse@stofanet.dk<br />inetnum:	212.10.0.0 - 212.10.13.247<br />netname:	STOFANET<br />descr:	Telia Stofa A/SCable operator<br />ns1:	auth-ns2.stofanet.dk<br />ns2:	auth-ns1.stofanet.dk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hnuc.org/VOD/music.aspx]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11219608</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.JL.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11219608</guid>
			<pubDate>2013-05-20T21:20:03+02:00</pubDate>
			<description><![CDATA[id:	11219608<br />first:	1369077603<br />last:	0<br />md5:	1f3bdec775059500f4dbd3ae65713ab9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f3bdec775059500f4dbd3ae65713ab9<br />vt_score:	16/46 (34.8%)<br />scanner:	avira<br />virusname:	JS/Redirector.JL.1<br />url:	http://hnuc.org/VOD/music.aspx<br />recent:	up<br />response:	alive<br />ip:	202.197.75.212<br />as:	AS4538<br />review:	202.197.75.212<br />domain:	hnuc.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@net.edu.cn<br />inetnum:	202.197.64.0 - 202.197.79.255<br />netname:	CSUT-CN<br />descr:	Central South University of TechnologyChangsha City 410083Hunan Province, P. R. of China<br />ns1:	dns23.hichina.com<br />ns2:	dns24.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enduropage.de/zettisch/DSCF1137.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11210420</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11210420</guid>
			<pubDate>2013-05-20T17:50:04+02:00</pubDate>
			<description><![CDATA[id:	11210420<br />first:	1369065004<br />last:	0<br />md5:	cc734cbd82de6fc679290dd929a02793<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cc734cbd82de6fc679290dd929a02793<br />vt_score:	23/34 (67.6%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://enduropage.de/zettisch/DSCF1137.html<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	enduropage.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns3.de<br />ns2:	dns.dns1.de<br />ns3:	dns.dns2.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dougdickinson.co.uk/blog/labels/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11207606</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/JS.Crytper.VIP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11207606</guid>
			<pubDate>2013-05-20T16:10:03+02:00</pubDate>
			<description><![CDATA[id:	11207606<br />first:	1369059003<br />last:	0<br />md5:	9d263c54842d62f7d6512167d3b55558<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9d263c54842d62f7d6512167d3b55558<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	SPR/JS.Crytper.VIP<br />url:	http://dougdickinson.co.uk/blog/labels/home.html<br />recent:	up<br />response:	alive<br />ip:	46.231.187.164<br />as:	AS31727<br />review:	46.231.187.164<br />domain:	dougdickinson.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@node4.co.uk<br />inetnum:	46.231.184.0 - 46.231.191.255<br />netname:	UK-NODE4-20100208<br />descr:	Node4 LimitedNode4 DC2 Network<br />ns1:	ns1.web-mania.com<br />ns2:	ns2.web-mania.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ddd.uab.cat/pub/expbib/2003/aqdaf/philosophie.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11205942</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Redlof.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11205942</guid>
			<pubDate>2013-05-20T15:30:04+02:00</pubDate>
			<description><![CDATA[id:	11205942<br />first:	1369056604<br />last:	0<br />md5:	12471249309af522cccd82248ab4eba4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=12471249309af522cccd82248ab4eba4<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	VBS/Redlof.E<br />url:	http://ddd.uab.cat/pub/expbib/2003/aqdaf/philosophie.htm<br />recent:	up<br />response:	alive<br />ip:	158.109.2.236<br />as:	AS13041<br />review:	158.109.2.236<br />domain:	uab.cat<br />country:	ES<br />source:	RIPE<br />email:	abuse@uab.es<br />inetnum:	158.109.0.0 - 158.109.255.255<br />netname:	XIUAB<br />descr:	Xarxa Informatica de laUniversitat Autonoma de Barcelona (UAB)Catalunya<br />ns1:	ns.uab.es<br />ns2:	pamela.uab.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ciadecomunicacao.com.br/luvep/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11201129</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.HM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11201129</guid>
			<pubDate>2013-05-20T13:30:03+02:00</pubDate>
			<description><![CDATA[id:	11201129<br />first:	1369049403<br />last:	0<br />md5:	06e93c961c9ace7de5af773554b9cdb5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=06e93c961c9ace7de5af773554b9cdb5<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/Obfuscated.HM<br />url:	http://ciadecomunicacao.com.br/luvep/<br />recent:	up<br />response:	alive<br />ip:	189.38.80.138<br />as:	AS28299<br />review:	189.38.80.138<br />domain:	ciadecomunicacao.com.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@kinghost.com.br<br />inetnum:	189.38.80.0 - 189.38.95.255<br />netname:	005.305.671/0001-84<br />descr:	Cyberweb Networks Ltda<br />ns1:	dns1.kinghost.com.br<br />ns2:	dns4.kinghost.com.br<br />ns3:	dns3.kinghost.com.br<br />ns4:	dns6.kinghost.com.br<br />ns5:	dns5.kinghost.com.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/brfifok.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11173512</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11173512</guid>
			<pubDate>2013-05-20T00:40:03+02:00</pubDate>
			<description><![CDATA[id:	11173512<br />first:	1369003203<br />last:	0<br />md5:	f518b8ca13c46cdd2f24f6fcb26c5e90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f518b8ca13c46cdd2f24f6fcb26c5e90<br />vt_score:	28/47 (59.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/brfifok.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sollicitatiebrief.eu/media/system/js/mootools-core.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11172210</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZK Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11172210</guid>
			<pubDate>2013-05-20T00:00:33+02:00</pubDate>
			<description><![CDATA[id:	11172210<br />first:	1369000833<br />last:	0<br />md5:	cf58a30ea9b7a731712baede90b790ec<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=32a91b99ed9e1cdd8f611aea5c2fb427<br />vt_score:	20/36 (55.6%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZK Trj<br />url:	http://sollicitatiebrief.eu/media/system/js/mootools-core.js<br />recent:	up<br />response:	alive<br />ip:	188.93.150.34<br />as:	AS21155<br />review:	188.93.150.34<br />domain:	sollicitatiebrief.eu<br />country:	NL<br />source:	RIPE<br />email:	noc@mijndomein.nl<br />inetnum:	188.93.144.0 - 188.93.151.255<br />netname:	NL-MIJNDOMEIN-20090514<br />descr:	mijndomein.nl BVmijndomein.nl BV<br />ns1:	ns2.metaregistrar.nl<br />ns2:	ns1.metaregistrar.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sollicitatiebrief.eu/media/system/js/core.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11172209</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11172209</guid>
			<pubDate>2013-05-20T00:00:33+02:00</pubDate>
			<description><![CDATA[id:	11172209<br />first:	1369000833<br />last:	0<br />md5:	4b59c964036a5a6ba36d4cfa34968c2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3d62e0c10a9ae6ca4b34e10d9cb0616b<br />vt_score:	18/38 (47.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://sollicitatiebrief.eu/media/system/js/core.js<br />recent:	up<br />response:	alive<br />ip:	188.93.150.34<br />as:	AS21155<br />review:	188.93.150.34<br />domain:	sollicitatiebrief.eu<br />country:	NL<br />source:	RIPE<br />email:	noc@mijndomein.nl<br />inetnum:	188.93.144.0 - 188.93.151.255<br />netname:	NL-MIJNDOMEIN-20090514<br />descr:	mijndomein.nl BVmijndomein.nl BV<br />ns1:	ns2.metaregistrar.nl<br />ns2:	ns1.metaregistrar.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sforzaruspoli.it/secoli/ruspoli_x_secolo.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11170875</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Script.4356]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11170875</guid>
			<pubDate>2013-05-19T23:10:03+02:00</pubDate>
			<description><![CDATA[id:	11170875<br />first:	1368997803<br />last:	0<br />md5:	9257d23ace3faf789d2324ca185e2e64<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9257d23ace3faf789d2324ca185e2e64<br />vt_score:	6/36 (16.7%)<br />scanner:	BitDefender<br />virusname:	Trojan.Script.4356<br />url:	http://sforzaruspoli.it/secoli/ruspoli_x_secolo.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	sforzaruspoli.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns3.arubadns.net<br />ns3:	dns.technorail.com<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pnxx.mhedu.sh.cn/images/data/1334/ernianjijiaoan.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11167253</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Nitol.blanu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11167253</guid>
			<pubDate>2013-05-19T21:00:08+02:00</pubDate>
			<description><![CDATA[id:	11167253<br />first:	1368990008<br />last:	0<br />md5:	efc3bd8a8f6e520099d1a26c117d56dc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=efc3bd8a8f6e520099d1a26c117d56dc<br />vt_score:	42/47 (89.4%)<br />scanner:	avira<br />virusname:	TR/Nitol.blanu<br />url:	http://pnxx.mhedu.sh.cn/images/data/1334/ernianjijiaoan.rar<br />recent:	up<br />response:	alive<br />ip:	202.158.162.73<br />as:	AS23850<br />review:	202.158.162.73<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@mgtd.com.cn<br />inetnum:	202.158.160.0 - 202.158.167.255<br />netname:	MGTDNET<br />descr:	MGTD Network<br />ns1:	c.dns.cn<br />ns2:	a.dns.cn<br />ns3:	b.dns.cn<br />ns4:	d.dns.cn<br />ns5:	e.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://maknet.eu/modules/mod_roktabs/tmpl/roktabs.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11163387</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11163387</guid>
			<pubDate>2013-05-19T17:20:02+02:00</pubDate>
			<description><![CDATA[id:	11163387<br />first:	1368976802<br />last:	0<br />md5:	31ac9f88f3c6bcc7b7a90e1b70b347d8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=31ac9f88f3c6bcc7b7a90e1b70b347d8<br />vt_score:	26/43 (60.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://maknet.eu/modules/mod_roktabs/tmpl/roktabs.js<br />recent:	up<br />response:	alive<br />ip:	79.96.20.69<br />as:	AS12824<br />review:	79.96.20.69<br />domain:	maknet.eu<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://light048.com.ne.kr/c.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11162655</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Changeset.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11162655</guid>
			<pubDate>2013-05-19T16:30:03+02:00</pubDate>
			<description><![CDATA[id:	11162655<br />first:	1368973803<br />last:	0<br />md5:	4e590bbb2f43fec5941210dadfe5da9f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4e590bbb2f43fec5941210dadfe5da9f<br />vt_score:	40/45 (88.9%)<br />scanner:	avira<br />virusname:	VBS/Changeset.A<br />url:	http://light048.com.ne.kr/c.htm<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://labtarni.rissani.org/etablis/belle_image/images/12.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11162446</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Chir.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11162446</guid>
			<pubDate>2013-05-19T16:10:02+02:00</pubDate>
			<description><![CDATA[id:	11162446<br />first:	1368972602<br />last:	0<br />md5:	265b29001841859ec66f496593ce10aa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=265b29001841859ec66f496593ce10aa<br />vt_score:	39/44 (88.6%)<br />scanner:	avira<br />virusname:	W32/Chir.B<br />url:	http://labtarni.rissani.org/etablis/belle_image/images/12.htm<br />recent:	up<br />response:	alive<br />ip:	72.29.83.201<br />as:	AS33182<br />review:	72.29.83.201<br />domain:	rissani.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns965.dizinc.com<br />ns2:	ns966.dizinc.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ijburgpampus.nl/js/scriptaculous.js?load=effectsbuilder]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11161024</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.S]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11161024</guid>
			<pubDate>2013-05-19T13:50:02+02:00</pubDate>
			<description><![CDATA[id:	11161024<br />first:	1368964202<br />last:	0<br />md5:	00571554d2682817b2e59692a8daeea6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=00571554d2682817b2e59692a8daeea6<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	JS/Blacole.S<br />url:	http://ijburgpampus.nl/js/scriptaculous.js?load=effectsbuilder<br />recent:	up<br />response:	alive<br />ip:	46.235.44.171<br />as:	AS34233<br />review:	46.235.44.171<br />domain:	ijburgpampus.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@webreus.nl<br />inetnum:	46.235.43.0 - 46.235.47.255<br />netname:	WEBREUS<br />descr:	WebReus WebhostingWebReus @ Superior<br />ns1:	ns1.webreus.nl<br />ns2:	ns3.webreus.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eparochie.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11156902</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Heuristic.LooksLike.HTML.Suspicious-URL.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11156902</guid>
			<pubDate>2013-05-19T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	11156902<br />first:	1368952804<br />last:	0<br />md5:	73090cb47f32d728cc903eaec4087366<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=73090cb47f32d728cc903eaec4087366<br />vt_score:	1/47 (2.1%)<br />scanner:	undef<br />virusname:	Heuristic.LooksLike.HTML.Suspicious-URL.B<br />url:	http://eparochie.nl/<br />recent:	up<br />response:	alive<br />ip:	212.115.204.39<br />as:	AS15542<br />review:	212.115.204.39<br />domain:	eparochie.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@staff.zeelandnet.nl<br />inetnum:	212.115.192.0 - 212.115.223.255<br />netname:	NL-ZEELANDNET-990714<br />descr:	ZeelandNet BVPROVIDERZeelandNet<br />ns1:	ns2.pluym.com<br />ns2:	ns1.pluym.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://digitalplace.nl/download/MSNfreezer.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11153603</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Homac]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11153603</guid>
			<pubDate>2013-05-19T09:20:03+02:00</pubDate>
			<description><![CDATA[id:	11153603<br />first:	1368948003<br />last:	0<br />md5:	ffe7060b6d3ba403fa3374291fc99c54<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ffe7060b6d3ba403fa3374291fc99c54<br />vt_score:	43/47 (91.5%)<br />scanner:	avira<br />virusname:	SPR/Homac<br />url:	http://digitalplace.nl/download/MSNfreezer.rar<br />recent:	up<br />response:	alive<br />ip:	195.211.72.41<br />as:	AS16243<br />review:	195.211.72.41<br />domain:	digitalplace.nl<br />country:	NL<br />source:	RIPE<br />email:	info@antagonist.nl<br />inetnum:	195.211.72.0 - 195.211.75.255<br />netname:	ANTAGONIST<br />descr:	Antagonist BVANTAGONIST via Virtu<br />ns1:	ns1.s16.webhostingserver.nl<br />ns2:	ns3.webhostingserver.nl<br />ns3:	ns2.webhostingserver.nl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bifvepkhku.jackpotwinner.us.org/En-WinPalace.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11150769</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[GAME/Casino.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11150769</guid>
			<pubDate>2013-05-19T06:10:02+02:00</pubDate>
			<description><![CDATA[id:	11150769<br />first:	1368936602<br />last:	0<br />md5:	f84902225999c5ed57b025cbb0f68d8b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	GAME/Casino.Gen2<br />url:	http://bifvepkhku.jackpotwinner.us.org/En-WinPalace.exe<br />recent:	up<br />response:	alive<br />ip:	212.58.4.190<br />as:	AS8685<br />review:	212.58.4.190<br />domain:	us.org<br />country:	TR<br />source:	RIPE<br />email:	abuse@doruk.net.tr<br />inetnum:	212.58.4.0 - 212.58.4.209<br />netname:	DorukNet<br />descr:	DorukNet Co-Location block<br />ns1:	ns2.centralnic.net<br />ns2:	ns5.centralnic.net<br />ns3:	ns6.centralnic.net<br />ns4:	ns3.centralnic.net<br />ns5:	ns7.centralnic.net<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ballonfahrten-baden-wuerttemberg.de]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11145276</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11145276</guid>
			<pubDate>2013-05-19T01:50:01+02:00</pubDate>
			<description><![CDATA[id:	11145276<br />first:	1368921001<br />last:	0<br />md5:	cbd60e989261fcb83d79a0249f8acc45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cbd60e989261fcb83d79a0249f8acc45<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	JS/Expack.VU.1<br />url:	http://ballonfahrten-baden-wuerttemberg.de<br />recent:	up<br />response:	alive<br />ip:	217.115.144.201<br />as:	AS20773<br />review:	217.115.144.201<br />domain:	ballonfahrten-baden-wuerttemberg.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	217.115.144.128 - 217.115.144.255<br />netname:	HE-DEDIC-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.de<br />ns1:	ns1.hans.hosteurope.de<br />ns2:	ns2.hans.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://webzap.co.uk/kodak/script.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11142127</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Gamburl.U]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11142127</guid>
			<pubDate>2013-05-18T23:30:05+02:00</pubDate>
			<description><![CDATA[id:	11142127<br />first:	1368912605<br />last:	0<br />md5:	e8c88d11976ded2cb078ccb813702d06<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e8c88d11976ded2cb078ccb813702d06<br />vt_score:	11/46 (23.9%)<br />scanner:	avira<br />virusname:	JS/Gamburl.U<br />url:	http://webzap.co.uk/kodak/script.js<br />recent:	up<br />response:	alive<br />ip:	91.186.0.8<br />as:	AS29550<br />review:	91.186.0.8<br />domain:	webzap.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@blueconnex.net<br />inetnum:	91.186.0.0 - 91.186.31.255<br />netname:	UK-POUNDHOST-20061103<br />descr:	BlueConnex MK LtdEuroconnex Networks LLP<br />ns1:	ns10.eukdns.com<br />ns2:	ns9.eukdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://webandcad.it/ami/public/22.php20120930193619.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11142126</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/C99Shell.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11142126</guid>
			<pubDate>2013-05-18T23:30:05+02:00</pubDate>
			<description><![CDATA[id:	11142126<br />first:	1368912605<br />last:	0<br />md5:	3629b59c46cd924d03bd439c20a44868<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3629b59c46cd924d03bd439c20a44868<br />vt_score:	32/45 (71.1%)<br />scanner:	avira<br />virusname:	PHP/C99Shell.B<br />url:	http://webandcad.it/ami/public/22.php20120930193619.jpg<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	webandcad.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns.technorail.com<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://visualsensation.pl/js-global/fancyzoomhtml.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11141858</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.F.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11141858</guid>
			<pubDate>2013-05-18T22:50:05+02:00</pubDate>
			<description><![CDATA[id:	11141858<br />first:	1368910205<br />last:	0<br />md5:	504f1ece33fd84f716de06ad706b3be7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=504f1ece33fd84f716de06ad706b3be7<br />vt_score:	25/47 (53.2%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.F.3<br />url:	http://visualsensation.pl/js-global/fancyzoomhtml.js<br />recent:	up<br />response:	alive<br />ip:	89.161.129.45<br />as:	AS12824<br />review:	89.161.129.45<br />domain:	visualsensation.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vigreto.com.br/SIV/pedidos/E002183.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11141508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11141508</guid>
			<pubDate>2013-05-18T22:40:07+02:00</pubDate>
			<description><![CDATA[id:	11141508<br />first:	1368909607<br />last:	0<br />md5:	f678b6cc95303a172a5844857c53f256<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f678b6cc95303a172a5844857c53f256<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://vigreto.com.br/SIV/pedidos/E002183.html<br />recent:	up<br />response:	alive<br />ip:	187.45.240.51<br />as:	AS27715<br />review:	187.45.240.51<br />domain:	vigreto.com.br<br />country:	BR<br />source:	LACNIC<br />email:	regcom@locaweb.com.br<br />inetnum:	187.45.224.0 - 187.45.255.255<br />netname:	002.351.877/0001-52<br />descr:	Locaweb Serviços de Internet S/A<br />ns1:	ns3.locaweb.com.br<br />ns2:	ns2.locaweb.com.br<br />ns3:	ns1.locaweb.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://usmcwhiskey1-12.org/scrapbk48.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11140889</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.yor]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11140889</guid>
			<pubDate>2013-05-18T22:10:03+02:00</pubDate>
			<description><![CDATA[id:	11140889<br />first:	1368907803<br />last:	0<br />md5:	375df62510f9764a3e82a7f5014da405<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=375df62510f9764a3e82a7f5014da405<br />vt_score:	21/46 (45.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.yor<br />url:	http://usmcwhiskey1-12.org/scrapbk48.html<br />recent:	up<br />response:	alive<br />ip:	199.204.248.106<br />as:	AS19730<br />review:	199.204.248.106<br />domain:	usmcwhiskey1-12.org<br />country:	US<br />source:	ARIN<br />email:	netops@hostican.com<br />inetnum:	199.204.248.0 - 199.204.255.255<br />netname:	HOSTICAN-NETWORK<br />descr:	HostICan HOSTI-15 9700 Atlee Commons Drive Ashland VA 23005<br />ns1:	NS1.MYHOSTCENTER.COM<br />ns2:	NS2.MYHOSTCENTER.COM<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://trewgreenenergy.co.uk/autoviewer/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11134762</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.CF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11134762</guid>
			<pubDate>2013-05-18T20:20:03+02:00</pubDate>
			<description><![CDATA[id:	11134762<br />first:	1368901203<br />last:	0<br />md5:	3b4db883750ce8a22c9d6e3511605f91<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b4db883750ce8a22c9d6e3511605f91<br />vt_score:	28/45 (62.2%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.CF<br />url:	http://trewgreenenergy.co.uk/autoviewer/index.html<br />recent:	up<br />response:	alive<br />ip:	88.208.252.143<br />as:	AS15418<br />review:	88.208.252.143<br />domain:	trewgreenenergy.co.uk<br />country:	GB<br />source:	RIPE<br />email:	mark.wood@fasthosts.co.uk<br />inetnum:	88.208.192.0 - 88.208.255.255<br />netname:	UK-FASTHOSTS-20051102<br />descr:	Fast Hosts LTDFasthostInternet Ltd<br />ns1:	ns1.livedns.co.uk<br />ns2:	ns3.livedns.co.uk<br />ns3:	ns2.livedns.co.uk<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://thefreekeylogger.info/downloads/freekeyloggerdemo.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11134293</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Heur.MSIL.Krypt.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11134293</guid>
			<pubDate>2013-05-18T19:20:03+02:00</pubDate>
			<description><![CDATA[id:	11134293<br />first:	1368897603<br />last:	0<br />md5:	02328202bb5656b2ccee0a743e658586<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02328202bb5656b2ccee0a743e658586<br />vt_score:	8/36 (22.2%)<br />scanner:	BitDefender<br />virusname:	Gen:Heur.MSIL.Krypt.5<br />url:	http://thefreekeylogger.info/downloads/freekeyloggerdemo.zip<br />recent:	up<br />response:	alive<br />ip:	174.132.165.221<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.132.165.221<br />domain:	thefreekeylogger.info<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.132.0.0 - 174.133.255.255<br />netname:	NETBLK-THEPLANET-BLK-15<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1393.hostgator.com<br />ns2:	ns1394.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://te-se.de]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11134292</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.GH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11134292</guid>
			<pubDate>2013-05-18T19:20:03+02:00</pubDate>
			<description><![CDATA[id:	11134292<br />first:	1368897603<br />last:	0<br />md5:	0ccfc943d4ba1f6af291a48ab8afcaf5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0ccfc943d4ba1f6af291a48ab8afcaf5<br />vt_score:	16/29 (55.2%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.GH<br />url:	http://te-se.de<br />recent:	up<br />response:	alive<br />ip:	178.254.62.21<br />as:	AS24989<br />review:	178.254.62.21<br />domain:	te-se.de<br />country:	DE<br />source:	RIPE<br />email:	info@evanzo.de<br />inetnum:	178.254.0.0 - 178.254.63.255<br />netname:	DE-EVANZO-20100618<br />descr:	EVANZO e-commerce GmbHDE-EVANZO-20100618<br />ns1:	ns2-tec.de<br />ns2:	ns1-tec.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/refaze.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11133890</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11133890</guid>
			<pubDate>2013-05-18T18:50:03+02:00</pubDate>
			<description><![CDATA[id:	11133890<br />first:	1368895803<br />last:	0<br />md5:	f5af3c3505639ca931b9a4a01c79d72c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f5af3c3505639ca931b9a4a01c79d72c<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/refaze.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns2.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns1.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://techgarage.com.br/js/shadowbox/shadowbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11133889</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11133889</guid>
			<pubDate>2013-05-18T18:50:03+02:00</pubDate>
			<description><![CDATA[id:	11133889<br />first:	1368895803<br />last:	0<br />md5:	dbae590c09b94a9f1e013f6aad7c76bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbae590c09b94a9f1e013f6aad7c76bc<br />vt_score:	29/35 (82.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://techgarage.com.br/js/shadowbox/shadowbox.js<br />recent:	up<br />response:	alive<br />ip:	75.125.138.106<br />as:	AS36420, AS30315, AS13749, AS21844, AS13884<br />review:	75.125.138.106<br />domain:	techgarage.com.br<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	75.125.0.0 - 75.125.255.255<br />netname:	NETBLK-THEPLANET-BLK-EV1-17<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns.techgarage.com.br<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sohydfgo.xoom.it/do-you-k04/quabup.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11131978</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.X]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11131978</guid>
			<pubDate>2013-05-18T17:00:12+02:00</pubDate>
			<description><![CDATA[id:	11131978<br />first:	1368889212<br />last:	0<br />md5:	fb110b8b5c60a01ea9cdb0a2c38945b4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fb110b8b5c60a01ea9cdb0a2c38945b4<br />vt_score:	26/47 (55.3%)<br />scanner:	avira<br />virusname:	JS/Kryptik.X<br />url:	http://sohydfgo.xoom.it/do-you-k04/quabup.js<br />recent:	up<br />response:	alive<br />ip:	212.48.16.77<br />as:	AS8660<br />review:	212.48.16.77<br />domain:	xoom.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@matrix.it<br />inetnum:	212.48.0.0 - 212.48.31.255<br />netname:	IT-MATRIX-980216<br />descr:	Matrix S.p.A.<br />ns1:	ns1.xoom.virgilio.it<br />ns2:	ns2.xoom.virgilio.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sawat-water.de/scripts/swfobject_modified.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11128594</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axi.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11128594</guid>
			<pubDate>2013-05-18T14:30:05+02:00</pubDate>
			<description><![CDATA[id:	11128594<br />first:	1368880205<br />last:	0<br />md5:	c86d6767796eec5f1a8551b5043a907b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c86d6767796eec5f1a8551b5043a907b<br />vt_score:	19/45 (42.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.axi.1<br />url:	http://sawat-water.de/scripts/swfobject_modified.js<br />recent:	up<br />response:	alive<br />ip:	87.106.112.102<br />as:	AS8560<br />review:	87.106.112.102<br />domain:	sawat-water.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	87.106.0.0 - 87.106.255.255<br />netname:	DE-SCHLUND-20050810<br />descr:	1&1 Internet AG<br />ns1:	ns55.1und1.de<br />ns2:	ns56.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://royalorchid.info/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11128593</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.NZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11128593</guid>
			<pubDate>2013-05-18T14:20:04+02:00</pubDate>
			<description><![CDATA[id:	11128593<br />first:	1368879604<br />last:	0<br />md5:	a7419dac695a73a41d567580de6d9e83<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a7419dac695a73a41d567580de6d9e83<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.NZ<br />url:	http://royalorchid.info/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	royalorchid.info<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/it/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11127391</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11127391</guid>
			<pubDate>2013-05-18T13:40:06+02:00</pubDate>
			<description><![CDATA[id:	11127391<br />first:	1368877206<br />last:	0<br />md5:	6694eec465a97775845b3301ce37896f<br />virustotal:	<br />vt_score:	35/46 (76.1%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/it/index.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns1.dreamhost.com<br />ns3:	ns2.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://resalh.ws/js/jquery.validate.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11127390</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.76]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11127390</guid>
			<pubDate>2013-05-18T13:40:06+02:00</pubDate>
			<description><![CDATA[id:	11127390<br />first:	1368877206<br />last:	0<br />md5:	8e190072323e9f7539f0595edb2c3001<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8e190072323e9f7539f0595edb2c3001<br />vt_score:	27/47 (57.4%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.76<br />url:	http://resalh.ws/js/jquery.validate.js<br />recent:	up<br />response:	alive<br />ip:	209.59.186.52<br />as:	AS32244<br />review:	209.59.186.52<br />domain:	resalh.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	209.59.128.0 - 209.59.191.255<br />netname:	LIQUIDWEB-2<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	ns1.arabsgate10.com<br />ns2:	ns2.arabsgate10.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://realm.hu/js/scripts.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11126907</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SU]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11126907</guid>
			<pubDate>2013-05-18T13:10:06+02:00</pubDate>
			<description><![CDATA[id:	11126907<br />first:	1368875406<br />last:	0<br />md5:	cdad78780b70d75d634f0f9818ae58aa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cdad78780b70d75d634f0f9818ae58aa<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.SU<br />url:	http://realm.hu/js/scripts.js<br />recent:	up<br />response:	alive<br />ip:	212.92.23.189<br />as:	AS8990<br />review:	212.92.23.189<br />domain:	realm.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@deninet.hu<br />inetnum:	212.92.23.0 - 212.92.23.255<br />netname:	Deninet-HU<br />descr:	Deninet serverhosting,<br />ns1:	ns5.deninet.hu<br />ns2:	vh.deninet.hu<br />ns3:	ns3.deninet.hu<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://realestateinmontegobayjamaica.com.jm/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11126906</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11126906</guid>
			<pubDate>2013-05-18T13:10:06+02:00</pubDate>
			<description><![CDATA[id:	11126906<br />first:	1368875406<br />last:	0<br />md5:	36a73ec1d4e2fc88f05e5885f8be005c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36a73ec1d4e2fc88f05e5885f8be005c<br />vt_score:	15/47 (31.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://realestateinmontegobayjamaica.com.jm/<br />recent:	up<br />response:	alive<br />ip:	209.217.226.131<br />as:	AS3595<br />review:	209.217.226.131<br />domain:	realestateinmontegobayjamaica.com.jm<br />country:	US<br />source:	ARIN<br />email:	greg@jaguarpc.com<br />inetnum:	209.217.224.0 - 209.217.239.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns2-bee.nswebhost.com<br />ns2:	ns1-bee.nswebhost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://raid.cl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11126903</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11126903</guid>
			<pubDate>2013-05-18T12:50:03+02:00</pubDate>
			<description><![CDATA[id:	11126903<br />first:	1368874203<br />last:	0<br />md5:	4f813db26939e602130416d706f90981<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4f813db26939e602130416d706f90981<br />vt_score:	16/45 (35.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://raid.cl/<br />recent:	up<br />response:	alive<br />ip:	74.52.153.226<br />as:	AS21844<br />review:	74.52.153.226<br />domain:	raid.cl<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	74.52.0.0 - 74.53.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 1333 North Stemmons Freeway Suite 110 Dallas TX 75207<br />ns1:	ns704.websitewelcome.com<br />ns2:	ns703.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ourhouseonline.co.uk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11123191</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Script.Inf.2501]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11123191</guid>
			<pubDate>2013-05-18T09:50:04+02:00</pubDate>
			<description><![CDATA[id:	11123191<br />first:	1368863404<br />last:	0<br />md5:	c0ff627c9b11bd487e966b8fdc7087fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c0ff627c9b11bd487e966b8fdc7087fa<br />vt_score:	6/36 (16.7%)<br />scanner:	avira<br />virusname:	HTML/Script.Inf.2501<br />url:	http://ourhouseonline.co.uk/<br />recent:	up<br />response:	alive<br />ip:	217.160.119.183<br />as:	AS8560<br />review:	217.160.119.183<br />domain:	ourhouseonline.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	217.160.0.0 - 217.160.255.255<br />netname:	DE-SCHLUND-20010307<br />descr:	1&1 Internet AGSCHLUND-PA-3<br />ns1:	ns59.1and1.co.uk<br />ns2:	ns60.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://orska.info/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11123190</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/PhoexRef.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11123190</guid>
			<pubDate>2013-05-18T09:50:04+02:00</pubDate>
			<description><![CDATA[id:	11123190<br />first:	1368863404<br />last:	0<br />md5:	30ef9138b172e1edc0bbf0780b601091<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30ef9138b172e1edc0bbf0780b601091<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/PhoexRef.A<br />url:	http://orska.info/<br />recent:	up<br />response:	alive<br />ip:	79.96.39.37<br />as:	AS12824<br />review:	79.96.39.37<br />domain:	orska.info<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	www.orska.pl<br />ns2:	orska.pl<br />ns3:	dns.home.pl<br />ns4:	dns2.home.pl<br />ns5:	dns3.home.pl<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://observer.co.il/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11121746</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.LZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11121746</guid>
			<pubDate>2013-05-18T09:00:14+02:00</pubDate>
			<description><![CDATA[id:	11121746<br />first:	1368860414<br />last:	0<br />md5:	9e2ae224401028b7f3be841be3b7de0c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9e2ae224401028b7f3be841be3b7de0c<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/iFrame.LZ<br />url:	http://observer.co.il/<br />recent:	up<br />response:	alive<br />ip:	62.219.78.116<br />as:	AS8551<br />review:	62.219.78.116<br />domain:	observer.co.il<br />country:	IL<br />source:	RIPE<br />email:	abuse@bezeqint.net<br />inetnum:	62.219.0.0 - 62.219.255.255<br />netname:	IL-BEZEQ-INTERNATIONAL-20001229<br />descr:	Bezeq International-Ltd<br />ns1:	ns1.livedns.co.il<br />ns2:	ns2.livedns.co.il<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nuestrochile.cl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11121745</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11121745</guid>
			<pubDate>2013-05-18T09:00:11+02:00</pubDate>
			<description><![CDATA[id:	11121745<br />first:	1368860411<br />last:	0<br />md5:	a2fd9f417a909aff8f052793729ec960<br />virustotal:	<br />vt_score:	28/45 (62.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.TF<br />url:	http://nuestrochile.cl/<br />recent:	up<br />response:	alive<br />ip:	200.73.5.195<br />as:	AS18747<br />review:	200.73.5.195<br />domain:	nuestrochile.cl<br />country:	CL<br />source:	LACNIC<br />email:	netadmin@ifxnw.cl<br />inetnum:	200.73.4.0 - 200.73.5.255<br />netname:	CL-INCS-LACNIC<br />descr:	IFX Networks Chile S.AApoquindo, 3000, Of 6026760341 - Santiago - RMApoquindo, 3000, P 67550202 - Santiago - RM<br />ns1:	ns1.rolsoft.cl<br />ns2:	ns2.rolsoft.cl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nederlandsbrandweerelftal.nl/ek2009/opening/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11121123</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.Inje.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11121123</guid>
			<pubDate>2013-05-18T08:20:05+02:00</pubDate>
			<description><![CDATA[id:	11121123<br />first:	1368858005<br />last:	0<br />md5:	061940bf4fd51f1cad7a36ea81c4f262<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=061940bf4fd51f1cad7a36ea81c4f262<br />vt_score:	26/45 (57.8%)<br />scanner:	avira<br />virusname:	HTML/IFrame.Inje.1<br />url:	http://nederlandsbrandweerelftal.nl/ek2009/opening/<br />recent:	up<br />response:	alive<br />ip:	194.109.108.201<br />as:	AS3265<br />review:	194.109.108.201<br />domain:	nederlandsbrandweerelftal.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@xs4all.nl<br />inetnum:	194.109.0.0 - 194.109.255.255<br />netname:	NL-XS4ALL-960513<br />descr:	Xs4all Internet BV<br />ns1:	ns2.scconline.nl<br />ns2:	ns1.scconline.nl<br />ns3:	ns3.scconline.nl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mrmojo.com.br/reviews/bnj/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11120759</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[EXP/JS.Iframe.AN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11120759</guid>
			<pubDate>2013-05-18T07:40:03+02:00</pubDate>
			<description><![CDATA[id:	11120759<br />first:	1368855603<br />last:	0<br />md5:	88361d23c568a9c41bd44a0336665a18<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=88361d23c568a9c41bd44a0336665a18<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	EXP/JS.Iframe.AN<br />url:	http://mrmojo.com.br/reviews/bnj/index.htm<br />recent:	up<br />response:	alive<br />ip:	72.167.131.9<br />as:	AS26496<br />review:	72.167.131.9<br />domain:	mrmojo.com.br<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	72.167.0.0 - 72.167.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns52.domaincontrol.com<br />ns2:	ns51.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mostwatched.ws/ebay-motors/cars-trucks.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11120755</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11120755</guid>
			<pubDate>2013-05-18T07:20:04+02:00</pubDate>
			<description><![CDATA[id:	11120755<br />first:	1368854404<br />last:	0<br />md5:	d8a68e2fe4ffd8e9a3765f399eedff74<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d8a68e2fe4ffd8e9a3765f399eedff74<br />vt_score:	10/36 (27.8%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://mostwatched.ws/ebay-motors/cars-trucks.html<br />recent:	up<br />response:	alive<br />ip:	208.109.46.211<br />as:	AS26496<br />review:	208.109.46.211<br />domain:	mostwatched.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns43.domaincontrol.com<br />ns2:	ns44.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://loosewomen.org.uk/site/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11115532</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11115532</guid>
			<pubDate>2013-05-18T04:10:04+02:00</pubDate>
			<description><![CDATA[id:	11115532<br />first:	1368843004<br />last:	0<br />md5:	0d489abfed3358ad442b37c451b93adb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0d489abfed3358ad442b37c451b93adb<br />vt_score:	28/42 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://loosewomen.org.uk/site/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	31.193.142.162<br />as:	AS29550<br />review:	31.193.142.162<br />domain:	loosewomen.org.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@as29550.net<br />inetnum:	31.193.128.0 - 31.193.143.255<br />netname:	UK-POUNDHOST-20110427<br />descr:	Simply Transit Ltd<br />ns1:	ns5.storminternet.net<br />ns2:	ns6.storminternet.net<br />ns3:	ns.loosewomen.org.uk<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lexcorpora.pl/menu_pol.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11115042</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SU]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11115042</guid>
			<pubDate>2013-05-18T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	11115042<br />first:	1368841205<br />last:	0<br />md5:	29a3297bf871a9a829fc94bda949cad1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=29a3297bf871a9a829fc94bda949cad1<br />vt_score:	9/46 (19.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.SU<br />url:	http://lexcorpora.pl/menu_pol.js<br />recent:	up<br />response:	alive<br />ip:	89.161.168.8<br />as:	AS12824<br />review:	89.161.168.8<br />domain:	lexcorpora.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lenhart.i-networx.de/sets/galerie08kopf.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11115040</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.BlacoleRef]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11115040</guid>
			<pubDate>2013-05-18T03:20:03+02:00</pubDate>
			<description><![CDATA[id:	11115040<br />first:	1368840003<br />last:	0<br />md5:	2327aae59af2717258266874b9ed0a00<br />virustotal:	<br />vt_score:	4/46 (8.7%)<br />scanner:	undef<br />virusname:	Trojan.JS.BlacoleRef<br />url:	http://lenhart.i-networx.de/sets/galerie08kopf.htm<br />recent:	up<br />response:	alive<br />ip:	217.70.142.36<br />as:	AS15366<br />review:	217.70.142.36<br />domain:	i-networx.de<br />country:	DE<br />source:	RIPE<br />email:	noc@dns-net.de<br />inetnum:	217.70.142.0 -  217.70.142.255<br />netname:	DE-INTERNETWORX-NET-1<br />descr:	InterNetworX Ltd. & Co. KGUffizio Internet Services RIPE block<br />ns1:	ns3.inwx.de<br />ns2:	ns2.inwx.de<br />ns3:	ns.inwx.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lajca.pl/js/calendar/calendar.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11114001</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PH.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11114001</guid>
			<pubDate>2013-05-18T02:50:10+02:00</pubDate>
			<description><![CDATA[id:	11114001<br />first:	1368838210<br />last:	0<br />md5:	b93dfe130e72003859e7d30d0569a170<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b93dfe130e72003859e7d30d0569a170<br />vt_score:	13/42 (31%)<br />scanner:	avira<br />virusname:	JS/iFrame.PH.3<br />url:	http://lajca.pl/js/calendar/calendar.js<br />recent:	up<br />response:	alive<br />ip:	79.96.66.154<br />as:	AS12824<br />review:	79.96.66.154<br />domain:	lajca.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdezentj.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11112340</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11112340</guid>
			<pubDate>2013-05-18T02:10:04+02:00</pubDate>
			<description><![CDATA[id:	11112340<br />first:	1368835804<br />last:	0<br />md5:	83a70e0add7bd844ddc93bad387d4790<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdezentj.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdezenta.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11112339</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11112339</guid>
			<pubDate>2013-05-18T02:10:04+02:00</pubDate>
			<description><![CDATA[id:	11112339<br />first:	1368835804<br />last:	0<br />md5:	8176b6aa650594672510f7d0d8563e3a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8176b6aa650594672510f7d0d8563e3a<br />vt_score:	14/35 (40%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdezenta.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jpkc.nwu.edu.cn/zglsdlx/main03/ppt/08/200507171707.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11109426</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.apn]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11109426</guid>
			<pubDate>2013-05-17T23:20:03+02:00</pubDate>
			<description><![CDATA[id:	11109426<br />first:	1368825603<br />last:	0<br />md5:	3d4a8b47f7ea00c2411fd5f467d6e283<br />virustotal:	<br />vt_score:	34/46 (73.9%)<br />scanner:	avira<br />virusname:	JS/Agent.apn<br />url:	http://jpkc.nwu.edu.cn/zglsdlx/main03/ppt/08/200507171707.htm<br />recent:	up<br />response:	alive<br />ip:	124.115.173.254<br />as:	AS4134<br />review:	124.115.173.254<br />domain:	nwu.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	124.114.0.0 - 124.115.255.255<br />netname:	CHINANET-SN<br />descr:	CHINANET Shanxi(SN) province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088From Shanxi(CHINANET-SN) Network of ChinaTelecom<br />ns1:	nwu02.nwu.edu.cn<br />ns2:	nwu01.nwu.edu.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://innovandosalud.cl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11106606</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11106606</guid>
			<pubDate>2013-05-17T21:10:11+02:00</pubDate>
			<description><![CDATA[id:	11106606<br />first:	1368817811<br />last:	0<br />md5:	bfd39f7a758490772a3a7eefe8ef70ef<br />virustotal:	<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.TF<br />url:	http://innovandosalud.cl/<br />recent:	up<br />response:	alive<br />ip:	208.113.155.195<br />as:	AS26347<br />review:	208.113.155.195<br />domain:	innovandosalud.cl<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	208.113.128.0 - 208.113.223.255<br />netname:	DREAMHOST-BLK6<br />descr:	New Dream Network, LLC NDN 10 Pointe Drive Suite 235 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://harlekin-grosspudel.at/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11102133</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_EXPLOIT.SMDZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11102133</guid>
			<pubDate>2013-05-17T18:50:07+02:00</pubDate>
			<description><![CDATA[id:	11102133<br />first:	1368809407<br />last:	0<br />md5:	50f01b4bc46d08b9edf6034012a31347<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50f01b4bc46d08b9edf6034012a31347<br />vt_score:	36/46 (78.3%)<br />scanner:	trendmicro<br />virusname:	JS_EXPLOIT.SMDZ<br />url:	http://harlekin-grosspudel.at/<br />recent:	up<br />response:	alive<br />ip:	213.208.135.16<br />as:	AS1764<br />review:	213.208.135.16<br />domain:	harlekin-grosspudel.at<br />country:	AT<br />source:	RIPE<br />email:	abuse@unixsecurity.at<br />inetnum:	213.208.135.0 - 213.208.135.255<br />netname:	WEBMACHINE-NET-4<br />descr:	Webmachine Unixsecurity Network VIE-IX<br />ns1:	ns2.webmachine.at<br />ns2:	ns1.webmachine.at<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gerbag.ph/js/lightbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11099255</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11099255</guid>
			<pubDate>2013-05-17T17:10:04+02:00</pubDate>
			<description><![CDATA[id:	11099255<br />first:	1368803404<br />last:	0<br />md5:	7003d264c21000cf33fa804d983ee042<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7003d264c21000cf33fa804d983ee042<br />vt_score:	24/44 (54.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://gerbag.ph/js/lightbox.js<br />recent:	up<br />response:	alive<br />ip:	64.13.232.152<br />as:	AS31815<br />review:	64.13.232.152<br />domain:	gerbag.ph<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	64.13.192.0 - 64.13.255.255<br />netname:	MEDIATEMPLE-103<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.mediatemple.net<br />ns2:	ns2.mediatemple.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gamedata.box.sk/_cht5/settlershoktrn5.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11098590</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Horse.ACH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11098590</guid>
			<pubDate>2013-05-17T16:30:09+02:00</pubDate>
			<description><![CDATA[id:	11098590<br />first:	1368801009<br />last:	0<br />md5:	bf0f67ec5bf602eedce45b49b11faa81<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bf0f67ec5bf602eedce45b49b11faa81<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	TR/Horse.ACH<br />url:	http://gamedata.box.sk/_cht5/settlershoktrn5.zip<br />recent:	up<br />response:	alive<br />ip:	88.212.3.3<br />as:	AS42841<br />review:	88.212.3.3<br />domain:	box.sk<br />country:	SK<br />source:	RIPE<br />email:	abuse@antik.sk<br />inetnum:	88.212.0.0 - 88.212.63.255<br />netname:	SK-ANTIK-20051208<br />descr:	Antik Computers and Communications s.r.o.<br />ns1:	elf.box.sk.sk<br />ns2:	elf2.box.sk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://forum.tusuweb.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11098289</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.QA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11098289</guid>
			<pubDate>2013-05-17T16:10:15+02:00</pubDate>
			<description><![CDATA[id:	11098289<br />first:	1368799815<br />last:	0<br />md5:	fd2ec27732918746aabfe082190522f8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fd2ec27732918746aabfe082190522f8<br />vt_score:	17/47 (36.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.QA<br />url:	http://forum.tusuweb.it/<br />recent:	up<br />response:	alive<br />ip:	62.149.140.133<br />as:	AS31034<br />review:	62.149.140.133<br />domain:	tusuweb.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.138.0 - 62.149.159.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access Provider<br />ns1:	dns3.arubadns.net<br />ns2:	dns.technorail.com<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://file.clickup.kr/app_file/clickup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11097192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/Genetic.gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11097192</guid>
			<pubDate>2013-05-17T15:20:06+02:00</pubDate>
			<description><![CDATA[id:	11097192<br />first:	1368796806<br />last:	0<br />md5:	673907bd659e1dd2818af43e042f6d03<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=673907bd659e1dd2818af43e042f6d03<br />vt_score:	14/44 (31.8%)<br />scanner:	undef<br />virusname:	Trj/Genetic.gen<br />url:	http://file.clickup.kr/app_file/clickup.exe<br />recent:	up<br />response:	alive<br />ip:	211.233.11.133<br />as:	AS3786<br />review:	211.233.11.133<br />domain:	clickup.kr<br />country:	kr<br />source:	APNIC<br />email:	support@kidc.net<br />inetnum:	211.233.0.0 - 211.233.63.255 ( - 211.233.63.255<br />netname:	KIDC-INFRA<br />descr:	<br />ns1:	ns1.funyjin.co.kr<br />ns2:	ns.funyjin.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://epfc.pt/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11095749</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.LZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11095749</guid>
			<pubDate>2013-05-17T13:40:23+02:00</pubDate>
			<description><![CDATA[id:	11095749<br />first:	1368790823<br />last:	0<br />md5:	4f3a5de41acea08633847f82fe3b72bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4f3a5de41acea08633847f82fe3b72bf<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/iFrame.LZ<br />url:	http://epfc.pt/<br />recent:	up<br />response:	alive<br />ip:	80.172.241.40<br />as:	AS5533<br />review:	80.172.241.40<br />domain:	epfc.pt<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	80.172.240.0 - 80.172.241.255<br />netname:	ESOTERICA<br />descr:	Claranet's customer<br />ns1:	ns1.esoterica.com<br />ns2:	ns2.esoterica.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://emotions-parfums.info/collection/divers_h_z/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11095747</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_ONLOAD.SMD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11095747</guid>
			<pubDate>2013-05-17T13:20:29+02:00</pubDate>
			<description><![CDATA[id:	11095747<br />first:	1368789629<br />last:	0<br />md5:	8d999f87460b8da0fff91ed0cab1e20b<br />virustotal:	<br />vt_score:	19/46 (41.3%)<br />scanner:	trendmicro<br />virusname:	JS_ONLOAD.SMD<br />url:	http://emotions-parfums.info/collection/divers_h_z/index.html<br />recent:	up<br />response:	alive<br />ip:	82.165.52.35<br />as:	AS8560<br />review:	82.165.52.35<br />domain:	emotions-parfums.info<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.48.0 - 82.165.63.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns11.1and1.fr<br />ns2:	ns12.1and1.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://drmsithaldia.org/script/localtime.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11094249</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11094249</guid>
			<pubDate>2013-05-17T12:40:06+02:00</pubDate>
			<description><![CDATA[id:	11094249<br />first:	1368787206<br />last:	0<br />md5:	31735b63338f8edb09cad99a1ebc5c9e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=31735b63338f8edb09cad99a1ebc5c9e<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://drmsithaldia.org/script/localtime.js<br />recent:	up<br />response:	alive<br />ip:	182.18.155.23<br />as:	AS18229<br />review:	182.18.155.23<br />domain:	drmsithaldia.org<br />country:	IN<br />source:	APNIC<br />email:	psridharreddy@hotmail.com<br />inetnum:	182.18.128.0 - 182.18.191.255<br />netname:	PIONEER_ELABS<br />descr:	Pioneer Elabs Ltd.7th Floor, Pioneer Towers,Plot No.16, APIIC Software Units Layout,Madhapur,CtrlSCtrlS IP Pools<br />ns1:	ns1.hostingkolkata.co.in<br />ns2:	ns2.hostingkolkata.co.in<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://drhamadani.org/images/index_57.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11094248</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscator.pse]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11094248</guid>
			<pubDate>2013-05-17T12:20:29+02:00</pubDate>
			<description><![CDATA[id:	11094248<br />first:	1368786029<br />last:	0<br />md5:	10987966b22787cb8f19cd16498bb2c9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=10987966b22787cb8f19cd16498bb2c9<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	JS/Obfuscator.pse<br />url:	http://drhamadani.org/images/index_57.jpg<br />recent:	up<br />response:	alive<br />ip:	173.192.11.4<br />as:	AS36351<br />review:	173.192.11.4<br />domain:	drhamadani.org<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	173.192.0.0 - 173.193.255.255<br />netname:	SOFTLAYER-4-8<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns16.hostingcare.net<br />ns2:	ns15.hostingcare.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/toys-hobbies/models-kits.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11092974</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11092974</guid>
			<pubDate>2013-05-17T11:42:15+02:00</pubDate>
			<description><![CDATA[id:	11092974<br />first:	1368783735<br />last:	0<br />md5:	3b0e991a6a4de57cc271cd3e0822cb5b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b0e991a6a4de57cc271cd3e0822cb5b<br />vt_score:	12/46 (26.1%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/toys-hobbies/models-kits.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns1.stabletransit.com<br />ns2:	dns2.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://demo.hosteasy.com.hk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11091031</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11091031</guid>
			<pubDate>2013-05-17T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	11091031<br />first:	1368780004<br />last:	0<br />md5:	8e4140ce4905c195f0cb86aaa16fc9e3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8e4140ce4905c195f0cb86aaa16fc9e3<br />vt_score:	24/47 (51.1%)<br />scanner:	undef<br />virusname:	HTML/Framer<br />url:	http://demo.hosteasy.com.hk/<br />recent:	up<br />response:	alive<br />ip:	114.142.147.24<br />as:	AS9584<br />review:	114.142.147.24<br />domain:	hosteasy.com.hk<br />country:	HK<br />source:	APNIC<br />email:	noc@dyxnet.com<br />inetnum:	114.142.144.0 - 114.142.159.255<br />netname:	GENESIS<br />descr:	Genesis Net Limited<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cimit.in/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11085667</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11085667</guid>
			<pubDate>2013-05-17T07:00:29+02:00</pubDate>
			<description><![CDATA[id:	11085667<br />first:	1368766829<br />last:	0<br />md5:	eec5dec2d4eb4e0fe6882e7d2edebbcd<br />virustotal:	<br />vt_score:	34/44 (77.3%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://cimit.in/<br />recent:	up<br />response:	alive<br />ip:	119.18.48.40<br />as:	AS36351<br />review:	119.18.48.40<br />domain:	cimit.in<br />country:	IN<br />source:	APNIC<br />email:	abuse@hostgator.in<br />inetnum:	119.18.48.0 - 119.18.56.255<br />netname:	WebsiteDNSPool2<br />descr:	This is the second Websitedns.in IP pool.<br />ns1:	gns11.hostgator.in<br />ns2:	gns12.hostgator.in<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://chiangmaictu.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11084045</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.O]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11084045</guid>
			<pubDate>2013-05-17T06:20:10+02:00</pubDate>
			<description><![CDATA[id:	11084045<br />first:	1368764410<br />last:	0<br />md5:	8cab0925173a1a1f2768869088e8853c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8cab0925173a1a1f2768869088e8853c<br />vt_score:	20/45 (44.4%)<br />scanner:	avira<br />virusname:	JS/RunForest.O<br />url:	http://chiangmaictu.org/<br />recent:	up<br />response:	alive<br />ip:	66.33.223.247<br />as:	AS26347<br />review:	66.33.223.247<br />domain:	chiangmaictu.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	66.33.192.0 - 66.33.223.255<br />netname:	DREAMHOST-BLK1<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns3.dreamhost.com<br />ns3:	ns2.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://checkmypc.org/check/see-r-kelly-sex-tape_sex_3105s.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11083559</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Script/FakeAlert]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11083559</guid>
			<pubDate>2013-05-17T05:50:05+02:00</pubDate>
			<description><![CDATA[id:	11083559<br />first:	1368762605<br />last:	0<br />md5:	f6f4bd67a8cd9e1cc0466fd8afc968be<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f6f4bd67a8cd9e1cc0466fd8afc968be<br />vt_score:	5/35 (14.3%)<br />scanner:	AVG<br />virusname:	Script/FakeAlert<br />url:	http://checkmypc.org/check/see-r-kelly-sex-tape_sex_3105s.html<br />recent:	up<br />response:	alive<br />ip:	75.119.200.232<br />as:	AS26347<br />review:	75.119.200.232<br />domain:	checkmypc.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	75.119.192.0 - 75.119.223.255<br />netname:	DREAMHOST-BLK8<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns2.dreamhost.com<br />ns2:	ns3.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cetti.com.ua/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11082294</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.ahf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11082294</guid>
			<pubDate>2013-05-17T05:30:06+02:00</pubDate>
			<description><![CDATA[id:	11082294<br />first:	1368761406<br />last:	0<br />md5:	2d0979cc184d01ffb5178c4d5cdc89cf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2d0979cc184d01ffb5178c4d5cdc89cf<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/Agent.ahf<br />url:	http://cetti.com.ua/<br />recent:	up<br />response:	alive<br />ip:	212.9.240.241<br />as:	AS12742<br />review:	212.9.240.241<br />domain:	cetti.com.ua<br />country:	UA<br />source:	RIPE<br />email:	abuse@iptelecom.ua<br />inetnum:	212.9.240.0 - 212.9.240.255<br />netname:	HOSTING-IPTCOM<br />descr:	IP Based Virtual Hosting<br />ns1:	ns2.iptelecom.net.ua<br />ns2:	ns.iptelecom.net.ua<br />ns3:	ns.alkar.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://breatheeasycannockandstaffs.co.uk/storage/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11077331</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11077331</guid>
			<pubDate>2013-05-17T03:20:05+02:00</pubDate>
			<description><![CDATA[id:	11077331<br />first:	1368753605<br />last:	0<br />md5:	49e332a712a99707ba067cd4b36129d5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=49e332a712a99707ba067cd4b36129d5<br />vt_score:	13/43 (30.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.TP<br />url:	http://breatheeasycannockandstaffs.co.uk/storage/index.html<br />recent:	up<br />response:	alive<br />ip:	37.75.232.4<br />as:	AS28673<br />review:	37.75.232.4<br />domain:	breatheeasycannockandstaffs.co.uk<br />country:	GB<br />source:	RIPE<br />email:	<br />inetnum:	37.75.232.0 - 37.75.239.255<br />netname:	<br />descr:	<br />ns1:	ns1.webhost-nameservers.com<br />ns2:	ns2.webhost-nameservers.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://actingforacure.org/Old%20Pages/afac.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11066816</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11066816</guid>
			<pubDate>2013-05-16T20:30:06+02:00</pubDate>
			<description><![CDATA[id:	11066816<br />first:	1368729006<br />last:	0<br />md5:	f21b9579e65a8d39932bf6a186e04fd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f21b9579e65a8d39932bf6a186e04fd2<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://actingforacure.org/Old%20Pages/afac.htm<br />recent:	up<br />response:	alive<br />ip:	97.74.144.162<br />as:	AS26496<br />review:	97.74.144.162<br />domain:	actingforacure.org<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns51.domaincontrol.com<br />ns2:	ns52.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://acomarca.com.br/editor/images/bart.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11066815</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11066815</guid>
			<pubDate>2013-05-16T20:30:05+02:00</pubDate>
			<description><![CDATA[id:	11066815<br />first:	1368729005<br />last:	0<br />md5:	f27e4f2dab310c00a23a6e828e6718ae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f27e4f2dab310c00a23a6e828e6718ae<br />vt_score:	32/46 (69.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://acomarca.com.br/editor/images/bart.html<br />recent:	up<br />response:	alive<br />ip:	216.59.16.30<br />as:	AS36167<br />review:	216.59.16.30<br />domain:	acomarca.com.br<br />country:	US<br />source:	ARIN<br />email:	abuse@netriplex.com<br />inetnum:	216.59.0.0 - 216.59.63.255<br />netname:	NETR-AVL-1<br />descr:	NETRIPLEX LLC NETRI-2 100 Technology Drive Suite C Asheville NC 28803<br />ns1:	ns2.televide.virtuaserver.com.br<br />ns2:	ns1.televideohostserv.com<br />ns3:	ns2.televideohostserv.com<br />ns4:	ns1.televide.virtuaserver.com.br<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ab.org.tr/ab01/prog/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11065834</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11065834</guid>
			<pubDate>2013-05-16T20:10:16+02:00</pubDate>
			<description><![CDATA[id:	11065834<br />first:	1368727816<br />last:	0<br />md5:	4552d0535a6772d25c4dbe8861bec45d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4552d0535a6772d25c4dbe8861bec45d<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://ab.org.tr/ab01/prog/<br />recent:	up<br />response:	alive<br />ip:	139.179.130.61<br />as:	AS8466<br />review:	139.179.130.61<br />domain:	ab.org.tr<br />country:	TR<br />source:	RIPE<br />email:	cayfer@bilkent.edu.tr<br />inetnum:	139.179.0.0 - 139.179.255.255<br />netname:	TR-BILNET<br />descr:	Bilkent UniversityP.O. Box 806572 Maltepe, AnkaraBilkent UniversityBilkent, Ankara 06800TURKEYBilkent UniversityBilkent, Ankara 06800TURKEY<br />ns1:	ns1.aygen.org<br />ns2:	sinan.sfk.org.tr<br />ns3:	admin.bilkent.edu.tr<br />ns4:	akgul.bilkent.edu.tr<br />ns5:	arf.afl.org.tr<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://85.25.109.219]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11065832</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.OC.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11065832</guid>
			<pubDate>2013-05-16T20:10:15+02:00</pubDate>
			<description><![CDATA[id:	11065832<br />first:	1368727815<br />last:	0<br />md5:	1a85fc97a9a65ee9b9ffd2065876ff6f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=419108fe8a3a50a4b3b51b8d38522bb8<br />vt_score:	15/46 (32.6%)<br />scanner:	avira<br />virusname:	HTML/IFrame.OC.3<br />url:	http://85.25.109.219<br />recent:	up<br />response:	alive<br />ip:	85.25.109.219<br />as:	AS8972<br />review:	85.25.109.219<br />domain:	85.25.109.219<br />country:	DE<br />source:	RIPE<br />email:	abuse@justdsl.de<br />inetnum:	85.25.96.0 - 85.25.111.255<br />netname:	JustDSL<br />descr:	JustDSL Broadband Dialin<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://80.duote.com.cn/baolilljl.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11065831</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11065831</guid>
			<pubDate>2013-05-16T20:10:15+02:00</pubDate>
			<description><![CDATA[id:	11065831<br />first:	1368727815<br />last:	0<br />md5:	f5aec69a7024333c82bf513b74f7b9e3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f5aec69a7024333c82bf513b74f7b9e3<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://80.duote.com.cn/baolilljl.zip<br />recent:	up<br />response:	alive<br />ip:	60.191.254.85<br />as:	AS4134<br />review:	60.191.254.85<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@mail.jhptt.zj.cn<br />inetnum:	60.191.254.0 - 60.191.254.255<br />netname:	JINHUA-IDC-CENTER<br />descr:	Jinhua Telecom Co.,ltd Network Management Assert Center IDC<br />ns1:	dns1.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns4.50bang.org<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://4home.com.pk/images/javascri.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11063537</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.P]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11063537</guid>
			<pubDate>2013-05-16T19:30:03+02:00</pubDate>
			<description><![CDATA[id:	11063537<br />first:	1368725403<br />last:	0<br />md5:	646e13784b0595ff1237154664667955<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=646e13784b0595ff1237154664667955<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	JS/Blacole.P<br />url:	http://4home.com.pk/images/javascri.js<br />recent:	up<br />response:	alive<br />ip:	174.142.20.169<br />as:	AS32613<br />review:	174.142.20.169<br />domain:	4home.com.pk<br />country:	CA<br />source:	ARIN<br />email:	abuse@noc.privatedns.com<br />inetnum:	174.142.0.0 - 174.142.255.255<br />netname:	IWEB-BLK-06<br />descr:	iWeb Technologies Inc. GIT-20 20, place du Commerce Montreal QC H3E-1Z6<br />ns1:	ns.4home.com.pk<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wpe-pro.at.ua/Setup.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11052901</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Drop.Small.PQ.107]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11052901</guid>
			<pubDate>2013-05-16T15:00:16+02:00</pubDate>
			<description><![CDATA[id:	11052901<br />first:	1368709216<br />last:	0<br />md5:	a3690b8d264835112175fcd063433e70<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a3690b8d264835112175fcd063433e70<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	TR/Drop.Small.PQ.107<br />url:	http://wpe-pro.at.ua/Setup.rar<br />recent:	up<br />response:	alive<br />ip:	193.109.247.62<br />as:	ASNA.193.109.246.0 - 193.109.247.255<br />review:	193.109.247.62<br />domain:	wpe-pro.at.ua<br />country:	VG<br />source:	RIPE<br />email:	abuse@compubyte.vg<br />inetnum:	193.109.246.0 - 193.109.247.255<br />netname:	UCOZ-NET<br />descr:	Compubyte Limited<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wherebrasil.com.br/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11052900</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Adl.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11052900</guid>
			<pubDate>2013-05-16T15:00:16+02:00</pubDate>
			<description><![CDATA[id:	11052900<br />first:	1368709216<br />last:	0<br />md5:	a103e428a1f63e663da79a23faa3d81b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a103e428a1f63e663da79a23faa3d81b<br />vt_score:	19/46 (41.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.Adl.1<br />url:	http://wherebrasil.com.br/<br />recent:	up<br />response:	alive<br />ip:	187.45.193.178<br />as:	AS27715<br />review:	187.45.193.178<br />domain:	wherebrasil.com.br<br />country:	BR<br />source:	LACNIC<br />email:	regcom@locaweb.com.br<br />inetnum:	187.45.192.0 - 187.45.223.255<br />netname:	002.351.877/0001-52<br />descr:	Locaweb Serviços de Internet S/A<br />ns1:	ns3.locaweb.com.br<br />ns2:	ns2.locaweb.com.br<br />ns3:	ns1.locaweb.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://waibling.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11052134</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInject.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11052134</guid>
			<pubDate>2013-05-16T14:20:05+02:00</pubDate>
			<description><![CDATA[id:	11052134<br />first:	1368706805<br />last:	0<br />md5:	c2ab6322113790a2fd29eca932926937<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c2ab6322113790a2fd29eca932926937<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	HTML/ScrInject.AC<br />url:	http://waibling.de/<br />recent:	up<br />response:	alive<br />ip:	94.102.217.135<br />as:	AS41078<br />review:	94.102.217.135<br />domain:	waibling.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@antagus.de<br />inetnum:	94.102.216.0 - 94.102.219.255<br />netname:	NETBEAT-HOSTING<br />descr:	NetBeat Domain Hosting FarmAntagus GmbH<br />ns1:	ns2.netbeat.de<br />ns2:	ns1.netbeat.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://uc-cairate.it/esempio3/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11048783</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.R.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11048783</guid>
			<pubDate>2013-05-16T13:30:18+02:00</pubDate>
			<description><![CDATA[id:	11048783<br />first:	1368703818<br />last:	0<br />md5:	ebeadef380c63cb98da98739a736cd61<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ebeadef380c63cb98da98739a736cd61<br />vt_score:	28/45 (62.2%)<br />scanner:	avira<br />virusname:	JS/Blacole.R.2<br />url:	http://uc-cairate.it/esempio3/index.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.163<br />domain:	uc-cairate.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tr-angelreisen.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11047596</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.brb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11047596</guid>
			<pubDate>2013-05-16T12:50:03+02:00</pubDate>
			<description><![CDATA[id:	11047596<br />first:	1368701403<br />last:	0<br />md5:	c3354e1d8738f519b4aeb32940223243<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.brb<br />url:	http://tr-angelreisen.de/<br />recent:	up<br />response:	alive<br />ip:	212.12.112.25<br />as:	AS12595<br />review:	212.12.112.25<br />domain:	tr-angelreisen.de<br />country:	DE<br />source:	RIPE<br />email:	hostmaster@expressmedia.de<br />inetnum:	212.12.112.0 - 212.12.112.255<br />netname:	DE-EXPRESSMEDIA-NET2<br />descr:	httpmops.net<br />ns1:	dns1.domainmedia.net<br />ns2:	dns2.domainmedia.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tourismus-fuer-alle.at/umgang/skins/common/ajax.js?116=]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11047014</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_ONLOAD.SMB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11047014</guid>
			<pubDate>2013-05-16T12:40:08+02:00</pubDate>
			<description><![CDATA[id:	11047014<br />first:	1368700808<br />last:	0<br />md5:	483dcfa269b8971d611e6a077de43553<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=483dcfa269b8971d611e6a077de43553<br />vt_score:	23/46 (50%)<br />scanner:	trendmicro<br />virusname:	JS_ONLOAD.SMB<br />url:	http://tourismus-fuer-alle.at/umgang/skins/common/ajax.js?116=<br />recent:	up<br />response:	alive<br />ip:	85.13.144.164<br />as:	AS34788<br />review:	85.13.144.164<br />domain:	tourismus-fuer-alle.at<br />country:	DE<br />source:	RIPE<br />email:	ip@all-inkl.com<br />inetnum:	85.13.128.0 - 85.13.191.255<br />netname:	DE-ALL-INKL-20050405<br />descr:	Neue Medien Muennich<br />ns1:	ns5.kasserver.com<br />ns2:	ns6.kasserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://syga.pl/js_s/checkForm.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11046231</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SU]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11046231</guid>
			<pubDate>2013-05-16T11:50:04+02:00</pubDate>
			<description><![CDATA[id:	11046231<br />first:	1368697804<br />last:	0<br />md5:	d463eee4cc74990745db11555dc4b3cb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d463eee4cc74990745db11555dc4b3cb<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.SU<br />url:	http://syga.pl/js_s/checkForm.js<br />recent:	up<br />response:	alive<br />ip:	93.157.100.49<br />as:	AS44514<br />review:	93.157.100.49<br />domain:	syga.pl<br />country:	PL<br />source:	RIPE<br />email:	admin@ogicom.pl<br />inetnum:	93.157.96.0 - 93.157.103.255<br />netname:	OGICOM<br />descr:	Ogicom Sp. z o.o.Ogicom Sp. z o.o.<br />ns1:	ns2.blink.pl<br />ns2:	ns1.blink.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rosario-bloemen.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11041823</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Iframe.ATT]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11041823</guid>
			<pubDate>2013-05-16T09:10:16+02:00</pubDate>
			<description><![CDATA[id:	11041823<br />first:	1368688216<br />last:	0<br />md5:	6793759ec1c2910cd864a1abdab0f1e0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6793759ec1c2910cd864a1abdab0f1e0<br />vt_score:	7/36 (19.4%)<br />scanner:	BitDefender<br />virusname:	Trojan.Iframe.ATT<br />url:	http://rosario-bloemen.nl/<br />recent:	up<br />response:	alive<br />ip:	81.169.145.162<br />as:	AS6724<br />review:	81.169.145.162<br />domain:	rosario-bloemen.nl<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	shades01.rzone.de<br />ns2:	docks06.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://reiseinfousa.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11041820</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11041820</guid>
			<pubDate>2013-05-16T09:10:14+02:00</pubDate>
			<description><![CDATA[id:	11041820<br />first:	1368688214<br />last:	0<br />md5:	4d7db418544ed1e50008b66577b0cbe8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d7db418544ed1e50008b66577b0cbe8<br />vt_score:	0/36 (0.0%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-inf<br />url:	http://reiseinfousa.de/<br />recent:	up<br />response:	alive<br />ip:	87.238.192.102<br />as:	AS24989<br />review:	87.238.192.102<br />domain:	reiseinfousa.de<br />country:	DE<br />source:	RIPE<br />email:	info@evanzo.de<br />inetnum:	87.238.192.0 - 87.238.199.255<br />netname:	DE-EVANZO-20060120<br />descr:	EVANZO e-commerce GmbHEVANZO-Frankfurt<br />ns1:	ns1.evanzo.com<br />ns2:	ns2.evanzo.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rbm.co.in/SpryAssets/SpryMenuBar.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11040688</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.P]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11040688</guid>
			<pubDate>2013-05-16T08:30:18+02:00</pubDate>
			<description><![CDATA[id:	11040688<br />first:	1368685818<br />last:	0<br />md5:	1e79fdacf5d5f7a7e1440cf19cc4b776<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1e79fdacf5d5f7a7e1440cf19cc4b776<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	JS/Blacole.P<br />url:	http://rbm.co.in/SpryAssets/SpryMenuBar.js<br />recent:	up<br />response:	alive<br />ip:	115.112.177.82<br />as:	AS4755<br />review:	115.112.177.82<br />domain:	rbm.co.in<br />country:	IN<br />source:	APNIC<br />email:	ip.admin@vsnl.co.in<br />inetnum:	115.112.0.0 - 115.119.255.255<br />netname:	TATACOMM-IN<br />descr:	Internet Service ProviderTATA Communications formerly VSNL is Leading ISP,Data and Voice Carrier in India<br />ns1:	kuma110788.mercury.orderbox-dns.com<br />ns2:	kuma110788.venus.orderbox-dns.com<br />ns3:	kuma110788.mars.orderbox-dns.com<br />ns4:	kuma110788.earth.orderbox-dns.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ptcgujarat.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11040483</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.NX.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11040483</guid>
			<pubDate>2013-05-16T08:20:03+02:00</pubDate>
			<description><![CDATA[id:	11040483<br />first:	1368685203<br />last:	0<br />md5:	9b9351f571a85f94731169eb51f121c6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9b9351f571a85f94731169eb51f121c6<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.NX.2<br />url:	http://ptcgujarat.org/<br />recent:	up<br />response:	alive<br />ip:	180.149.245.195<br />as:	AS33480<br />review:	180.149.245.195<br />domain:	ptcgujarat.org<br />country:	IN<br />source:	APNIC<br />email:	abuse@webwerks.com<br />inetnum:	180.149.240.0 - 180.149.245.255<br />netname:	WEBWERKS1-AP<br />descr:	Web Werks India Pvt. Ltd.<br />ns1:	ns2.linkaufbauservice.biz<br />ns2:	ns1.linkaufbauservice.biz<br />ns3:	ns1.nexus4live.com<br />ns4:	ns6.rtcserver.com<br />ns5:	ns5.rtcserver.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pohladnice.gjar-po.sk/~nationalparks/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11040040</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11040040</guid>
			<pubDate>2013-05-16T07:50:03+02:00</pubDate>
			<description><![CDATA[id:	11040040<br />first:	1368683403<br />last:	0<br />md5:	3fe38f052695c9fe4cc1271874ecf496<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3fe38f052695c9fe4cc1271874ecf496<br />vt_score:	18/46 (39.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://pohladnice.gjar-po.sk/~nationalparks/<br />recent:	up<br />response:	alive<br />ip:	193.87.77.242<br />as:	AS2607<br />review:	193.87.77.242<br />domain:	gjar-po.sk<br />country:	SK<br />source:	RIPE<br />email:	horvath@sanet.sk<br />inetnum:	193.87.0.0 - 193.87.255.255<br />netname:	SK-SANET-930901<br />descr:	Slovak Academic NetworkProvider Local RegistrySANET-AS2607-BLOCK<br />ns1:	rayman.gjar-po.sk<br />ns2:	ns.cnl.tuke.sk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mobilemarketing.com.pl/bellodecor/galeria1/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11036814</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11036814</guid>
			<pubDate>2013-05-16T05:30:04+02:00</pubDate>
			<description><![CDATA[id:	11036814<br />first:	1368675004<br />last:	0<br />md5:	d88039d36e3e2a4ca331119439bdcb62<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d88039d36e3e2a4ca331119439bdcb62<br />vt_score:	6/27 (22.2%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://mobilemarketing.com.pl/bellodecor/galeria1/index.html<br />recent:	up<br />response:	alive<br />ip:	89.161.158.77<br />as:	AS12824<br />review:	89.161.158.77<br />domain:	mobilemarketing.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mlfun.org.ua/progi/gun.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11036813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Joke/Gun]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11036813</guid>
			<pubDate>2013-05-16T05:30:04+02:00</pubDate>
			<description><![CDATA[id:	11036813<br />first:	1368675004<br />last:	0<br />md5:	e320cd59c4e397a5e3eeef2b94dcab0b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e320cd59c4e397a5e3eeef2b94dcab0b<br />vt_score:	21/45 (46.7%)<br />scanner:	undef<br />virusname:	Joke/Gun<br />url:	http://mlfun.org.ua/progi/gun.rar<br />recent:	up<br />response:	alive<br />ip:	212.111.196.162<br />as:	AS12687<br />review:	212.111.196.162<br />domain:	mlfun.org.ua<br />country:	UA<br />source:	RIPE<br />email:	abuse@uran.net.ua<br />inetnum:	212.111.192.0 - 212.111.223.255<br />netname:	UA-URAN-990525<br />descr:	Association of users of Ukranian Research & Academic Network "URAN"<br />ns1:	ns.mlfun.org.ua<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://microanalise.com.br/eixo]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11033574</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.GA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11033574</guid>
			<pubDate>2013-05-16T04:50:04+02:00</pubDate>
			<description><![CDATA[id:	11033574<br />first:	1368672604<br />last:	0<br />md5:	2865c85cc1016a2419b1592388c4d5bb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2865c85cc1016a2419b1592388c4d5bb<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	JS/Redirector.GA<br />url:	http://microanalise.com.br/eixo<br />recent:	up<br />response:	alive<br />ip:	187.17.96.41<br />as:	AS15201<br />review:	187.17.96.41<br />domain:	microanalise.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.17.64.0 - 187.17.127.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns3.dominios.uol.com.br<br />ns2:	ns1.dominios.uol.com.br<br />ns3:	ns2.dominios.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://megaboxtv.info/downloads/DONGLE2.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11033566</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Sdbot.A.109]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11033566</guid>
			<pubDate>2013-05-16T04:30:06+02:00</pubDate>
			<description><![CDATA[id:	11033566<br />first:	1368671406<br />last:	0<br />md5:	88d5e76dfcb2104fcde7969b969ceed4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=88d5e76dfcb2104fcde7969b969ceed4<br />vt_score:	34/45 (75.6%)<br />scanner:	avira<br />virusname:	BDS/Sdbot.A.109<br />url:	http://megaboxtv.info/downloads/DONGLE2.zip<br />recent:	up<br />response:	alive<br />ip:	173.192.13.202<br />as:	AS36351<br />review:	173.192.13.202<br />domain:	megaboxtv.info<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	173.192.0.0 - 173.193.255.255<br />netname:	SOFTLAYER-4-8<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns1.googlemkt.com.br<br />ns2:	ns2.googlemkt.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://medizinprodukte-praxisartikel.de]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11033565</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.azb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11033565</guid>
			<pubDate>2013-05-16T04:30:06+02:00</pubDate>
			<description><![CDATA[id:	11033565<br />first:	1368671406<br />last:	0<br />md5:	0ab4e1275934fe796c31a0d863a84e70<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0ab4e1275934fe796c31a0d863a84e70<br />vt_score:	14/42 (33.3%)<br />scanner:	avira<br />virusname:	HTML/IFrame.azb<br />url:	http://medizinprodukte-praxisartikel.de<br />recent:	up<br />response:	alive<br />ip:	81.169.145.90<br />as:	AS6724<br />review:	81.169.145.90<br />domain:	medizinprodukte-praxisartikel.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	shades10.rzone.de<br />ns2:	docks14.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://luzonviviendas.com.ar/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11033011</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.IFrame]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11033011</guid>
			<pubDate>2013-05-16T04:00:08+02:00</pubDate>
			<description><![CDATA[id:	11033011<br />first:	1368669608<br />last:	0<br />md5:	00d114241ceac81d4177fd5323648426<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=00d114241ceac81d4177fd5323648426<br />vt_score:	12/41 (29.3%)<br />scanner:	undef<br />virusname:	Trojan.JS.IFrame<br />url:	http://luzonviviendas.com.ar/home.html<br />recent:	up<br />response:	alive<br />ip:	200.59.119.132<br />as:	AS11311<br />review:	200.59.119.132<br />domain:	luzonviviendas.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	nets@uolsinectis.com.ar<br />inetnum:	200.59.112.0 - 200.59.127.255<br />netname:	AR-SISA7-LACNIC<br />descr:	Sinectis S.A.Florida, 537, Piso 6C1005AAK - BuenosAires -Florida, 537, piso 4C1005AAK - BuenosAires -<br />ns1:	ns2.sinectis.com.ar<br />ns2:	ns1.sinectis.com.ar<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=mandidee-pixandvideo&amp;]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11031274</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11031274</guid>
			<pubDate>2013-05-16T02:50:07+02:00</pubDate>
			<description><![CDATA[id:	11031274<br />first:	1368665407<br />last:	0<br />md5:	aa131e607d465e227d15d84519018252<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aa131e607d465e227d15d84519018252<br />vt_score:	22/33 (66.7%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=mandidee-pixandvideo&amp;<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://korozja.com.pl/logo/4f64eb7555e17]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11030410</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/C99Shell.AK]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11030410</guid>
			<pubDate>2013-05-16T02:20:07+02:00</pubDate>
			<description><![CDATA[id:	11030410<br />first:	1368663607<br />last:	0<br />md5:	0a4d17d0b3e6551cde71a09cc2070490<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0a4d17d0b3e6551cde71a09cc2070490<br />vt_score:	20/38 (52.6%)<br />scanner:	avira<br />virusname:	PHP/C99Shell.AK<br />url:	http://korozja.com.pl/logo/4f64eb7555e17<br />recent:	up<br />response:	alive<br />ip:	89.161.128.29<br />as:	AS12824<br />review:	89.161.128.29<br />domain:	korozja.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://katja-veit.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11029813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Afreim.W]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11029813</guid>
			<pubDate>2013-05-16T02:00:14+02:00</pubDate>
			<description><![CDATA[id:	11029813<br />first:	1368662414<br />last:	0<br />md5:	65a911d6079369efd76d136b879d9db1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=65a911d6079369efd76d136b879d9db1<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	HTML/Afreim.W<br />url:	http://katja-veit.de/<br />recent:	up<br />response:	alive<br />ip:	83.137.100.201<br />as:	AS31442<br />review:	83.137.100.201<br />domain:	katja-veit.de<br />country:	DE<br />source:	RIPE<br />email:	hostmaster@terions.de<br />inetnum:	83.137.100.192 - 83.137.100.223<br />netname:	FRITSCH<br />descr:	Fritsch IP SpaceTERIONS PA BLOCK<br />ns1:	ns1.rent-a-bind.de<br />ns2:	ns2.rent-a-bind.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jjauto.co.kr/image/num.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11028234</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11028234</guid>
			<pubDate>2013-05-16T01:30:07+02:00</pubDate>
			<description><![CDATA[id:	11028234<br />first:	1368660607<br />last:	0<br />md5:	2b295ce0fd10b9cb625e26ce88aec857<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2b295ce0fd10b9cb625e26ce88aec857<br />vt_score:	19/45 (42.2%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen3<br />url:	http://jjauto.co.kr/image/num.gif<br />recent:	up<br />response:	alive<br />ip:	112.175.11.233<br />as:	AS132524<br />review:	112.175.11.233<br />domain:	jjauto.co.kr<br />country:	KR<br />source:	APNIC<br />email:	<br />inetnum:	112.160.0.0 - 112.175.255.255<br />netname:	<br />descr:	<br />ns1:	ns2.cafe24.com<br />ns2:	ns.cafe24.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://iz.la/soft/dital/MformatV1.00.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11028233</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/StartPage.psb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11028233</guid>
			<pubDate>2013-05-16T01:20:11+02:00</pubDate>
			<description><![CDATA[id:	11028233<br />first:	1368660011<br />last:	0<br />md5:	022342cb2f2bbcc7ffee38529f8d803f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=022342cb2f2bbcc7ffee38529f8d803f<br />vt_score:	13/45 (28.9%)<br />scanner:	avira<br />virusname:	VBS/StartPage.psb<br />url:	http://iz.la/soft/dital/MformatV1.00.zip<br />recent:	up<br />response:	alive<br />ip:	124.118.138.30<br />as:	AS4134<br />review:	124.118.138.30<br />domain:	iz.la<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	124.118.0.0 - 124.119.255.255<br />netname:	CHINANET-XJ<br />descr:	CHINANET Xinjiang province networkChina TelecomNo1,jin-rong StreetBeijing 100032From Xinjiang Network of ChinaTelecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://foxpa.ws/dist/DFind_1.0.9.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11022604</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/DFind.A.8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11022604</guid>
			<pubDate>2013-05-15T22:30:08+02:00</pubDate>
			<description><![CDATA[id:	11022604<br />first:	1368649808<br />last:	0<br />md5:	2cb97dee10518f042f579d198afdd0da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2cb97dee10518f042f579d198afdd0da<br />vt_score:	28/35 (80%)<br />scanner:	avira<br />virusname:	SPR/DFind.A.8<br />url:	http://foxpa.ws/dist/DFind_1.0.9.rar<br />recent:	up<br />response:	alive<br />ip:	37.247.53.18<br />as:	AS34971<br />review:	37.247.53.18<br />domain:	foxpa.ws<br />country:	IT<br />source:	RIPE<br />email:	sciacco@iperweb.com<br />inetnum:	37.247.48.0 - 37.247.55.255<br />netname:	IT-PROMETEUSIPERWEB-20120418<br />descr:	Prometeus di Daniela AgroPrometeus Fist PA Block<br />ns1:	ns4.furrydns.org<br />ns2:	ns2.furrydns.org<br />ns3:	ns6.furrydns.org<br />ns4:	ns3.furrydns.org<br />ns5:	ns5.furrydns.org<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://filmdoni.ir/new.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11022602</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Spage.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11022602</guid>
			<pubDate>2013-05-15T22:30:07+02:00</pubDate>
			<description><![CDATA[id:	11022602<br />first:	1368649807<br />last:	0<br />md5:	96327522b657343b6f8654ea8bf8ee88<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=96327522b657343b6f8654ea8bf8ee88<br />vt_score:	14/35 (40%)<br />scanner:	avira<br />virusname:	HTML/Spage.B<br />url:	http://filmdoni.ir/new.htm<br />recent:	up<br />response:	alive<br />ip:	199.19.95.103<br />as:	AS22923<br />review:	199.19.95.103<br />domain:	filmdoni.ir<br />country:	CA<br />source:	ARIN<br />email:	peterk@yesup.com<br />inetnum:	199.19.92.0 - 199.19.95.255<br />netname:	YESUP-COM<br />descr:	Yesup Ecommerce Solutions Inc. YESUP 565 Gordon Baker Road North York ON M2H-2W2<br />ns1:	ns2.rozblog.com<br />ns2:	ns1.rozblog.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://emotions-parfums.info/cartes/Betty_barclay/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11018778</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_ONLOAD.SMD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11018778</guid>
			<pubDate>2013-05-15T21:00:18+02:00</pubDate>
			<description><![CDATA[id:	11018778<br />first:	1368644418<br />last:	0<br />md5:	2d9fd82a4c9d086c7601dbc1f098faab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2d9fd82a4c9d086c7601dbc1f098faab<br />vt_score:	20/45 (44.4%)<br />scanner:	trendmicro<br />virusname:	JS_ONLOAD.SMD<br />url:	http://emotions-parfums.info/cartes/Betty_barclay/index.html<br />recent:	up<br />response:	alive<br />ip:	82.165.52.35<br />as:	AS8560<br />review:	82.165.52.35<br />domain:	emotions-parfums.info<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.48.0 - 82.165.63.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns12.1and1.fr<br />ns2:	ns11.1and1.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://business.org.br/BUSINESS/FranqPropor.asp?cod=6]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11008402</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.ggb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11008402</guid>
			<pubDate>2013-05-15T15:00:24+02:00</pubDate>
			<description><![CDATA[id:	11008402<br />first:	1368622824<br />last:	0<br />md5:	2f6fe2839f330dfbe00cac04c7afee12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f6fe2839f330dfbe00cac04c7afee12<br />vt_score:	13/46 (28.3%)<br />scanner:	avira<br />virusname:	JS/Agent.ggb<br />url:	http://business.org.br/BUSINESS/FranqPropor.asp?cod=6<br />recent:	up<br />response:	alive<br />ip:	200.248.178.54<br />as:	AS4230<br />review:	200.248.178.54<br />domain:	business.org.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@embratel.net.br<br />inetnum:	200.248.0.0 - 200.248.255.255<br />netname:	033.530.486/0001-29<br />descr:	EMBRATEL-EMPRESA BRASILEIRA DE TELECOMUNICAÇÕES SA<br />ns1:	mail4.business.org.br<br />ns2:	ns2.business.org.br<br />ns3:	business.business.org.br<br />ns4:	mail.business.org.br<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ataque.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11004627</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11004627</guid>
			<pubDate>2013-05-15T12:30:07+02:00</pubDate>
			<description><![CDATA[id:	11004627<br />first:	1368613807<br />last:	0<br />md5:	c854a85d86ce20360aa80931388fbdd9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c854a85d86ce20360aa80931388fbdd9<br />vt_score:	27/42 (64.3%)<br />scanner:	avira<br />virusname:	JS/Expack.VU.1<br />url:	http://ataque.org/<br />recent:	up<br />response:	alive<br />ip:	210.188.235.105<br />as:	AS4725<br />review:	210.188.235.105<br />domain:	ataque.org<br />country:	JP<br />source:	APNIC<br />email:	abuse@odn.ad.jp<br />inetnum:	210.188.0.0 - 210.191.255.255<br />netname:	JPNIC-NET-JP<br />descr:	Japan Network Information CenterTOKYO TELECOMMUNICATION NETWORK CO.,INC.<br />ns1:	ns2.ccc-ns.net<br />ns2:	ns.ccc-ns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://area51service.it/switchicon.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11003227</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11003227</guid>
			<pubDate>2013-05-15T11:10:16+02:00</pubDate>
			<description><![CDATA[id:	11003227<br />first:	1368609016<br />last:	0<br />md5:	ad039c66f7f022d1ee40bb5393438d2f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ad039c66f7f022d1ee40bb5393438d2f<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://area51service.it/switchicon.js<br />recent:	up<br />response:	alive<br />ip:	195.88.6.245<br />as:	AS48815<br />review:	195.88.6.245<br />domain:	area51service.it<br />country:	IT<br />source:	RIPE<br />email:	info@criticalcase.com<br />inetnum:	195.88.6.0 - 195.88.7.255<br />netname:	CriticalCase<br />descr:	CriticalCase srl<br />ns1:	nsrm.dnsitalia.net<br />ns2:	ns2.dnsitalia.net<br />ns3:	nsct.dnsitalia.net<br />ns4:	ns1.dnsitalia.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://area51service.it/switchcontent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11003226</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11003226</guid>
			<pubDate>2013-05-15T11:10:16+02:00</pubDate>
			<description><![CDATA[id:	11003226<br />first:	1368609016<br />last:	0<br />md5:	d07374b508ac5a9052a2411868ebb304<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d07374b508ac5a9052a2411868ebb304<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://area51service.it/switchcontent.js<br />recent:	up<br />response:	alive<br />ip:	195.88.6.245<br />as:	AS48815<br />review:	195.88.6.245<br />domain:	area51service.it<br />country:	IT<br />source:	RIPE<br />email:	info@criticalcase.com<br />inetnum:	195.88.6.0 - 195.88.7.255<br />netname:	CriticalCase<br />descr:	CriticalCase srl<br />ns1:	nsrm.dnsitalia.net<br />ns2:	ns2.dnsitalia.net<br />ns3:	nsct.dnsitalia.net<br />ns4:	ns1.dnsitalia.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://alles-ist-relativ.de/rollover.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11001991</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11001991</guid>
			<pubDate>2013-05-15T10:40:05+02:00</pubDate>
			<description><![CDATA[id:	11001991<br />first:	1368607205<br />last:	0<br />md5:	563a44bbbd8a464fe12955d87efcd628<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=563a44bbbd8a464fe12955d87efcd628<br />vt_score:	16/36 (44.4%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA Trj<br />url:	http://alles-ist-relativ.de/rollover.js<br />recent:	up<br />response:	alive<br />ip:	82.165.89.134<br />as:	AS8560<br />review:	82.165.89.134<br />domain:	alles-ist-relativ.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns17.schlund.de<br />ns2:	ns18.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://agifors.org/symposium2002/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11001268</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11001268</guid>
			<pubDate>2013-05-15T10:00:24+02:00</pubDate>
			<description><![CDATA[id:	11001268<br />first:	1368604824<br />last:	0<br />md5:	ef3ef644321519e8519b40cbeabd42e3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ef3ef644321519e8519b40cbeabd42e3<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://agifors.org/symposium2002/<br />recent:	up<br />response:	alive<br />ip:	212.252.39.6<br />as:	AS6822<br />review:	212.252.39.6<br />domain:	agifors.org<br />country:	TR<br />source:	RIPE<br />email:	solip@superonline.net<br />inetnum:	212.252.0.0 - 212.252.127.255<br />netname:	SOLNET-3-1<br />descr:	SuperOnline Inc.Superonline RO-2Superonline RO-1-1<br />ns1:	ns1.globalforte.com<br />ns2:	ns2.globalforte.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://122.224.9.35:85/tt/6.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10999907</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.39008.8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10999907</guid>
			<pubDate>2013-05-15T08:50:03+02:00</pubDate>
			<description><![CDATA[id:	10999907<br />first:	1368600603<br />last:	0<br />md5:	ab17a044bfea0ce90e438930b8297ffe<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ab17a044bfea0ce90e438930b8297ffe<br />vt_score:	40/46 (87%)<br />scanner:	avira<br />virusname:	TR/Kazy.39008.8<br />url:	http://122.224.9.35:85/tt/6.exe<br />recent:	up<br />response:	alive<br />ip:	122.224.9.35<br />as:	AS4134<br />review:	122.224.9.35<br />domain:	122.224.9.35<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@mail.sxptt.zj.cn<br />inetnum:	122.224.9.0 - 122.224.9.255<br />netname:	NINBO-LANZHONG-LTD<br />descr:	Ninbo Lanzhong Network Ltd<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://woppsen.de/chatter/htms/sauerlandboy14.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10996862</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Fujacks.iFrame]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10996862</guid>
			<pubDate>2013-05-15T06:40:08+02:00</pubDate>
			<description><![CDATA[id:	10996862<br />first:	1368592808<br />last:	0<br />md5:	2bc4a4c67b1f606dbd8f7b0c8ded0985<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2bc4a4c67b1f606dbd8f7b0c8ded0985<br />vt_score:	34/43 (79.1%)<br />scanner:	avira<br />virusname:	HTML/Fujacks.iFrame<br />url:	http://woppsen.de/chatter/htms/sauerlandboy14.htm<br />recent:	up<br />response:	alive<br />ip:	85.31.1.33<br />as:	AS21013<br />review:	85.31.1.33<br />domain:	woppsen.de<br />country:	AT<br />source:	RIPE<br />email:	hostmaster@itandtel.at<br />inetnum:	85.31.1.0 - 85.31.1.255<br />netname:	NETZPIONIER-AT-NET-03<br />descr:	NETZPIONIER Hannes MinimairITANDTEL, Wels, AUSTRIA<br />ns1:	ns1.ourdns.org<br />ns2:	ns3.ourdns.org<br />ns3:	ns2.ourdns.org<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://silver-light.org/Eng8000/Eng1000.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10987801</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.QNP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10987801</guid>
			<pubDate>2013-05-15T03:40:07+02:00</pubDate>
			<description><![CDATA[id:	10987801<br />first:	1368582007<br />last:	0<br />md5:	06ee7bad2b6aed1c82d268cae48893f3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=06ee7bad2b6aed1c82d268cae48893f3<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	JS/Agent.QNP<br />url:	http://silver-light.org/Eng8000/Eng1000.htm<br />recent:	up<br />response:	alive<br />ip:	50.116.99.161<br />as:	AS36351<br />review:	50.116.99.161<br />domain:	silver-light.org<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	50.116.64.0 - 50.116.127.255<br />netname:	HGBLOCK-3<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns3744.hostgator.com<br />ns2:	ns3743.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://open-std.org/JTC1/SC22/WG15/iso14766/325]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10979572</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Mydoom.F]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10979572</guid>
			<pubDate>2013-05-15T00:10:16+02:00</pubDate>
			<description><![CDATA[id:	10979572<br />first:	1368569416<br />last:	0<br />md5:	69cb79b7c9198f10506f8065fc286a1c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=69cb79b7c9198f10506f8065fc286a1c<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	WORM/Mydoom.F<br />url:	http://open-std.org/JTC1/SC22/WG15/iso14766/325<br />recent:	up<br />response:	alive<br />ip:	93.90.116.65<br />as:	AS45032<br />review:	93.90.116.65<br />domain:	open-std.org<br />country:	DK<br />source:	RIPE<br />email:	root@fab-it.dk<br />inetnum:	93.90.112.0 - 93.90.127.255<br />netname:	DK-FAB-IT-20080422<br />descr:	FabFabVesterbrogade 50 1. tv.1620 København VDanmark<br />ns1:	ns3.gratisdns.dk<br />ns2:	ns1.gratisdns.dk<br />ns3:	ns4.gratisdns.dk<br />ns4:	ns5.gratisdns.dk<br />ns5:	ns2.gratisdns.dk<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://inet-tr.org.tr/inetconf6/inet-forum/Oct/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10972250</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10972250</guid>
			<pubDate>2013-05-14T20:20:06+02:00</pubDate>
			<description><![CDATA[id:	10972250<br />first:	1368555606<br />last:	0<br />md5:	f20c8b1fe44c715925e20e701eb02c7d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f20c8b1fe44c715925e20e701eb02c7d<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://inet-tr.org.tr/inetconf6/inet-forum/Oct/<br />recent:	up<br />response:	alive<br />ip:	139.179.130.61<br />as:	AS8466<br />review:	139.179.130.61<br />domain:	inet-tr.org.tr<br />country:	TR<br />source:	RIPE<br />email:	cayfer@bilkent.edu.tr<br />inetnum:	139.179.0.0 - 139.179.255.255<br />netname:	TR-BILNET<br />descr:	Bilkent UniversityP.O. Box 806572 Maltepe, AnkaraBilkent UniversityBilkent, Ankara 06800TURKEYBilkent UniversityBilkent, Ankara 06800TURKEY<br />ns1:	ns1.aygen.org<br />ns2:	akgul.bilkent.edu.tr<br />ns3:	yuce.ubak.gov.tr<br />ns4:	admin.bilkent.edu.tr<br />ns5:	sinan.sfk.org.tr<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://file.myfiles.com.cn/Safe/myfiles_roundce_mima.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10966586</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/PSW.VB.F]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10966586</guid>
			<pubDate>2013-05-14T18:50:04+02:00</pubDate>
			<description><![CDATA[id:	10966586<br />first:	1368550204<br />last:	0<br />md5:	c0cab827c77233d7cfeb193f28fa27eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c0cab827c77233d7cfeb193f28fa27eb<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	SPR/PSW.VB.F<br />url:	http://file.myfiles.com.cn/Safe/myfiles_roundce_mima.rar<br />recent:	up<br />response:	alive<br />ip:	222.218.45.177<br />as:	AS132524<br />review:	121.11.151.71<br />domain:	myfiles.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	222.218.0.0 - 222.218.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom<br />ns1:	dns7.hichina.com<br />ns2:	dns8.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://blackwarez.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10957202</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.T]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10957202</guid>
			<pubDate>2013-05-14T13:30:03+02:00</pubDate>
			<description><![CDATA[id:	10957202<br />first:	1368531003<br />last:	0<br />md5:	3739528e6f1089ecc1ca22ea0a5d5574<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3739528e6f1089ecc1ca22ea0a5d5574<br />vt_score:	21/46 (45.7%)<br />scanner:	avira<br />virusname:	JS/RunForest.T<br />url:	http://blackwarez.pl/<br />recent:	up<br />response:	alive<br />ip:	91.236.52.103<br />as:	AS57239<br />review:	91.236.52.103<br />domain:	blackwarez.pl<br />country:	PL<br />source:	RIPE<br />email:	piotr.chrostek@globalnetwork.pl<br />inetnum:	91.236.52.0 - 91.236.55.255<br />netname:	BLUE-LEAF<br />descr:	BLUE LEAF Sp. z o.o.BlueLeafBlueLeaf<br />ns1:	ns1.blcluster.net<br />ns2:	ns2.blcluster.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://apstudio-pc.it]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10950951</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML_IFRAME.SMDC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10950951</guid>
			<pubDate>2013-05-14T11:00:05+02:00</pubDate>
			<description><![CDATA[id:	10950951<br />first:	1368522005<br />last:	0<br />md5:	7178908853529a6abb445a9752a10318<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7178908853529a6abb445a9752a10318<br />vt_score:	9/36 (25%)<br />scanner:	trendmicro<br />virusname:	HTML_IFRAME.SMDC<br />url:	http://apstudio-pc.it<br />recent:	up<br />response:	alive<br />ip:	195.110.124.133<br />as:	AS12363<br />review:	195.110.124.133<br />domain:	apstudio-pc.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@dada.net<br />inetnum:	195.110.124.128 - 195.110.124.191<br />netname:	register-it<br />descr:	Register.it S.p.A.DADANETInternet Service ProviderDADANETInternet Service Provider<br />ns1:	ns2.register.it<br />ns2:	ns1.register.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://apaescolapias.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10950950</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10950950</guid>
			<pubDate>2013-05-14T11:00:05+02:00</pubDate>
			<description><![CDATA[id:	10950950<br />first:	1368522005<br />last:	0<br />md5:	205fff78d1ad2320c83768328d8791c4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=205fff78d1ad2320c83768328d8791c4<br />vt_score:	19/46 (41.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://apaescolapias.org/<br />recent:	up<br />response:	alive<br />ip:	212.227.210.154<br />as:	AS8560<br />review:	212.227.210.154<br />domain:	apaescolapias.org<br />country:	DE<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	212.227.0.0 - 212.227.255.255<br />netname:	DE-SCHLUND-980910<br />descr:	1&1 Internet AGSCHLUND-PA-2<br />ns1:	ns64.1and1.es<br />ns2:	ns63.1and1.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pc-master.co.kr/down/PCMasterSetupVer300102988.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10943396</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10943396</guid>
			<pubDate>2013-05-14T08:00:14+02:00</pubDate>
			<description><![CDATA[id:	10943396<br />first:	1368511214<br />last:	0<br />md5:	a2612f7b92204cbb49a488e67c1ff1c5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a2612f7b92204cbb49a488e67c1ff1c5<br />vt_score:	18/36 (50%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Gen<br />url:	http://pc-master.co.kr/down/PCMasterSetupVer300102988.exe<br />recent:	up<br />response:	alive<br />ip:	222.231.31.88<br />as:	AS3786<br />review:	222.231.31.88<br />domain:	pc-master.co.kr<br />country:	KR<br />source:	APNIC<br />email:	support@kidc.net<br />inetnum:	222.231.0.0 - 222.231.63.255<br />netname:	KIDC-KR<br />descr:	LG DACOM KIDC<br />ns1:	ns20.hanbiro.com<br />ns2:	ns21.hanbiro.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vesttiudx.xoom.it/fun-math75/zmxg.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10930360</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.X]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10930360</guid>
			<pubDate>2013-05-14T03:40:11+02:00</pubDate>
			<description><![CDATA[id:	10930360<br />first:	1368495611<br />last:	0<br />md5:	589f9465c48b60bc73a2decfef99368b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=589f9465c48b60bc73a2decfef99368b<br />vt_score:	18/45 (40%)<br />scanner:	avira<br />virusname:	JS/Kryptik.X<br />url:	http://vesttiudx.xoom.it/fun-math75/zmxg.js<br />recent:	up<br />response:	alive<br />ip:	212.48.16.69<br />as:	AS8660<br />review:	212.48.16.69<br />domain:	xoom.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@matrix.it<br />inetnum:	212.48.0.0 - 212.48.31.255<br />netname:	IT-MATRIX-980216<br />descr:	Matrix S.p.A.<br />ns1:	ns1.xoom.virgilio.it<br />ns2:	ns2.xoom.virgilio.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ulucam.com.tr/js/jquery-ui.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10928627</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Obfuscated-GA [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10928627</guid>
			<pubDate>2013-05-14T02:00:43+02:00</pubDate>
			<description><![CDATA[id:	10928627<br />first:	1368489643<br />last:	0<br />md5:	66e3eadf2bb1476b07f585567328e6b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=66e3eadf2bb1476b07f585567328e6b3<br />vt_score:	0/46 (0.0%)<br />scanner:	Avast<br />virusname:	JS:Obfuscated-GA [Trj]<br />url:	http://ulucam.com.tr/js/jquery-ui.min.js<br />recent:	up<br />response:	alive<br />ip:	91.102.161.11<br />as:	AS41801<br />review:	91.102.161.11<br />domain:	ulucam.com.tr<br />country:	tr<br />source:	RIPE<br />email:	aydin@datafon.com.tr<br />inetnum:	91.102.161.0 - 91.102.161.255<br />netname:	datafon<br />descr:	Datafon iletisim A.Sdatafon<br />ns1:	ns.ulucam.com.tr<br />ns2:	user-0848ed06dd<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://triaxiontms.com.au/temp-fence.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10925145</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Crypt.GG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10925145</guid>
			<pubDate>2013-05-14T00:50:13+02:00</pubDate>
			<description><![CDATA[id:	10925145<br />first:	1368485413<br />last:	0<br />md5:	4524b10061270bbf9f3e728c4ebd7fef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4524b10061270bbf9f3e728c4ebd7fef<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	JS/Crypt.GG<br />url:	http://triaxiontms.com.au/temp-fence.html<br />recent:	up<br />response:	alive<br />ip:	182.50.130.158<br />as:	AS26496<br />review:	182.50.130.158<br />domain:	triaxiontms.com.au<br />country:	SG<br />source:	APNIC<br />email:	gschwimer@godaddy.com<br />inetnum:	182.50.128.0 - 182.50.159.255<br />netname:	GODADDY-NET-SG<br />descr:	8 Cross Street#11-00 PWC Building<br />ns1:	ns01.domaincontrol.com<br />ns2:	ns02.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://triaxiontms.com.au/labour-hire.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10925144</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Crypt.GG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10925144</guid>
			<pubDate>2013-05-14T00:50:13+02:00</pubDate>
			<description><![CDATA[id:	10925144<br />first:	1368485413<br />last:	0<br />md5:	7f8a83825c849849758c4b4c51ec9a37<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7f8a83825c849849758c4b4c51ec9a37<br />vt_score:	22/46 (47.8%)<br />scanner:	AntiVir<br />virusname:	JS/Crypt.GG<br />url:	http://triaxiontms.com.au/labour-hire.html<br />recent:	up<br />response:	alive<br />ip:	182.50.130.158<br />as:	AS26496<br />review:	182.50.130.158<br />domain:	triaxiontms.com.au<br />country:	SG<br />source:	APNIC<br />email:	gschwimer@godaddy.com<br />inetnum:	182.50.128.0 - 182.50.159.255<br />netname:	GODADDY-NET-SG<br />descr:	8 Cross Street#11-00 PWC Building<br />ns1:	ns01.domaincontrol.com<br />ns2:	ns02.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tabernaculoarica.cl/audiovisual/fotos]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10921796</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10921796</guid>
			<pubDate>2013-05-13T23:20:08+02:00</pubDate>
			<description><![CDATA[id:	10921796<br />first:	1368480008<br />last:	0<br />md5:	8854d7322220c30b4818bc1c27784e04<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8854d7322220c30b4818bc1c27784e04<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.TF<br />url:	http://tabernaculoarica.cl/audiovisual/fotos<br />recent:	up<br />response:	alive<br />ip:	184.173.228.187<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	184.173.228.187<br />domain:	tabernaculoarica.cl<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	184.172.0.0 - 184.173.255.255<br />netname:	NETBLK-THEPLANET-BLK-17<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns2999.hostgator.com<br />ns2:	ns3000.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sonding.de/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10919786</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.chw]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10919786</guid>
			<pubDate>2013-05-13T21:50:11+02:00</pubDate>
			<description><![CDATA[id:	10919786<br />first:	1368474611<br />last:	0<br />md5:	aaaa156c19b589b6a487c679dd4aa609<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=425efcf7c07699e2063377677b5554da<br />vt_score:	14/46 (30.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.chw<br />url:	http://sonding.de/index.html<br />recent:	up<br />response:	alive<br />ip:	178.254.10.135<br />as:	AS24989<br />review:	178.254.10.135<br />domain:	sonding.de<br />country:	DE<br />source:	RIPE<br />email:	info@evanzo.de<br />inetnum:	178.254.0.0 - 178.254.63.255<br />netname:	DE-EVANZO-20100618<br />descr:	EVANZO e-commerce GmbHDE-EVANZO-20100618<br />ns1:	ns01.1blu.de<br />ns2:	ns02.1blu.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sh3ll.org/tool.txt]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10918158</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/ASP.Ace.AH.21]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10918158</guid>
			<pubDate>2013-05-13T20:40:05+02:00</pubDate>
			<description><![CDATA[id:	10918158<br />first:	1368470405<br />last:	0<br />md5:	4ab68d38527d5834e9c1ff64407b34fb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4ab68d38527d5834e9c1ff64407b34fb<br />vt_score:	29/42 (69%)<br />scanner:	avira<br />virusname:	BDS/ASP.Ace.AH.21<br />url:	http://sh3ll.org/tool.txt<br />recent:	up<br />response:	alive<br />ip:	69.10.52.162<br />as:	AS19318<br />review:	69.10.52.162<br />domain:	sh3ll.org<br />country:	US<br />source:	ARIN<br />email:	abuse@trouble-free.net<br />inetnum:	69.10.32.0 - 69.10.63.255<br />netname:	INTERSERVER<br />descr:	Interserver, Inc INTER-83 110 Meadowlands Pkwy 1st Floor Secaucus NJ 07094<br />ns1:	ns10.jixhost.com<br />ns2:	ns9.jixhost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sawat-water.de/scripts/ac_runactivecontent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10917138</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axi.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10917138</guid>
			<pubDate>2013-05-13T19:58:03+02:00</pubDate>
			<description><![CDATA[id:	10917138<br />first:	1368467883<br />last:	0<br />md5:	144f57a5750c78e7bc206baa70a76df0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=144f57a5750c78e7bc206baa70a76df0<br />vt_score:	15/30 (50%)<br />scanner:	avira<br />virusname:	JS/iFrame.axi.1<br />url:	http://sawat-water.de/scripts/ac_runactivecontent.js<br />recent:	up<br />response:	alive<br />ip:	87.106.112.102<br />as:	AS8560<br />review:	87.106.112.102<br />domain:	sawat-water.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	87.106.0.0 - 87.106.255.255<br />netname:	DE-SCHLUND-20050810<br />descr:	1&1 Internet AG<br />ns1:	ns55.1und1.de<br />ns2:	ns56.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nertena.hotusa.org/webcam-sindee-dildo.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10897452</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Decdec.psc]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10897452</guid>
			<pubDate>2013-05-13T12:50:08+02:00</pubDate>
			<description><![CDATA[id:	10897452<br />first:	1368442208<br />last:	0<br />md5:	1d77abdba8f286779a23148ae5d78738<br />virustotal:	<br />vt_score:	28/41 (68.3%)<br />scanner:	avira<br />virusname:	JS/Decdec.psc<br />url:	http://nertena.hotusa.org/webcam-sindee-dildo.html<br />recent:	up<br />response:	alive<br />ip:	198.23.52.87<br />as:	AS53340<br />review:	198.23.52.87<br />domain:	hotusa.org<br />country:	US<br />source:	ARIN<br />email:	abuse@propersupport.com<br />inetnum:	198.23.48.0 - 198.23.63.255<br />netname:	LIQUIDNET-HOSTING<br />descr:	LiquidNet US LLC LUL-5 1500 University Drive Coral Springs FL 33071<br />ns1:	dns2.fateback.com<br />ns2:	dns1.fateback.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kohlehydratblocker.de/kh_data/_layout1.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10892815</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10892815</guid>
			<pubDate>2013-05-13T06:10:04+02:00</pubDate>
			<description><![CDATA[id:	10892815<br />first:	1368418204<br />last:	0<br />md5:	97ab4c2358779d972a62f32675f6d9dc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=97ab4c2358779d972a62f32675f6d9dc<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://kohlehydratblocker.de/kh_data/_layout1.js<br />recent:	up<br />response:	alive<br />ip:	85.236.55.100<br />as:	AS15456<br />review:	85.236.55.100<br />domain:	kohlehydratblocker.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@internetx.de<br />inetnum:	85.236.32.0 - 85.236.63.255<br />netname:	DE-INTERNETX-20050518<br />descr:	InterNetX GmbH<br />ns1:	b.ns14.net<br />ns2:	c.ns14.net<br />ns3:	d.ns14.net<br />ns4:	a.ns14.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jtechracing.it/conto.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10890672</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.ZBot.9987452]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10890672</guid>
			<pubDate>2013-05-13T04:40:07+02:00</pubDate>
			<description><![CDATA[id:	10890672<br />first:	1368412807<br />last:	0<br />md5:	8b86fe809a1445e987cf08c5cb56c9d4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8b86fe809a1445e987cf08c5cb56c9d4<br />vt_score:	40/46 (87%)<br />scanner:	avira<br />virusname:	TR/Spy.ZBot.9987452<br />url:	http://jtechracing.it/conto.zip<br />recent:	up<br />response:	alive<br />ip:	77.238.14.138<br />as:	AS20746<br />review:	77.238.14.138<br />domain:	jtechracing.it<br />country:	IT<br />source:	RIPE<br />email:	<br />inetnum:	77.238.0.0 - 77.238.31.255<br />netname:	<br />descr:	<br />ns1:	ns1.rossoxweb.it<br />ns2:	ns2.rossoxweb.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hsgmission.org/home]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10888367</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ADD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10888367</guid>
			<pubDate>2013-05-13T01:40:07+02:00</pubDate>
			<description><![CDATA[id:	10888367<br />first:	1368402007<br />last:	0<br />md5:	cf7b8b508b23e94fa07c03400a3e77f6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cf7b8b508b23e94fa07c03400a3e77f6<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.ADD<br />url:	http://hsgmission.org/home<br />recent:	up<br />response:	alive<br />ip:	72.29.69.3<br />as:	AS33182<br />review:	72.29.69.3<br />domain:	hsgmission.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	dns5849.dizinc.com<br />ns2:	ns2.idewales.com<br />ns3:	ns1.idewales.com<br />ns4:	dns5848.dizinc.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://file.myfiles.com.cn/net/myfiles_infoking_setup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10883454</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Hupigon.A.1100]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10883454</guid>
			<pubDate>2013-05-12T21:20:06+02:00</pubDate>
			<description><![CDATA[id:	10883454<br />first:	1368386406<br />last:	0<br />md5:	2088e2d8209b888027583874d750fcec<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2088e2d8209b888027583874d750fcec<br />vt_score:	20/33 (60.6%)<br />scanner:	avira<br />virusname:	BDS/Hupigon.A.1100<br />url:	http://file.myfiles.com.cn/net/myfiles_infoking_setup.exe<br />recent:	up<br />response:	alive<br />ip:	202.100.92.222<br />as:	AS132524<br />review:	222.218.45.177<br />domain:	myfiles.com.cn<br />country:	CN<br />source:	APNIC<br />email:	<br />inetnum:	202.100.80.0 - 202.100.95.255<br />netname:	<br />descr:	<br />ns1:	dns8.hichina.com<br />ns2:	dns7.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://exportconsultants.co.th/file/eDM/ThaiLogis03/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10882523</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Illiframe-C Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10882523</guid>
			<pubDate>2013-05-12T20:40:13+02:00</pubDate>
			<description><![CDATA[id:	10882523<br />first:	1368384013<br />last:	0<br />md5:	a28c60d851787aea3d1664a0070e141d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	Avast<br />virusname:	HTML:Illiframe-C Trj<br />url:	http://exportconsultants.co.th/file/eDM/ThaiLogis03/<br />recent:	up<br />response:	alive<br />ip:	122.155.168.142<br />as:	AS9931<br />review:	122.155.168.142<br />domain:	exportconsultants.co.th<br />country:	TH<br />source:	APNIC<br />email:	abuse@idc.cattelecom.com<br />inetnum:	122.155.160.0 - 122.155.191.255<br />netname:	CAT-IDC2-Service<br />descr:	CAT IDC2 14th floor<br />ns1:	ns.exportconsultants.co.th<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://exportconsultants.co.th/file/eDM/OSP0810/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10882522</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Illiframe-C Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10882522</guid>
			<pubDate>2013-05-12T20:40:13+02:00</pubDate>
			<description><![CDATA[id:	10882522<br />first:	1368384013<br />last:	0<br />md5:	ac0fdf7187267f7652fca3d61a095f0c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ac0fdf7187267f7652fca3d61a095f0c<br />vt_score:	9/36 (25%)<br />scanner:	Avast<br />virusname:	HTML:Illiframe-C Trj<br />url:	http://exportconsultants.co.th/file/eDM/OSP0810/<br />recent:	up<br />response:	alive<br />ip:	122.155.168.142<br />as:	AS9931<br />review:	122.155.168.142<br />domain:	exportconsultants.co.th<br />country:	TH<br />source:	APNIC<br />email:	abuse@idc.cattelecom.com<br />inetnum:	122.155.160.0 - 122.155.191.255<br />netname:	CAT-IDC2-Service<br />descr:	CAT IDC2 14th floor<br />ns1:	ns.exportconsultants.co.th<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/books/wholesale-bulk-lots.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10875127</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10875127</guid>
			<pubDate>2013-05-12T17:10:07+02:00</pubDate>
			<description><![CDATA[id:	10875127<br />first:	1368371407<br />last:	0<br />md5:	1e72e55091f5425127b9cffa327348c8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1e72e55091f5425127b9cffa327348c8<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/books/wholesale-bulk-lots.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns1.stabletransit.com<br />ns2:	dns2.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cccnj.org/taiwanese/act%20ind01.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10868270</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Dldr.Psyme.6190]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10868270</guid>
			<pubDate>2013-05-12T10:30:07+02:00</pubDate>
			<description><![CDATA[id:	10868270<br />first:	1368347407<br />last:	0<br />md5:	e45bc68a73856ca7123193ba8e2559ee<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e45bc68a73856ca7123193ba8e2559ee<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/Dldr.Psyme.6190<br />url:	http://cccnj.org/taiwanese/act%20ind01.htm<br />recent:	up<br />response:	alive<br />ip:	50.22.57.39<br />as:	AS36351<br />review:	50.22.57.39<br />domain:	cccnj.org<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	50.22.0.0 - 50.23.255.255<br />netname:	SOFTLAYER-4-9<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns1.softlayer.com<br />ns2:	ns2.softlayer.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://calora.pl/oferta062010/oferta.html?keepThis=true]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10867336</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10867336</guid>
			<pubDate>2013-05-12T10:00:15+02:00</pubDate>
			<description><![CDATA[id:	10867336<br />first:	1368345615<br />last:	0<br />md5:	256c5ed52bbfa1128bd2c0334ad69e9b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=256c5ed52bbfa1128bd2c0334ad69e9b<br />vt_score:	22/45 (48.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://calora.pl/oferta062010/oferta.html?keepThis=true<br />recent:	up<br />response:	alive<br />ip:	62.129.198.82<br />as:	AS12824<br />review:	62.129.198.82<br />domain:	calora.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bus-oktoberfest.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10867335</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU!tr.dldr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10867335</guid>
			<pubDate>2013-05-12T10:00:11+02:00</pubDate>
			<description><![CDATA[id:	10867335<br />first:	1368345611<br />last:	0<br />md5:	043cddca1339bc908b54c1b16d0d1879<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=043cddca1339bc908b54c1b16d0d1879<br />vt_score:	13/46 (28.3%)<br />scanner:	undef<br />virusname:	JS/Expack.VU!tr.dldr<br />url:	http://bus-oktoberfest.it/<br />recent:	up<br />response:	alive<br />ip:	85.94.200.139<br />as:	AS12637<br />review:	85.94.200.139<br />domain:	bus-oktoberfest.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@seeweb.it<br />inetnum:	85.94.200.0 - 85.94.202.255<br />netname:	SEEWEB-DH<br />descr:	Dedicated Hosting customers<br />ns1:	dns2.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns3.arubadns.net<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://biala.salezjanie.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10866047</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.UT]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10866047</guid>
			<pubDate>2013-05-12T07:00:12+02:00</pubDate>
			<description><![CDATA[id:	10866047<br />first:	1368334812<br />last:	0<br />md5:	f0e4b6107ba94e0b1e920cbd03337799<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f0e4b6107ba94e0b1e920cbd03337799<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.UT<br />url:	http://biala.salezjanie.pl/<br />recent:	up<br />response:	alive<br />ip:	156.17.205.251<br />as:	AS8970<br />review:	156.17.205.251<br />domain:	salezjanie.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@wask.wroc.pl<br />inetnum:	156.17.0.0 - 156.17.255.255<br />netname:	WASK<br />descr:	the network covers whole Wroclaw area(a large academic centre in West-SouthernPoland)<br />ns1:	janek.salezjanie.pl<br />ns2:	filip.salezjanie.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://acd-auto.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10859548</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10859548</guid>
			<pubDate>2013-05-11T23:40:07+02:00</pubDate>
			<description><![CDATA[id:	10859548<br />first:	1368308407<br />last:	0<br />md5:	05c56b54a9c2bc42459a179bf33be2af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=05c56b54a9c2bc42459a179bf33be2af<br />vt_score:	28/46 (60.9%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://acd-auto.pl/<br />recent:	up<br />response:	alive<br />ip:	85.128.192.186<br />as:	AS15967<br />review:	85.128.192.186<br />domain:	acd-auto.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@netart.pl<br />inetnum:	85.128.168.0 - 85.128.199.255<br />netname:	NETART<br />descr:	NetArt webhosting servers<br />ns1:	ns3.netart.pl<br />ns2:	ns1.netart.pl<br />ns3:	ns2.netart.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.91.252.248/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10859046</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/JS.Crytper.VIP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10859046</guid>
			<pubDate>2013-05-11T22:40:38+02:00</pubDate>
			<description><![CDATA[id:	10859046<br />first:	1368304838<br />last:	0<br />md5:	a0e0f58c0f2c42150a4e54138ae57376<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a0e0f58c0f2c42150a4e54138ae57376<br />vt_score:	30/44 (68.2%)<br />scanner:	avira<br />virusname:	SPR/JS.Crytper.VIP<br />url:	http://74.91.252.248/index.html<br />recent:	up<br />response:	alive<br />ip:	74.91.252.248<br />as:	AS32392<br />review:	74.91.252.248<br />domain:	74.91.252.248<br />country:	US<br />source:	ARIN<br />email:	abuse@ecommerce.com<br />inetnum:	74.91.128.0 - 74.91.255.255<br />netname:	ECOMM-201105<br />descr:	Ecommerce Corporation ECOMM-5 1774 Dividend Dr Columbus OH 43228<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://24.duote.com.cn/yxftv.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10859032</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.zgt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10859032</guid>
			<pubDate>2013-05-11T22:40:14+02:00</pubDate>
			<description><![CDATA[id:	10859032<br />first:	1368304814<br />last:	0<br />md5:	79d855d0874500cb33bfb3a2e67b2aa3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=79d855d0874500cb33bfb3a2e67b2aa3<br />vt_score:	26/46 (56.5%)<br />scanner:	avira<br />virusname:	TR/Agent.zgt<br />url:	http://24.duote.com.cn/yxftv.zip<br />recent:	up<br />response:	alive<br />ip:	61.164.44.6<br />as:	AS4134<br />review:	61.164.44.6<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	antispam@dcb.hz.zj.cn<br />inetnum:	61.164.32.0 - 61.164.63.255<br />netname:	CHINANET-ZJ-HZ<br />descr:	CHINANET-ZJ Hangzhou node networkZhejiang Telecom<br />ns1:	dns2.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://202.117.156.4/ftps/docs/WinRAR-GUI3.42.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10858942</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Chifrax.A.351]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10858942</guid>
			<pubDate>2013-05-11T22:00:08+02:00</pubDate>
			<description><![CDATA[id:	10858942<br />first:	1368302408<br />last:	0<br />md5:	efca9d7c42e9ff5e85e0711731cb3b1d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=efca9d7c42e9ff5e85e0711731cb3b1d<br />vt_score:	18/46 (39.1%)<br />scanner:	avira<br />virusname:	TR/Chifrax.A.351<br />url:	http://202.117.156.4/ftps/docs/WinRAR-GUI3.42.exe<br />recent:	up<br />response:	alive<br />ip:	202.117.156.4<br />as:	AS4538<br />review:	202.117.156.4<br />domain:	202.117.156.4<br />country:	CN<br />source:	APNIC<br />email:	cernet-helpdesk-ip@net.edu.cn<br />inetnum:	202.117.144.0 - 202.117.159.255<br />netname:	SSTU-CN<br />descr:	~{IBNwJ&764sQ'~}Shaanxi Teachers UniversityChang An Nan Lu Shi Da Lu 1#Xi'an, Shaan Xi<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://1973.co.kr/bbs/images/index_04.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10858449</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:RedirME-inf Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10858449</guid>
			<pubDate>2013-05-11T21:40:03+02:00</pubDate>
			<description><![CDATA[id:	10858449<br />first:	1368301203<br />last:	0<br />md5:	b1396d70ef3d523de20ba44401a69583<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=49ab4bf3c0595c030c00ec40ad1c7f49<br />vt_score:	4/42 (9.5%)<br />scanner:	Avast<br />virusname:	HTML:RedirME-inf Trj<br />url:	http://1973.co.kr/bbs/images/index_04.gif<br />recent:	up<br />response:	alive<br />ip:	211.49.162.63<br />as:	AS9318<br />review:	211.49.162.63<br />domain:	1973.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@hanaro.com<br />inetnum:	211.49.162.0 - 211.49.162.255<br />netname:	HANANET-INFRA<br />descr:	KRNICKorea Network Information CenterHanaro Telecom Inc.<br />ns1:	ns2.ivyro.net<br />ns2:	ns1.ivyro.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://119.147.137.50:82/code/201003/gamebook.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10857650</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/ASP.Ace.AS.8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10857650</guid>
			<pubDate>2013-05-11T21:00:19+02:00</pubDate>
			<description><![CDATA[id:	10857650<br />first:	1368298819<br />last:	0<br />md5:	53073d9a37231ec7814727029ce9d0cc<br />virustotal:	<br />vt_score:	14/46 (30.4%)<br />scanner:	avira<br />virusname:	BDS/ASP.Ace.AS.8<br />url:	http://119.147.137.50:82/code/201003/gamebook.zip<br />recent:	up<br />response:	alive<br />ip:	119.147.137.50<br />as:	AS4134<br />review:	119.147.137.50<br />domain:	119.147.137.50<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	119.144.0.0 - 119.147.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wybrzezegdansk.pl/bonguosto]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10849788</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10849788</guid>
			<pubDate>2013-05-11T17:30:15+02:00</pubDate>
			<description><![CDATA[id:	10849788<br />first:	1368286215<br />last:	0<br />md5:	657f8ab2308fc151d53e9ebf6fb42d49<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=657f8ab2308fc151d53e9ebf6fb42d49<br />vt_score:	23/44 (52.3%)<br />scanner:	avira<br />virusname:	JS/Redirect.AC<br />url:	http://wybrzezegdansk.pl/bonguosto<br />recent:	up<br />response:	alive<br />ip:	77.55.63.210<br />as:	AS15967<br />review:	77.55.63.210<br />domain:	wybrzezegdansk.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@netart.pl<br />inetnum:	77.55.0.0 - 77.55.127.255<br />netname:	NETART<br />descr:	NetArt webhosting servers<br />ns1:	ns2.netart.pl<br />ns2:	ns1.netart.pl<br />ns3:	ns3.netart.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://triaxiontms.com.au/triaxion.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10843357</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Crypt.GG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10843357</guid>
			<pubDate>2013-05-11T12:10:04+02:00</pubDate>
			<description><![CDATA[id:	10843357<br />first:	1368267004<br />last:	0<br />md5:	69c048a03e3a0f9dee602e280f146d99<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=69c048a03e3a0f9dee602e280f146d99<br />vt_score:	13/35 (37.1%)<br />scanner:	AntiVir<br />virusname:	JS/Crypt.GG<br />url:	http://triaxiontms.com.au/triaxion.html<br />recent:	up<br />response:	alive<br />ip:	182.50.130.158<br />as:	AS26496<br />review:	182.50.130.158<br />domain:	triaxiontms.com.au<br />country:	SG<br />source:	APNIC<br />email:	gschwimer@godaddy.com<br />inetnum:	182.50.128.0 - 182.50.159.255<br />netname:	GODADDY-NET-SG<br />descr:	8 Cross Street#11-00 PWC Building<br />ns1:	ns02.domaincontrol.com<br />ns2:	ns01.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://trachtenverein-thaur.at/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10842381</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10842381</guid>
			<pubDate>2013-05-11T11:20:57+02:00</pubDate>
			<description><![CDATA[id:	10842381<br />first:	1368264057<br />last:	0<br />md5:	031416fd2123cc114170494fdfc1a8a0<br />virustotal:	<br />vt_score:	4/45 (8.9%)<br />scanner:	AVG<br />virusname:	HTML/Framer<br />url:	http://trachtenverein-thaur.at/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	85.13.133.76<br />as:	AS34788<br />review:	85.13.133.76<br />domain:	trachtenverein-thaur.at<br />country:	DE<br />source:	RIPE<br />email:	ip@all-inkl.com<br />inetnum:	85.13.128.0 - 85.13.191.255<br />netname:	DE-ALL-INKL-20050405<br />descr:	Neue Medien Muennich<br />ns1:	ns5.kasserver.com<br />ns2:	ns6.kasserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://t5rbm.ac.th/media/system/js/mootools.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10840264</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10840264</guid>
			<pubDate>2013-05-11T09:20:17+02:00</pubDate>
			<description><![CDATA[id:	10840264<br />first:	1368256817<br />last:	0<br />md5:	c2466c082e03257d158189d208c5433b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c2466c082e03257d158189d208c5433b<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://t5rbm.ac.th/media/system/js/mootools.js<br />recent:	up<br />response:	alive<br />ip:	61.19.245.20<br />as:	AS9931<br />review:	61.19.245.20<br />domain:	t5rbm.ac.th<br />country:	TH<br />source:	APNIC<br />email:	abuse@idc.cattelecom.com<br />inetnum:	61.19.240.0 - 61.19.255.255<br />netname:	CAT-IDC-Service<br />descr:	CAT TELECOM Data Comm. Dept, IDC Office***send spam abuse to support@idc.cattelecom.com and  abuse@idc.cattelecom.com***<br />ns1:	teal.cat.net.th<br />ns2:	ns2.idc.cattelecom.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sollicitatiebrief.eu/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10838514</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10838514</guid>
			<pubDate>2013-05-11T07:10:20+02:00</pubDate>
			<description><![CDATA[id:	10838514<br />first:	1368249020<br />last:	0<br />md5:	031416fd2123cc114170494fdfc1a8a0<br />virustotal:	<br />vt_score:	4/45 (8.9%)<br />scanner:	AVG<br />virusname:	HTML/Framer<br />url:	http://sollicitatiebrief.eu/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	188.93.150.34<br />as:	AS21155<br />review:	188.93.150.34<br />domain:	sollicitatiebrief.eu<br />country:	NL<br />source:	RIPE<br />email:	noc@mijndomein.nl<br />inetnum:	188.93.144.0 - 188.93.151.255<br />netname:	NL-MIJNDOMEIN-20090514<br />descr:	mijndomein.nl BVmijndomein.nl BV<br />ns1:	ns2.metaregistrar.nl<br />ns2:	ns1.metaregistrar.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soft-lab.de/joko/xcomp097.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10838513</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Offend.56.7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10838513</guid>
			<pubDate>2013-05-11T07:10:20+02:00</pubDate>
			<description><![CDATA[id:	10838513<br />first:	1368249020<br />last:	0<br />md5:	a438733314eb3ebf923aa486e7e50850<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a438733314eb3ebf923aa486e7e50850<br />vt_score:	34/46 (73.9%)<br />scanner:	avira<br />virusname:	TR/Offend.56.7<br />url:	http://soft-lab.de/joko/xcomp097.zip<br />recent:	up<br />response:	alive<br />ip:	87.106.171.238<br />as:	AS8560<br />review:	87.106.171.238<br />domain:	soft-lab.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	87.106.160.0 - 87.106.175.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGSCHLUND-PA-5<br />ns1:	ns65.1und1.de<br />ns2:	ns66.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://phi-long.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10825145</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10825145</guid>
			<pubDate>2013-05-10T21:20:14+02:00</pubDate>
			<description><![CDATA[id:	10825145<br />first:	1368213614<br />last:	0<br />md5:	e0a2327ffb1b40f1943d9c6432e9461a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e0a2327ffb1b40f1943d9c6432e9461a<br />vt_score:	31/45 (68.9%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://phi-long.de/<br />recent:	up<br />response:	alive<br />ip:	91.223.141.107<br />as:	AS25504<br />review:	91.223.141.107<br />domain:	phi-long.de<br />country:	DE<br />source:	RIPE<br />email:	patrick@argonius.de<br />inetnum:	91.223.141.0 - 91.223.141.255<br />netname:	FLUSHMEDIA-NET<br />descr:	Patrick Kaiser--------------------------------------------------Flush Media--------------------------------------------------FLUSHMEDIA-NET<br />ns1:	srvdns01.yopeho-server.de<br />ns2:	srvdns02.yopeho-server.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://perday.org/uploadfile/2008-12/2008121153619643.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10818603</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Gendal.22016.HL]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10818603</guid>
			<pubDate>2013-05-10T18:30:07+02:00</pubDate>
			<description><![CDATA[id:	10818603<br />first:	1368203407<br />last:	0<br />md5:	c4d272fb4b9833b65cc8df0490a3e35a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c4d272fb4b9833b65cc8df0490a3e35a<br />vt_score:	27/45 (60%)<br />scanner:	avira<br />virusname:	TR/Gendal.22016.HL<br />url:	http://perday.org/uploadfile/2008-12/2008121153619643.rar<br />recent:	up<br />response:	alive<br />ip:	218.93.127.153<br />as:	AS23650<br />review:	218.93.127.153<br />domain:	perday.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	218.90.0.0 - 218.94.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://osteopatija.zdravi.me/wp-includes/js/comment-reply.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10816332</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PH.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10816332</guid>
			<pubDate>2013-05-10T17:00:54+02:00</pubDate>
			<description><![CDATA[id:	10816332<br />first:	1368198054<br />last:	0<br />md5:	20ef5771571f1be483869066b2830c2f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a1f3d43851f20e26c4d76c4e725814b7<br />vt_score:	13/35 (37.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.PH.3<br />url:	http://osteopatija.zdravi.me/wp-includes/js/comment-reply.js<br />recent:	up<br />response:	alive<br />ip:	91.185.222.37<br />as:	AS41828<br />review:	91.185.222.37<br />domain:	zdravi.me<br />country:	SI<br />source:	RIPE<br />email:	abuse@tusmobil.si<br />inetnum:	91.185.222.0 - 91.185.222.127<br />netname:	SI-TUSMOBIL-SIEL-1<br />descr:	SIEL, d.o.o.Mariborska cesta 763000 Celje<br />ns1:	dns2.siel.si<br />ns2:	dns3.siel.si<br />ns3:	dns1.siel.si<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://modsys.co.kr/board/js/wrest.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10806645</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Gamburl.U]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10806645</guid>
			<pubDate>2013-05-10T11:50:08+02:00</pubDate>
			<description><![CDATA[id:	10806645<br />first:	1368179408<br />last:	0<br />md5:	afa9c79dfe75a5429d78abd1a9174c0a<br />virustotal:	<br />vt_score:	16/46 (34.8%)<br />scanner:	avira<br />virusname:	JS/Gamburl.U<br />url:	http://modsys.co.kr/board/js/wrest.js<br />recent:	up<br />response:	alive<br />ip:	211.115.206.108<br />as:	AS9848<br />review:	211.115.206.108<br />domain:	modsys.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@sejongtelecom.net<br />inetnum:	211.115.192.0 - 211.115.207.255<br />netname:	SEJONGNET-KR<br />descr:	SEJONG TELECOM<br />ns1:	ns2.sdsns.com<br />ns2:	ns1.sdsns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mail.samowar-ps.de/trap/offending.202.126.91.84.txt]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10804318</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacode.AL]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10804318</guid>
			<pubDate>2013-05-10T09:21:01+02:00</pubDate>
			<description><![CDATA[id:	10804318<br />first:	1368170461<br />last:	0<br />md5:	d56b7c4b0712693b07263ca79aff9987<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d56b7c4b0712693b07263ca79aff9987<br />vt_score:	28/46 (60.9%)<br />scanner:	avira<br />virusname:	JS/Blacode.AL<br />url:	http://mail.samowar-ps.de/trap/offending.202.126.91.84.txt<br />recent:	up<br />response:	alive<br />ip:	83.220.144.209<br />as:	AS25074<br />review:	83.220.144.209<br />domain:	samowar-ps.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@inetbone.net<br />inetnum:	83.220.144.0 - 83.220.144.255<br />netname:	DE-SPEICHERHOSTING<br />descr:	SpeicherhostingCustomer PA Space<br />ns1:	ns29.ns1-tech.de<br />ns2:	ns3.ns1-tech.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://leyfieldsfarm.co.uk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10802295</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Iframeinf.A.259]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10802295</guid>
			<pubDate>2013-05-10T08:00:44+02:00</pubDate>
			<description><![CDATA[id:	10802295<br />first:	1368165644<br />last:	0<br />md5:	afeb941e52f562ab98eb468993e048ca<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=afeb941e52f562ab98eb468993e048ca<br />vt_score:	12/42 (28.6%)<br />scanner:	avira<br />virusname:	HTML/Iframeinf.A.259<br />url:	http://leyfieldsfarm.co.uk/<br />recent:	up<br />response:	alive<br />ip:	79.170.40.231<br />as:	AS31727<br />review:	79.170.40.231<br />domain:	leyfieldsfarm.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@heartinternet.co.uk<br />inetnum:	79.170.40.0 - 79.170.42.255<br />netname:	HEART-INTERNET<br />descr:	Heart Internet Network<br />ns1:	ns2.heartinternet.co.uk<br />ns2:	ns.heartinternet.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lenhart.i-networx.de/sets/rezeptekopf.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10802294</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Feebs.gen@MM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10802294</guid>
			<pubDate>2013-05-10T08:00:31+02:00</pubDate>
			<description><![CDATA[id:	10802294<br />first:	1368165631<br />last:	0<br />md5:	95b7403d0b8eae99d14b6fc375705ac7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=95b7403d0b8eae99d14b6fc375705ac7<br />vt_score:	1/46 (2.2%)<br />scanner:	undef<br />virusname:	JS/Feebs.gen@MM<br />url:	http://lenhart.i-networx.de/sets/rezeptekopf.htm<br />recent:	up<br />response:	alive<br />ip:	217.70.142.36<br />as:	AS15366<br />review:	217.70.142.36<br />domain:	i-networx.de<br />country:	DE<br />source:	RIPE<br />email:	noc@dns-net.de<br />inetnum:	217.70.142.0 -  217.70.142.255<br />netname:	DE-INTERNETWORX-NET-1<br />descr:	InterNetworX Ltd. & Co. KGUffizio Internet Services RIPE block<br />ns1:	ns3.inwx.de<br />ns2:	ns.inwx.de<br />ns3:	ns2.inwx.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lenhart.i-networx.de/sets/impressumkopf.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10802293</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Feebs.gen@MM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10802293</guid>
			<pubDate>2013-05-10T08:00:31+02:00</pubDate>
			<description><![CDATA[id:	10802293<br />first:	1368165631<br />last:	0<br />md5:	568eb875fd493ffd0852119b52613fa5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=568eb875fd493ffd0852119b52613fa5<br />vt_score:	1/46 (2.2%)<br />scanner:	undef<br />virusname:	JS/Feebs.gen@MM<br />url:	http://lenhart.i-networx.de/sets/impressumkopf.htm<br />recent:	up<br />response:	alive<br />ip:	217.70.142.36<br />as:	AS15366<br />review:	217.70.142.36<br />domain:	i-networx.de<br />country:	DE<br />source:	RIPE<br />email:	noc@dns-net.de<br />inetnum:	217.70.142.0 -  217.70.142.255<br />netname:	DE-INTERNETWORX-NET-1<br />descr:	InterNetworX Ltd. & Co. KGUffizio Internet Services RIPE block<br />ns1:	ns3.inwx.de<br />ns2:	ns.inwx.de<br />ns3:	ns2.inwx.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kontramet.pl/oferta.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10801505</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Script-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10801505</guid>
			<pubDate>2013-05-10T06:30:33+02:00</pubDate>
			<description><![CDATA[id:	10801505<br />first:	1368160233<br />last:	0<br />md5:	92b9368dd37e05f24919d2646c6c1043<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=92b9368dd37e05f24919d2646c6c1043<br />vt_score:	12/46 (26.1%)<br />scanner:	Avast<br />virusname:	HTML:Script-inf<br />url:	http://kontramet.pl/oferta.html<br />recent:	up<br />response:	alive<br />ip:	176.119.35.232<br />as:	AS42503<br />review:	176.119.35.232<br />domain:	kontramet.pl<br />country:	PL<br />source:	ARIN<br />email:	<br />inetnum:	176.119.32.0 - 176.119.63.255<br />netname:	K2-net<br />descr:	K2 Internet S.A.K2 Internet S.A.K2<br />ns1:	nms3.projekty.pl<br />ns2:	nms1.projekty.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p554p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10798900</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10798900</guid>
			<pubDate>2013-05-10T04:30:07+02:00</pubDate>
			<description><![CDATA[id:	10798900<br />first:	1368153007<br />last:	0<br />md5:	b65be68ed81786c9bd8428ec72a0301a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b65be68ed81786c9bd8428ec72a0301a<br />vt_score:	27/42 (64.3%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p554p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://isensei.org/content/2]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10795275</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.GT.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10795275</guid>
			<pubDate>2013-05-10T03:00:26+02:00</pubDate>
			<description><![CDATA[id:	10795275<br />first:	1368147626<br />last:	0<br />md5:	efba3ff060aedd3398f33f61c5183282<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=efba3ff060aedd3398f33f61c5183282<br />vt_score:	28/46 (60.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.GT.5<br />url:	http://isensei.org/content/2<br />recent:	up<br />response:	alive<br />ip:	173.201.97.128<br />as:	AS26496<br />review:	173.201.97.128<br />domain:	isensei.org<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	173.201.0.0 - 173.201.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns44.domaincontrol.com<br />ns2:	ns43.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://healingteddies.org.il/hemlah/j_nya2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10790121</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10790121</guid>
			<pubDate>2013-05-09T23:40:22+02:00</pubDate>
			<description><![CDATA[id:	10790121<br />first:	1368135622<br />last:	0<br />md5:	0b8282457eb963f4611941093f66802d<br />virustotal:	<br />vt_score:	24/44 (54.5%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://healingteddies.org.il/hemlah/j_nya2.html<br />recent:	up<br />response:	alive<br />ip:	208.109.14.20<br />as:	AS26496<br />review:	208.109.14.20<br />domain:	healingteddies.org.il<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns4.secureserver.net<br />ns2:	ns3.secureserver.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dsims.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10771978</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10771978</guid>
			<pubDate>2013-05-09T13:40:16+02:00</pubDate>
			<description><![CDATA[id:	10771978<br />first:	1368099616<br />last:	0<br />md5:	090cfcd2e349d2004f0788618670e2da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=090cfcd2e349d2004f0788618670e2da<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Expack.VU.1<br />url:	http://dsims.org/<br />recent:	up<br />response:	alive<br />ip:	77.235.35.94<br />as:	AS16265<br />review:	77.235.35.94<br />domain:	dsims.org<br />country:	NL<br />source:	RIPE<br />email:	security@eurovps.com<br />inetnum:	77.235.32.0 - 77.235.63.255<br />netname:	GR-EUROVPS-20070116<br />descr:	EuroVPSEuroVPS<br />ns1:	ns2.thecityofswindon.co.uk<br />ns2:	ns1.thecityofswindon.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/video-games/vintage-games.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10771465</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10771465</guid>
			<pubDate>2013-05-09T12:50:16+02:00</pubDate>
			<description><![CDATA[id:	10771465<br />first:	1368096616<br />last:	0<br />md5:	9c9fd22507131ed9cd465e8a2f3a1765<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9c9fd22507131ed9cd465e8a2f3a1765<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/video-games/vintage-games.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/sports-cards-fan-shop/cards.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10771464</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10771464</guid>
			<pubDate>2013-05-09T12:50:15+02:00</pubDate>
			<description><![CDATA[id:	10771464<br />first:	1368096615<br />last:	0<br />md5:	1354a70fadb468e5885e2758900aff53<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1354a70fadb468e5885e2758900aff53<br />vt_score:	12/46 (26.1%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/sports-cards-fan-shop/cards.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://caroleholding.bm/pages/checkout/checkout1.asp?id=23]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10763192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.hhd]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10763192</guid>
			<pubDate>2013-05-09T05:30:10+02:00</pubDate>
			<description><![CDATA[id:	10763192<br />first:	1368070210<br />last:	0<br />md5:	88b9b7f2e885310f6049bd3fb88883e3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=88b9b7f2e885310f6049bd3fb88883e3<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	JS/Agent.hhd<br />url:	http://caroleholding.bm/pages/checkout/checkout1.asp?id=23<br />recent:	up<br />response:	alive<br />ip:	216.119.75.250<br />as:	AS14992<br />review:	216.119.75.250<br />domain:	caroleholding.bm<br />country:	US<br />source:	ARIN<br />email:	abuse@crystaltech.com<br />inetnum:	216.119.64.0 - 216.119.127.255<br />netname:	CRYSTALTECH-BLK-1<br />descr:	CrystalTech Web Hosting Inc. CRTW 1125 W. Pinnacle Peak Road, Suite 103 Phoenix AZ 85027<br />ns1:	ns2.webcontrolcenter.com<br />ns2:	ns1.webcontrolcenter.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aysuelektrik.com.tr/scripts/mootools-1.2.1-core-yc.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10758728</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10758728</guid>
			<pubDate>2013-05-09T00:30:10+02:00</pubDate>
			<description><![CDATA[id:	10758728<br />first:	1368052210<br />last:	0<br />md5:	1f0695c95863a213d1d08aec3f7f1638<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f0695c95863a213d1d08aec3f7f1638<br />vt_score:	32/46 (69.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://aysuelektrik.com.tr/scripts/mootools-1.2.1-core-yc.js<br />recent:	up<br />response:	alive<br />ip:	46.28.239.152<br />as:	AS9121<br />review:	46.28.239.152<br />domain:	aysuelektrik.com.tr<br />country:	TR<br />source:	RIPE<br />email:	abuse@ttnet.net.tr<br />inetnum:	46.28.239.0 - 46.28.239.255<br />netname:	DATAXI<br />descr:	Dataxi TRTR-SOFTCOM<br />ns1:	ns.aysuelektrik.com.tr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aprendejugando.cl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10753218</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10753218</guid>
			<pubDate>2013-05-08T20:20:14+02:00</pubDate>
			<description><![CDATA[id:	10753218<br />first:	1368037214<br />last:	0<br />md5:	c593200fd53f784839db2f7de4e96d69<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c593200fd53f784839db2f7de4e96d69<br />vt_score:	29/45 (64.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.TF<br />url:	http://aprendejugando.cl/<br />recent:	up<br />response:	alive<br />ip:	50.87.15.136<br />as:	AS11798<br />review:	50.87.15.136<br />domain:	aprendejugando.cl<br />country:	US<br />source:	ARIN<br />email:	netops@bluehost.com<br />inetnum:	50.87.0.0 - 50.87.255.255<br />netname:	BLUEHOST-NETWORK-9<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns2.rhostjh.com<br />ns2:	ns1.rhostjh.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aplab.com.my/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10753217</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10753217</guid>
			<pubDate>2013-05-08T20:20:13+02:00</pubDate>
			<description><![CDATA[id:	10753217<br />first:	1368037213<br />last:	0<br />md5:	cf990ab92dd3d3e85cff9af947705ef3<br />virustotal:	<br />vt_score:	31/45 (68.9%)<br />scanner:	avira<br />virusname:	JS/Expack.VU.1<br />url:	http://aplab.com.my/<br />recent:	up<br />response:	alive<br />ip:	119.110.108.42<br />as:	AS17971<br />review:	119.110.108.42<br />domain:	aplab.com.my<br />country:	MY<br />source:	APNIC<br />email:	gatekeeper@eastgate.net.my<br />inetnum:	119.110.96.0 - 119.110.111.255<br />netname:	TM-IDC<br />descr:	TM NET SDN BHDEASTGATE<br />ns1:	ns11.localdns.com<br />ns2:	ns10.localdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://agenda.universia.com.pa/templates/default/js/common.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10736669</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Script.51950]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10736669</guid>
			<pubDate>2013-05-08T13:50:02+02:00</pubDate>
			<description><![CDATA[id:	10736669<br />first:	1368013802<br />last:	0<br />md5:	1660d6257a0dfef2303a983077e8bde8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d59a6dd5a588f36be3ee6c40a05a8871<br />vt_score:	10/32 (31.3%)<br />scanner:	avira<br />virusname:	TR/Script.51950<br />url:	http://agenda.universia.com.pa/templates/default/js/common.js<br />recent:	up<br />response:	alive<br />ip:	195.149.210.100<br />as:	AS2134<br />review:	195.149.210.100<br />domain:	universia.com.pa<br />country:	ES<br />source:	RIPE<br />email:	admin@gsvnet.net<br />inetnum:	195.149.208.0 - 195.149.215.255<br />netname:	SCH<br />descr:	Grupo SantanderCiudad FinancieraBoadilla del Monte. Madrid<br />ns1:	dns02.santandergroup.net<br />ns2:	dns01.santandergroup.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://adsantarem.org/edom/page0001.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10735096</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.apo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10735096</guid>
			<pubDate>2013-05-08T13:20:03+02:00</pubDate>
			<description><![CDATA[id:	10735096<br />first:	1368012003<br />last:	0<br />md5:	7de4cfda3c1b9124cd0b2d959349eec0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7de4cfda3c1b9124cd0b2d959349eec0<br />vt_score:	25/42 (59.5%)<br />scanner:	avira<br />virusname:	JS/Agent.apo<br />url:	http://adsantarem.org/edom/page0001.htm<br />recent:	up<br />response:	alive<br />ip:	213.171.218.43<br />as:	AS2856<br />review:	213.171.218.43<br />domain:	adsantarem.org<br />country:	GB<br />source:	RIPE<br />email:	abuse@fasthosts.co.uk<br />inetnum:	213.171.218.0 - 213.171.219.255<br />netname:	FASTHOSTS-UK-NETWORK<br />descr:	UK's largest web hosting companybased in Gloucester, England<br />ns1:	ns1.livedns.co.uk<br />ns2:	ns3.livedns.co.uk<br />ns3:	ns2.livedns.co.uk<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://adi-max.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10735095</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.NI.23]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10735095</guid>
			<pubDate>2013-05-08T13:20:03+02:00</pubDate>
			<description><![CDATA[id:	10735095<br />first:	1368012003<br />last:	0<br />md5:	f75b557e5da973edca490955b6cc6242<br />virustotal:	<br />vt_score:	25/43 (58.1%)<br />scanner:	avira<br />virusname:	HTML/IFrame.NI.23<br />url:	http://adi-max.de/<br />recent:	up<br />response:	alive<br />ip:	85.183.254.23<br />as:	AS13184<br />review:	85.183.254.23<br />domain:	adi-max.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@hansenet.com<br />inetnum:	85.176.0.0 - 85.183.255.255<br />netname:	DE-HANSENET-20041029<br />descr:	PROVIDER Local RegistryHanseNet Telekommunikation GmbH<br />ns1:	ns1.hansenet.de<br />ns2:	ns2.hansenet.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://25.duote.com.cn/wzsllgj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734576</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734576</guid>
			<pubDate>2013-05-08T11:34:07+02:00</pubDate>
			<description><![CDATA[id:	10734576<br />first:	1368005647<br />last:	0<br />md5:	62fc1b3b302dc7eabcbee372c5568822<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=62fc1b3b302dc7eabcbee372c5568822<br />vt_score:	16/35 (45.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://25.duote.com.cn/wzsllgj.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.195<br />as:	AS132524<br />review:	60.209.5.195<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	<br />inetnum:	60.208.0.0 - 60.215.255.255<br />netname:	<br />descr:	<br />ns1:	dns4.50bang.org<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zhenfei.com.cn/zysb_cn.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10732840</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.AN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10732840</guid>
			<pubDate>2013-05-08T08:30:28+02:00</pubDate>
			<description><![CDATA[id:	10732840<br />first:	1367994628<br />last:	0<br />md5:	256b067847bab55b0111c1aba84c9fa2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=256b067847bab55b0111c1aba84c9fa2<br />vt_score:	26/42 (61.9%)<br />scanner:	avira<br />virusname:	HTML/IFrame.AN<br />url:	http://zhenfei.com.cn/zysb_cn.asp<br />recent:	up<br />response:	alive<br />ip:	61.139.126.8<br />as:	AS4134<br />review:	61.139.126.8<br />domain:	zhenfei.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	61.139.0.0 - 61.139.127.255<br />netname:	CHINANET-SC<br />descr:	CHINANET Sichuan province networkData Communication DivisionChina Telecom<br />ns1:	dns2.hichina.com<br />ns2:	dns1.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://shixue.org/shiku/gs/xz/jianan7.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10725566</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.403071]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10725566</guid>
			<pubDate>2013-05-08T01:30:23+02:00</pubDate>
			<description><![CDATA[id:	10725566<br />first:	1367969423<br />last:	0<br />md5:	c04495764a9ff6f071d13be2f9d3eaed<br />virustotal:	<br />vt_score:	23/46 (50%)<br />scanner:	avira<br />virusname:	TR/Spy.403071<br />url:	http://shixue.org/shiku/gs/xz/jianan7.zip<br />recent:	up<br />response:	alive<br />ip:	66.147.240.188<br />as:	AS11798<br />review:	66.147.240.188<br />domain:	shixue.org<br />country:	US<br />source:	ARIN<br />email:	abuse@bluehost.com<br />inetnum:	66.147.240.0 - 66.147.255.255<br />netname:	BLUEHOST-NETWORK-4<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns2.hostmonster.com<br />ns2:	ns1.hostmonster.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://romaahousing.in/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10722731</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/IFrame]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10722731</guid>
			<pubDate>2013-05-07T22:00:18+02:00</pubDate>
			<description><![CDATA[id:	10722731<br />first:	1367956818<br />last:	0<br />md5:	ddf5652c4035c4dfafe5f329221e6297<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ddf5652c4035c4dfafe5f329221e6297<br />vt_score:	0/35 (0.0%)<br />scanner:	AhnLab_V3<br />virusname:	JS/IFrame<br />url:	http://romaahousing.in/<br />recent:	up<br />response:	alive<br />ip:	173.254.28.100<br />as:	AS11798<br />review:	173.254.28.100<br />domain:	romaahousing.in<br />country:	US<br />source:	ARIN<br />email:	support@bluehost.com<br />inetnum:	173.254.0.0 - 173.254.127.255<br />netname:	BLUEHOST-NETWORK-8<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns4.acquainttech.net<br />ns2:	ns3.acquainttech.net<br />ns3:	ns1.acquainttech.net<br />ns4:	ns2.acquainttech.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://por.tw/Downloads/SpecialFoldersView-1.05.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10722730</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32/PolyCrypt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10722730</guid>
			<pubDate>2013-05-07T22:00:18+02:00</pubDate>
			<description><![CDATA[id:	10722730<br />first:	1367956818<br />last:	0<br />md5:	f39546dd0defbe7843ad6bac01620154<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f39546dd0defbe7843ad6bac01620154<br />vt_score:	16/46 (34.8%)<br />scanner:	AVG<br />virusname:	Win32/PolyCrypt<br />url:	http://por.tw/Downloads/SpecialFoldersView-1.05.rar<br />recent:	up<br />response:	alive<br />ip:	121.254.73.32<br />as:	AS17809<br />review:	121.254.73.32<br />domain:	por.tw<br />country:	TW<br />source:	APNIC<br />email:	frank@emax.net.tw<br />inetnum:	121.254.64.0 - 121.254.95.255<br />netname:	MONAD-TW<br />descr:	Monad Digitnamic CorpMAN providerTaichung Taiwan R.O.C<br />ns1:	pdns2.pchome.com.tw<br />ns2:	pdns1.pchome.com.tw<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://loughorlifeboat.org.uk/tenby/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10714391</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.cse]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10714391</guid>
			<pubDate>2013-05-07T11:10:08+02:00</pubDate>
			<description><![CDATA[id:	10714391<br />first:	1367917808<br />last:	0<br />md5:	d2fb99a54a47a9d1fac1b7b7ab92066e<br />virustotal:	<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.cse<br />url:	http://loughorlifeboat.org.uk/tenby/index.html<br />recent:	up<br />response:	alive<br />ip:	62.128.152.236<br />as:	AS8912<br />review:	62.128.152.236<br />domain:	loughorlifeboat.org.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@netbenefit.co.uk<br />inetnum:	62.128.152.0 - 62.128.152.255<br />netname:	NETBENEFIT-DEDICATED-10<br />descr:	[ Netbenefit Dedicated Servers Sovereign House]NetBenefit, Commercial Internet Services ProviderLondon, UKGroup NBT plcGroupNBT-Agg-62-128-128<br />ns1:	ns.hosteurope.com<br />ns2:	ns2.hosteurope.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=revistapcactualespa?ano.250]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10714074</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10714074</guid>
			<pubDate>2013-05-07T10:30:19+02:00</pubDate>
			<description><![CDATA[id:	10714074<br />first:	1367915419<br />last:	0<br />md5:	faeea0ee52133caca77464948949c30f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=faeea0ee52133caca77464948949c30f<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=revistapcactualespa?ano.250<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://korneliuszmatauszek.pl/kazania/trid/wcz08.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10713907</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10713907</guid>
			<pubDate>2013-05-07T10:10:10+02:00</pubDate>
			<description><![CDATA[id:	10713907<br />first:	1367914210<br />last:	0<br />md5:	a13541918d0d4be4f2d91b7dfeae5cba<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a13541918d0d4be4f2d91b7dfeae5cba<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://korneliuszmatauszek.pl/kazania/trid/wcz08.html<br />recent:	up<br />response:	alive<br />ip:	89.161.179.213<br />as:	AS12824<br />review:	89.161.179.213<br />domain:	korneliuszmatauszek.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p842p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10713432</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10713432</guid>
			<pubDate>2013-05-07T09:10:07+02:00</pubDate>
			<description><![CDATA[id:	10713432<br />first:	1367910607<br />last:	0<br />md5:	30cff2694548c40382c54fe9d9ef9504<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30cff2694548c40382c54fe9d9ef9504<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p842p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p36p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10713431</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10713431</guid>
			<pubDate>2013-05-07T09:10:07+02:00</pubDate>
			<description><![CDATA[id:	10713431<br />first:	1367910607<br />last:	0<br />md5:	d42f1074ec971dfec5c1ac49c46b7ce7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d42f1074ec971dfec5c1ac49c46b7ce7<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p36p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hideway.com.br/css/_notes/erro/bvs-recebimento.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10711921</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Banload.AQU]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10711921</guid>
			<pubDate>2013-05-07T06:20:09+02:00</pubDate>
			<description><![CDATA[id:	10711921<br />first:	1367900409<br />last:	0<br />md5:	a8eec2ecaa8df503698b3c48e282cfe5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a8eec2ecaa8df503698b3c48e282cfe5<br />vt_score:	29/35 (82.9%)<br />scanner:	avira<br />virusname:	TR/Dldr.Banload.AQU<br />url:	http://hideway.com.br/css/_notes/erro/bvs-recebimento.zip<br />recent:	up<br />response:	alive<br />ip:	187.17.96.65<br />as:	AS15201<br />review:	187.17.96.65<br />domain:	hideway.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.17.64.0 - 187.17.127.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns1.dominios.uol.com.br<br />ns2:	ns2.dominios.uol.com.br<br />ns3:	ns3.dominios.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fashion-ol.com.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10709724</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.T]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10709724</guid>
			<pubDate>2013-05-07T02:30:12+02:00</pubDate>
			<description><![CDATA[id:	10709724<br />first:	1367886612<br />last:	0<br />md5:	2339dbb5bd2079c94d99f6780cc7ac9f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2339dbb5bd2079c94d99f6780cc7ac9f<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Twetti.T<br />url:	http://fashion-ol.com.pl/<br />recent:	up<br />response:	alive<br />ip:	212.85.104.237<br />as:	AS12824<br />review:	212.85.104.237<br />domain:	fashion-ol.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.96.0 - 212.85.113.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://csliu.inetfile.org/attach/1/dialupass.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10705813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/NSoft.PassRec.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10705813</guid>
			<pubDate>2013-05-06T21:20:13+02:00</pubDate>
			<description><![CDATA[id:	10705813<br />first:	1367868013<br />last:	0<br />md5:	3de02f431068e2100def79708d7eff66<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3de02f431068e2100def79708d7eff66<br />vt_score:	32/46 (69.6%)<br />scanner:	avira<br />virusname:	SPR/NSoft.PassRec.1<br />url:	http://csliu.inetfile.org/attach/1/dialupass.rar<br />recent:	up<br />response:	alive<br />ip:	205.164.12.12<br />as:	AS18779<br />review:	205.164.12.12<br />domain:	inetfile.org<br />country:	US<br />source:	ARIN<br />email:	abuse@egihosting.com<br />inetnum:	205.164.12.0 - 205.164.12.255<br />netname:	NET-205-164-12-0<br />descr:	Fremont, CA 94538 San Jose CA 95113<br />ns1:	dns1.inetfile.org<br />ns2:	dns2.inetfile.org<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://club.sisat.ac.th/architecture-club]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10704075</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10704075</guid>
			<pubDate>2013-05-06T19:41:57+02:00</pubDate>
			<description><![CDATA[id:	10704075<br />first:	1367862117<br />last:	0<br />md5:	81dcfc5b81e6cf31be58d6dcc88cd2ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=81dcfc5b81e6cf31be58d6dcc88cd2ef<br />vt_score:	28/36 (77.8%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://club.sisat.ac.th/architecture-club<br />recent:	up<br />response:	alive<br />ip:	61.19.124.42<br />as:	AS9931<br />review:	61.19.124.42<br />domain:	sisat.ac.th<br />country:	TH<br />source:	APNIC<br />email:	admin-thix@cat.net.th<br />inetnum:	61.19.64.0 - 61.19.127.255<br />netname:	CAT-ISP-NET<br />descr:	72 Charoenkrung Road Bangrak Bangkok THAILAND 10501<br />ns1:	NS1.sisat.ac.th<br />ns2:	NS2.sisat.ac.th<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://brandweb.cl/clientes/chicureo/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10702823</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10702823</guid>
			<pubDate>2013-05-06T18:00:23+02:00</pubDate>
			<description><![CDATA[id:	10702823<br />first:	1367856023<br />last:	0<br />md5:	dbc1e34c808e84ed753f9784ed7f766a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbc1e34c808e84ed753f9784ed7f766a<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.TF<br />url:	http://brandweb.cl/clientes/chicureo/home.html<br />recent:	up<br />response:	alive<br />ip:	66.33.223.206<br />as:	AS26347<br />review:	66.33.223.206<br />domain:	brandweb.cl<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	66.33.192.0 - 66.33.223.255<br />netname:	DREAMHOST-BLK1<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://arfo.de/seite13.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10699951</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ExpKit.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10699951</guid>
			<pubDate>2013-05-06T13:50:41+02:00</pubDate>
			<description><![CDATA[id:	10699951<br />first:	1367841041<br />last:	0<br />md5:	a518842ea674d525821d33f43e2bd326<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a518842ea674d525821d33f43e2bd326<br />vt_score:	18/35 (51.4%)<br />scanner:	AntiVir<br />virusname:	HTML/ExpKit.Gen3<br />url:	http://arfo.de/seite13.htm<br />recent:	up<br />response:	alive<br />ip:	80.237.133.52<br />as:	AS20773<br />review:	80.237.133.52<br />domain:	arfo.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.133.0 - 80.237.133.255<br />netname:	HE-SH-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.de<br />ns1:	a1.wpns.hosteurope.de<br />ns2:	a1.wsns.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://akkisettycharitabletrust.org/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10696850</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10696850</guid>
			<pubDate>2013-05-06T12:20:14+02:00</pubDate>
			<description><![CDATA[id:	10696850<br />first:	1367835614<br />last:	0<br />md5:	002bf2abaa42d9baa17ccb164aea3039<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=002bf2abaa42d9baa17ccb164aea3039<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/Expack.VU.1<br />url:	http://akkisettycharitabletrust.org/index.html<br />recent:	up<br />response:	alive<br />ip:	174.123.46.194<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.123.46.194<br />domain:	akkisettycharitabletrust.org<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-16<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns54.hostingcare.net<br />ns2:	ns53.hostingcare.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://28.duote.org/xpysj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10691886</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10691886</guid>
			<pubDate>2013-05-06T09:50:05+02:00</pubDate>
			<description><![CDATA[id:	10691886<br />first:	1367826605<br />last:	0<br />md5:	c4414e9eed839cdea9a353034cc921a2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c4414e9eed839cdea9a353034cc921a2<br />vt_score:	15/46 (32.6%)<br />scanner:	undef<br />virusname:	Suspicion: unknown virus<br />url:	http://28.duote.org/xpysj.zip<br />recent:	up<br />response:	alive<br />ip:	221.180.22.214<br />as:	AS56042<br />review:	221.180.22.214<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	hostmaster@chinamobile.com<br />inetnum:	221.176.0.0 - 221.183.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in China<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://24rs.org/forums/clientscript/vbulletin_menu.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10691885</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10691885</guid>
			<pubDate>2013-05-06T09:50:05+02:00</pubDate>
			<description><![CDATA[id:	10691885<br />first:	1367826605<br />last:	0<br />md5:	b04b46f5118cf4812ac1c2c9cab4104d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b04b46f5118cf4812ac1c2c9cab4104d<br />vt_score:	33/46 (71.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://24rs.org/forums/clientscript/vbulletin_menu.js<br />recent:	up<br />response:	alive<br />ip:	24.106.10.35<br />as:	AS11955<br />review:	24.106.10.35<br />domain:	24rs.org<br />country:	US<br />source:	ARIN<br />email:	abuse@rr.com<br />inetnum:	24.106.0.0 - 24.106.63.255<br />netname:	RR-COMMER-CENTRAL-2<br />descr:	Road Runner HoldCo LLC RCWE 13241 Woodland Park Road Herndon VA 20171<br />ns1:	ns.24rs.org<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://archus.is]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10686832</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SR.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10686832</guid>
			<pubDate>2013-05-06T07:40:06+02:00</pubDate>
			<description><![CDATA[id:	10686832<br />first:	1367818806<br />last:	0<br />md5:	c5f4c9b311f94e27fa0889f3faacab1b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c5f4c9b311f94e27fa0889f3faacab1b<br />vt_score:	7/33 (21.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.SR.1<br />url:	http://archus.is<br />recent:	up<br />response:	alive<br />ip:	157.157.130.207<br />as:	AS6677<br />review:	157.157.130.207<br />domain:	archus.is<br />country:	IS<br />source:	RIPE<br />email:	abuse@simnet.is<br />inetnum:	157.157.0.0 - 157.157.255.255<br />netname:	IS-ICENET-20050203<br />descr:	Siminn hf<br />ns1:	ns2.simnet.is<br />ns2:	ns1.simnet.is<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zhenfei.com.cn/zysb_en.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10686757</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.AN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10686757</guid>
			<pubDate>2013-05-06T07:00:29+02:00</pubDate>
			<description><![CDATA[id:	10686757<br />first:	1367816429<br />last:	0<br />md5:	14fcd3b76566cb6bad6a9d6bb13d8f52<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=14fcd3b76566cb6bad6a9d6bb13d8f52<br />vt_score:	28/46 (60.9%)<br />scanner:	avira<br />virusname:	HTML/IFrame.AN<br />url:	http://zhenfei.com.cn/zysb_en.asp<br />recent:	up<br />response:	alive<br />ip:	61.139.126.8<br />as:	AS4134<br />review:	61.139.126.8<br />domain:	zhenfei.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	61.139.0.0 - 61.139.127.255<br />netname:	CHINANET-SC<br />descr:	CHINANET Sichuan province networkData Communication DivisionChina Telecom<br />ns1:	dns1.hichina.com<br />ns2:	dns2.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://womeninanimation.org/guestbook/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10686087</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.GT.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10686087</guid>
			<pubDate>2013-05-06T05:20:18+02:00</pubDate>
			<description><![CDATA[id:	10686087<br />first:	1367810418<br />last:	0<br />md5:	88a4096091945f7e376da4764b9d4e6c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=88a4096091945f7e376da4764b9d4e6c<br />vt_score:	20/43 (46.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.GT.3<br />url:	http://womeninanimation.org/guestbook/index.html<br />recent:	up<br />response:	alive<br />ip:	174.133.125.18<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.133.125.18<br />domain:	womeninanimation.org<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.132.0.0 - 174.133.255.255<br />netname:	NETBLK-THEPLANET-BLK-15<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns38.worldnic.com<br />ns2:	ns37.worldnic.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wohnungsbau-ostalb.de/wohnungsbau-ostalb-kontakt.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10686086</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.alf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10686086</guid>
			<pubDate>2013-05-06T05:20:18+02:00</pubDate>
			<description><![CDATA[id:	10686086<br />first:	1367810418<br />last:	0<br />md5:	a6a0b2c546cfa11cb4f3f45acb66ee9a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a6a0b2c546cfa11cb4f3f45acb66ee9a<br />vt_score:	6/46 (13%)<br />scanner:	AntiVir<br />virusname:	HTML/IFrame.alf<br />url:	http://wohnungsbau-ostalb.de/wohnungsbau-ostalb-kontakt.htm<br />recent:	up<br />response:	alive<br />ip:	195.234.228.80<br />as:	AS25260<br />review:	195.234.228.80<br />domain:	wohnungsbau-ostalb.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@de.colt.net<br />inetnum:	195.234.228.0 - 195.234.231.255<br />netname:	DE-COLT-QUALITYHOSTING<br />descr:	QualityHosting GbRZum Wartturm 163571 GelnhausenGermanyabuse/spam  mail to abuse@qualityhosting.deabuse/spam  please do not contact abuse@de.colt.netQUALITYHOSTING, Gelnhausen<br />ns1:	ns2.domainkunden.de<br />ns2:	ns1.domainkunden.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://weddingproject.co.za/tmp/F49uN_R41N.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10685878</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Script.KD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10685878</guid>
			<pubDate>2013-05-06T04:50:13+02:00</pubDate>
			<description><![CDATA[id:	10685878<br />first:	1367808613<br />last:	0<br />md5:	6788a69c99d4f779d84d8a17f2888b45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6788a69c99d4f779d84d8a17f2888b45<br />vt_score:	7/36 (19.4%)<br />scanner:	BitDefender<br />virusname:	Trojan.Script.KD<br />url:	http://weddingproject.co.za/tmp/F49uN_R41N.html<br />recent:	up<br />response:	alive<br />ip:	50.22.210.116<br />as:	AS36351<br />review:	50.22.210.116<br />domain:	weddingproject.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	50.22.0.0 - 50.23.255.255<br />netname:	SOFTLAYER-4-9<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns1.jcwdns.net<br />ns2:	ns2.jcwdns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://videoprofesional.eu/highslide/highslide-with-gallery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10685452</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.qii]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10685452</guid>
			<pubDate>2013-05-06T04:01:31+02:00</pubDate>
			<description><![CDATA[id:	10685452<br />first:	1367805691<br />last:	0<br />md5:	057320ae7dafc3aeba9460aa8905a55c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=057320ae7dafc3aeba9460aa8905a55c<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	JS/Agent.qii<br />url:	http://videoprofesional.eu/highslide/highslide-with-gallery.js<br />recent:	up<br />response:	alive<br />ip:	74.220.215.204<br />as:	AS11798<br />review:	74.220.215.204<br />domain:	videoprofesional.eu<br />country:	US<br />source:	ARIN<br />email:	support@bluehost.com<br />inetnum:	74.220.192.0 - 74.220.223.255<br />netname:	BLUEHOST-NETWORK-2<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns1.hostmonster.com<br />ns2:	ns2.hostmonster.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vall.jp/fax/common.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10685451</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10685451</guid>
			<pubDate>2013-05-06T04:01:01+02:00</pubDate>
			<description><![CDATA[id:	10685451<br />first:	1367805661<br />last:	0<br />md5:	83605fbd1d0a5a1bfdcbf196c9af34d5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=83605fbd1d0a5a1bfdcbf196c9af34d5<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://vall.jp/fax/common.js<br />recent:	up<br />response:	alive<br />ip:	124.211.27.46<br />as:	AS2516<br />review:	124.211.27.46<br />domain:	vall.jp<br />country:	JP<br />source:	APNIC<br />email:	domain@purenic.jp<br />inetnum:	124.211.27.0 - 124.211.27.255<br />netname:	PURENIC02<br />descr:	PURENIC JAPAN., Inc<br />ns1:	ns.vall.jp<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://usmcwhiskey1-12.org/scrapbk49.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10685428</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.yor]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10685428</guid>
			<pubDate>2013-05-06T03:50:12+02:00</pubDate>
			<description><![CDATA[id:	10685428<br />first:	1367805012<br />last:	0<br />md5:	be9d4a192533e2239082c26b5b112f2b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be9d4a192533e2239082c26b5b112f2b<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.yor<br />url:	http://usmcwhiskey1-12.org/scrapbk49.html<br />recent:	up<br />response:	alive<br />ip:	199.204.248.106<br />as:	AS19730<br />review:	199.204.248.106<br />domain:	usmcwhiskey1-12.org<br />country:	US<br />source:	ARIN<br />email:	netops@hostican.com<br />inetnum:	199.204.248.0 - 199.204.255.255<br />netname:	HOSTICAN-NETWORK<br />descr:	HostICan HOSTI-15 9700 Atlee Commons Drive Ashland VA 23005<br />ns1:	NS1.MYHOSTCENTER.COM<br />ns2:	NS2.MYHOSTCENTER.COM<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ufocui.it/cui/cui/ufotel/ufote224.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10684897</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.5577]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10684897</guid>
			<pubDate>2013-05-06T02:51:57+02:00</pubDate>
			<description><![CDATA[id:	10684897<br />first:	1367801517<br />last:	0<br />md5:	9e0adc40b7736dad53df6b06d80cda01<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9e0adc40b7736dad53df6b06d80cda01<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	JS/Agent.5577<br />url:	http://ufocui.it/cui/cui/ufotel/ufote224.htm<br />recent:	up<br />response:	alive<br />ip:	62.149.128.154<br />as:	AS31034<br />review:	62.149.128.151<br />domain:	ufocui.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tzs.sk/racio2004.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10684896</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/TwitScroll.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10684896</guid>
			<pubDate>2013-05-06T02:51:47+02:00</pubDate>
			<description><![CDATA[id:	10684896<br />first:	1367801507<br />last:	0<br />md5:	c941d9c28894c94fcfc95df7b695da88<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c941d9c28894c94fcfc95df7b695da88<br />vt_score:	23/46 (50%)<br />scanner:	AntiVir<br />virusname:	HTML/TwitScroll.B<br />url:	http://tzs.sk/racio2004.htm<br />recent:	up<br />response:	alive<br />ip:	213.215.124.70<br />as:	AS5578<br />review:	213.215.124.70<br />domain:	tzs.sk<br />country:	SK<br />source:	RIPE<br />email:	abuse@gts.sk<br />inetnum:	213.215.64.0 - 213.215.127.255<br />netname:	SK-GTS-20001222<br />descr:	GTS Slovakia, a.s.<br />ns1:	ns.euronet.biz<br />ns2:	ns.euronet.mobi<br />ns3:	ns.euronet.sk<br />ns4:	ns.euronet.info<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sunshine.com.vn/js/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10683221</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.aql]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10683221</guid>
			<pubDate>2013-05-06T00:40:52+02:00</pubDate>
			<description><![CDATA[id:	10683221<br />first:	1367793652<br />last:	0<br />md5:	e4af2b4805203f1ac490ad67531b848b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36d8b728f376a8026179581270ff3e04<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	JS/Agent.aql<br />url:	http://sunshine.com.vn/js/jquery.js<br />recent:	up<br />response:	alive<br />ip:	74.53.239.51<br />as:	AS21844<br />review:	74.53.239.51<br />domain:	sunshine.com.vn<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	74.52.0.0 - 74.53.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 1333 North Stemmons Freeway Suite 110 Dallas TX 75207<br />ns1:	ns1.sunshinevietnam.com<br />ns2:	ns2.sunshinevietnam.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://spagenie.ae/vs-spagenie-ae/js/jquery-1.2.3.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10682861</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redir.jea]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10682861</guid>
			<pubDate>2013-05-05T23:30:09+02:00</pubDate>
			<description><![CDATA[id:	10682861<br />first:	1367789409<br />last:	0<br />md5:	2850e324387ecbae03ef466df5818bd8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2850e324387ecbae03ef466df5818bd8<br />vt_score:	12/40 (30%)<br />scanner:	avira<br />virusname:	JS/Redir.jea<br />url:	http://spagenie.ae/vs-spagenie-ae/js/jquery-1.2.3.min.js<br />recent:	up<br />response:	alive<br />ip:	67.227.166.210<br />as:	AS32244<br />review:	67.227.166.210<br />domain:	spagenie.ae<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	67.227.128.0 - 67.227.191.255<br />netname:	LIQUIDWEB-9<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	ns1.salonyservers.com<br />ns2:	ns2.salonyservers.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sangiovanni.tn.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10680181</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.CZ.11]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10680181</guid>
			<pubDate>2013-05-05T19:30:14+02:00</pubDate>
			<description><![CDATA[id:	10680181<br />first:	1367775014<br />last:	0<br />md5:	142b8a5a0c1383efb14c425fe23e7283<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=142b8a5a0c1383efb14c425fe23e7283<br />vt_score:	5/46 (10.9%)<br />scanner:	AntiVir<br />virusname:	JS/BlacoleRef.CZ.11<br />url:	http://sangiovanni.tn.it/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	tn.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://salerno1943.it/chisiamo.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10680178</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.73]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10680178</guid>
			<pubDate>2013-05-05T19:20:38+02:00</pubDate>
			<description><![CDATA[id:	10680178<br />first:	1367774438<br />last:	0<br />md5:	fd0020b4a8b1820cd4f0f6f90f2a1974<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fd0020b4a8b1820cd4f0f6f90f2a1974<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.73<br />url:	http://salerno1943.it/chisiamo.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	salerno1943.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns.technorail.com<br />ns3:	dns3.arubadns.net<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://radioacacia.nl/berichtenbalk/newsticker.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10679842</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HKW]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10679842</guid>
			<pubDate>2013-05-05T17:50:10+02:00</pubDate>
			<description><![CDATA[id:	10679842<br />first:	1367769010<br />last:	0<br />md5:	ea8ed8a531581ddea1257dd980597aaf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ea8ed8a531581ddea1257dd980597aaf<br />vt_score:	0/46 (0.0%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HKW<br />url:	http://radioacacia.nl/berichtenbalk/newsticker.js<br />recent:	up<br />response:	alive<br />ip:	159.253.0.64<br />as:	as61387<br />review:	159.253.0.64<br />domain:	radioacacia.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@denkers-ict.nl<br />inetnum:	159.253.0.1 - 159.253.0.255<br />netname:	AXC<br />descr:	AXC IP infrastructureABUSE -> abuse@denkers-ict.nl<br />ns1:	ns2.ns-1.be<br />ns2:	ns1.ns-1.be<br />ns3:	ns3.ns-1.be<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ontologos.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10674122</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS.Obfus-211]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10674122</guid>
			<pubDate>2013-05-05T14:00:24+02:00</pubDate>
			<description><![CDATA[id:	10674122<br />first:	1367755224<br />last:	0<br />md5:	968ad05be8cc3ea8e4f282aabdd0bc0e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=968ad05be8cc3ea8e4f282aabdd0bc0e<br />vt_score:	30/46 (65.2%)<br />scanner:	clamav<br />virusname:	JS.Obfus-211<br />url:	http://ontologos.org/<br />recent:	up<br />response:	alive<br />ip:	216.98.224.128<br />as:	AS19092<br />review:	216.98.224.128<br />domain:	ontologos.org<br />country:	US<br />source:	ARIN<br />email:	noc@turbonet.com<br />inetnum:	216.98.224.0 - 216.98.255.255<br />netname:	TURBONET<br />descr:	Cactus International, Inc. CACTU-2 211 S. Main St. Moscow ID 83843<br />ns1:	ns3.turbonet.com<br />ns2:	ns1.turbonet.com<br />ns3:	ns2.turbonet.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://oknews.co.kr/suhan/htm/main/target33.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10673648</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10673648</guid>
			<pubDate>2013-05-05T13:50:09+02:00</pubDate>
			<description><![CDATA[id:	10673648<br />first:	1367754609<br />last:	0<br />md5:	841d156a962647e70315390940f796e4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=841d156a962647e70315390940f796e4<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://oknews.co.kr/suhan/htm/main/target33.htm<br />recent:	up<br />response:	alive<br />ip:	218.38.13.104<br />as:	AS9318<br />review:	218.38.13.104<br />domain:	oknews.co.kr<br />country:	kr<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	218.38.0.0 - 218.39.255.255 ( - 218.39.255.255<br />netname:	HANANET-INFRA<br />descr:	<br />ns1:	ns2.hhosting.co.kr<br />ns2:	ns1.hhosting.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nevesbells.com.br/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10673177</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ImgHack.A.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10673177</guid>
			<pubDate>2013-05-05T13:00:30+02:00</pubDate>
			<description><![CDATA[id:	10673177<br />first:	1367751630<br />last:	0<br />md5:	2c227a89c3a6be8495ef2b507ae4d0f5<br />virustotal:	<br />vt_score:	19/39 (48.7%)<br />scanner:	avira<br />virusname:	HTML/ImgHack.A.1<br />url:	http://nevesbells.com.br/<br />recent:	up<br />response:	alive<br />ip:	187.61.61.125<br />as:	AS15201<br />review:	187.61.61.125<br />domain:	nevesbells.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.61.0.0 - 187.61.63.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns1.insite.com.br<br />ns2:	ns3.insite.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lenhart.i-networx.de/sets/filmtext.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10664637</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Feebs.gen@MM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10664637</guid>
			<pubDate>2013-05-05T09:00:11+02:00</pubDate>
			<description><![CDATA[id:	10664637<br />first:	1367737211<br />last:	0<br />md5:	13514d84315f3993d3509717f33c11d2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=13514d84315f3993d3509717f33c11d2<br />vt_score:	1/35 (2.9%)<br />scanner:	TheHacker<br />virusname:	JS/Feebs.gen@MM<br />url:	http://lenhart.i-networx.de/sets/filmtext.htm<br />recent:	up<br />response:	alive<br />ip:	217.70.142.36<br />as:	AS15366<br />review:	217.70.142.36<br />domain:	i-networx.de<br />country:	DE<br />source:	RIPE<br />email:	noc@dns-net.de<br />inetnum:	217.70.142.0 -  217.70.142.255<br />netname:	DE-INTERNETWORX-NET-1<br />descr:	InterNetworX Ltd. & Co. KGUffizio Internet Services RIPE block<br />ns1:	ns3.inwx.de<br />ns2:	ns.inwx.de<br />ns3:	ns2.inwx.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKaeznemezis.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663813</guid>
			<pubDate>2013-05-05T07:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663813<br />first:	1367732414<br />last:	0<br />md5:	28868bda47994c23a6f4e2e7c977b2b1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=28868bda47994c23a6f4e2e7c977b2b1<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKaeznemezis.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://knlsystem.co.kr/new_site/board/file/1265182682.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663812</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Induc.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663812</guid>
			<pubDate>2013-05-05T07:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663812<br />first:	1367732414<br />last:	0<br />md5:	15c8a39f6ea6675658da35fcd1a1b4e8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=15c8a39f6ea6675658da35fcd1a1b4e8<br />vt_score:	37/46 (80.4%)<br />scanner:	avira<br />virusname:	W32/Induc.A<br />url:	http://knlsystem.co.kr/new_site/board/file/1265182682.zip<br />recent:	up<br />response:	alive<br />ip:	1.214.195.194<br />as:	AS3786<br />review:	1.214.195.194<br />domain:	knlsystem.co.kr<br />country:	KR<br />source:	APNIC<br />email:	security@bora.net<br />inetnum:	1.208.0.0 - 1.223.255.255<br />netname:	BORANET<br />descr:	BORANET65-228,DACOM Bldg ,Hangangro 1ga Yongsangu, Seoul****************************************Allocated to KRNIC Member.If you would like to find assignmentinformation in detail please refer tothe KRNIC Whois Database athttp****************************<br />ns1:	ns1.whoisdomain.kr<br />ns2:	ns2.whoisdomain.kr<br />ns3:	ns3.whoisdomain.kr<br />ns4:	ns4.whoisdomain.kr<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p920p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663400</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663400</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663400<br />first:	1367728814<br />last:	0<br />md5:	1bd7537e42325cd9b02fbc8d7146ef17<br />virustotal:	<br />vt_score:	29/45 (64.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p920p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p91p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663399</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663399</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663399<br />first:	1367728814<br />last:	0<br />md5:	f5ce1422bff551960125b7c235a04f80<br />virustotal:	<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p91p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p837p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663398</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663398</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663398<br />first:	1367728814<br />last:	0<br />md5:	47b00bc8cecb4ce150e4d48ee69ba50a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=47b00bc8cecb4ce150e4d48ee69ba50a<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p837p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p789p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663397</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663397</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663397<br />first:	1367728814<br />last:	0<br />md5:	24d89903544882f934e291c60fe94f7d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=24d89903544882f934e291c60fe94f7d<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p789p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p638p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663396</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663396</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663396<br />first:	1367728814<br />last:	0<br />md5:	9879bec91dd013c5a91aa7a9c24cb0fd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9879bec91dd013c5a91aa7a9c24cb0fd<br />vt_score:	28/35 (80%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p638p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p636p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663395</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663395</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663395<br />first:	1367728814<br />last:	0<br />md5:	3dc539209a8e4d87efb9b6cc79fe40dd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3dc539209a8e4d87efb9b6cc79fe40dd<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p636p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p617p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663394</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663394</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663394<br />first:	1367728814<br />last:	0<br />md5:	def679fa7b84369d005af4048d03d3c6<br />virustotal:	<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p617p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p560p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663393</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663393</guid>
			<pubDate>2013-05-05T06:40:14+02:00</pubDate>
			<description><![CDATA[id:	10663393<br />first:	1367728814<br />last:	0<br />md5:	c75f559eb4165eae0a19300b74dee8a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c75f559eb4165eae0a19300b74dee8a3<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p560p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p230p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10663392</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10663392</guid>
			<pubDate>2013-05-05T06:40:09+02:00</pubDate>
			<description><![CDATA[id:	10663392<br />first:	1367728809<br />last:	0<br />md5:	07c930055fa06b96b6422b635a812d33<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=07c930055fa06b96b6422b635a812d33<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p230p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://indianeducationfund.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10661523</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.VA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10661523</guid>
			<pubDate>2013-05-05T04:40:04+02:00</pubDate>
			<description><![CDATA[id:	10661523<br />first:	1367721604<br />last:	0<br />md5:	dfbd1ee66a4e792349591b88660c0956<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.VA<br />url:	http://indianeducationfund.org/<br />recent:	up<br />response:	alive<br />ip:	50.56.211.35<br />as:	AS19994<br />review:	50.56.211.35<br />domain:	indianeducationfund.org<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	50.56.0.0 - 50.57.255.255<br />netname:	RACKS-8-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	ns51.1and1.com<br />ns2:	ns52.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hacha.org/programas/scrollbar.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10660834</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.27136.405]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10660834</guid>
			<pubDate>2013-05-05T02:20:27+02:00</pubDate>
			<description><![CDATA[id:	10660834<br />first:	1367713227<br />last:	0<br />md5:	b15a58fe196b7fb9e06fc96557b603f0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b15a58fe196b7fb9e06fc96557b603f0<br />vt_score:	8/46 (17.4%)<br />scanner:	avira<br />virusname:	TR/Spy.27136.405<br />url:	http://hacha.org/programas/scrollbar.rar<br />recent:	up<br />response:	alive<br />ip:	66.96.147.106<br />as:	AS29873<br />review:	66.96.147.106<br />domain:	hacha.org<br />country:	US<br />source:	ARIN<br />email:	bnbrock@maileig.com<br />inetnum:	66.96.128.0 - 66.96.191.255<br />netname:	BIZLAND-FC01<br />descr:	The Endurance International Group, Inc. EIG-12 70 Blanchard Road Burlington MA 01803<br />ns1:	ns2.ipage.com<br />ns2:	ns1.ipage.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://golabki.gminalukow.pl/karta.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10660226</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.aqu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10660226</guid>
			<pubDate>2013-05-05T01:10:05+02:00</pubDate>
			<description><![CDATA[id:	10660226<br />first:	1367709005<br />last:	0<br />md5:	b8a3679280b0324910aa8666d1eb939b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b8a3679280b0324910aa8666d1eb939b<br />vt_score:	11/43 (25.6%)<br />scanner:	avira<br />virusname:	JS/Agent.aqu<br />url:	http://golabki.gminalukow.pl/karta.html<br />recent:	up<br />response:	alive<br />ip:	195.149.224.233<br />as:	AS29522<br />review:	195.149.224.233<br />domain:	gminalukow.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@kei.pl<br />inetnum:	195.149.224.0 - 195.149.231.255<br />netname:	KEI-KRAKOW-PL<br />descr:	Krakowskie e-Centrum Informatyczne JUMP<br />ns1:	ns2.kei.pl<br />ns2:	ns1.kei.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://de.ufpe.br/~cysneiros/ftp/proensino/Marcela.doc]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10655666</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W97M/Ozwer.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10655666</guid>
			<pubDate>2013-05-04T18:10:26+02:00</pubDate>
			<description><![CDATA[id:	10655666<br />first:	1367683826<br />last:	0<br />md5:	bba8d38b86c456da5a8e6c9d3e763729<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bba8d38b86c456da5a8e6c9d3e763729<br />vt_score:	41/46 (89.1%)<br />scanner:	avira<br />virusname:	W97M/Ozwer.B<br />url:	http://de.ufpe.br/~cysneiros/ftp/proensino/Marcela.doc<br />recent:	up<br />response:	alive<br />ip:	150.161.44.1<br />as:	AS1916<br />review:	150.161.44.1<br />domain:	ufpe.br<br />country:	BR<br />source:	LACNIC<br />email:	alms@cin.ufpe.br<br />inetnum:	150.161.0.0 - 150.161.255.255<br />netname:	BR-UFPE-LACNIC<br />descr:	Universidade Federal de PernambucoAv Prof. Luis Freire, s/n,50740-540 - Recife - PEAv. Prof. Luiz Freire S/N Cidade Universitaria, S/N, CIN50740-540 - Recife - PE<br />ns1:	dns2.cin.ufpe.br<br />ns2:	maracatu.ufpe.br<br />ns3:	frevo.ufpe.br<br />ns4:	dns1.cin.ufpe.br<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cwa-transporte.at/templates/cwa_transporte/script.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10649032</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10649032</guid>
			<pubDate>2013-05-04T17:10:05+02:00</pubDate>
			<description><![CDATA[id:	10649032<br />first:	1367680205<br />last:	0<br />md5:	74e223644b56074415b22a23dfff9623<br />virustotal:	<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://cwa-transporte.at/templates/cwa_transporte/script.js<br />recent:	up<br />response:	alive<br />ip:	213.208.134.240<br />as:	AS1764<br />review:	213.208.134.240<br />domain:	cwa-transporte.at<br />country:	AT<br />source:	RIPE<br />email:	abuse@unixsecurity.at<br />inetnum:	213.208.134.0 - 213.208.134.255<br />netname:	WEBMACHINE-NET-3<br />descr:	webmachine Unixsecurity Network VIE-IX<br />ns1:	ns2.webmachine.at<br />ns2:	ns1.webmachine.at<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://csfformazione.it/aule.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10649031</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10649031</guid>
			<pubDate>2013-05-04T17:10:05+02:00</pubDate>
			<description><![CDATA[id:	10649031<br />first:	1367680205<br />last:	0<br />md5:	666a4a42bf455e23c78fb999d6a277f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=666a4a42bf455e23c78fb999d6a277f2<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.inf<br />url:	http://csfformazione.it/aule.htm<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	csfformazione.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns4.arubadns.cz<br />ns3:	dns2.technorail.com<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://charolas.es/conjuntos2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10647723</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HEUR:Trojan.Script.Generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10647723</guid>
			<pubDate>2013-05-04T13:10:27+02:00</pubDate>
			<description><![CDATA[id:	10647723<br />first:	1367665827<br />last:	0<br />md5:	13a4388d43a88bc512d0e30092efad12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=13a4388d43a88bc512d0e30092efad12<br />vt_score:	1/35 (2.9%)<br />scanner:	Kaspersky<br />virusname:	HEUR:Trojan.Script.Generic<br />url:	http://charolas.es/conjuntos2.html<br />recent:	up<br />response:	alive<br />ip:	217.116.0.144<br />as:	AS16371<br />review:	217.116.0.144<br />domain:	charolas.es<br />country:	ES<br />source:	RIPE<br />email:	abuse@acens.net<br />inetnum:	217.116.0.0 - 217.116.1.127<br />netname:	ACENS-MAD-1<br />descr:	acens technologiesHosting and Housing Madrid<br />ns1:	ns7.acens.net<br />ns2:	ns4.acens.net<br />ns3:	ns3.acens.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://brunoraineri.it/links/siti1.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10647173</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10647173</guid>
			<pubDate>2013-05-04T12:20:03+02:00</pubDate>
			<description><![CDATA[id:	10647173<br />first:	1367662803<br />last:	0<br />md5:	01a84cf5d05e5004d590fd9a3f13d576<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=01a84cf5d05e5004d590fd9a3f13d576<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://brunoraineri.it/links/siti1.htm<br />recent:	up<br />response:	alive<br />ip:	217.73.229.110<br />as:	AS31034<br />review:	217.73.229.110<br />domain:	brunoraineri.it<br />country:	IT<br />source:	RIPE<br />email:	ced@consultingweb.it<br />inetnum:	217.73.224.0 - 217.73.231.255<br />netname:	ALICOM<br />descr:	Alicom S.r.l. NetworkAlicom s.r.l. Network<br />ns1:	ns2.tuonome.it<br />ns2:	ns3.tuonome.it<br />ns3:	ns.tuonome.it<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bizdaily.com.sg/biz_daily_newsletter_002/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10643349</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.alf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10643349</guid>
			<pubDate>2013-05-04T10:40:03+02:00</pubDate>
			<description><![CDATA[id:	10643349<br />first:	1367656803<br />last:	0<br />md5:	89c97fac4dbeb3da2825f7783db289d0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=89c97fac4dbeb3da2825f7783db289d0<br />vt_score:	24/45 (53.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.alf<br />url:	http://bizdaily.com.sg/biz_daily_newsletter_002/<br />recent:	up<br />response:	alive<br />ip:	103.9.101.81<br />as:	AS58621<br />review:	103.9.101.81<br />domain:	bizdaily.com.sg<br />country:	SG<br />source:	APNIC<br />email:	noc@vodien.com<br />inetnum:	103.9.100.0 - 103.9.103.255<br />netname:	VODIEN-AS-AP<br />descr:	Vodien Internet Solutions Pte Ltd40C Hong Kong StreetVodien Internet Solutions Pte Ltd<br />ns1:	dns3.singhost.net<br />ns2:	dns1.singhost.net<br />ns3:	dns4.singhost.net<br />ns4:	dns2.singhost.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bavshvi.ge/index_rus.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10643208</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10643208</guid>
			<pubDate>2013-05-04T10:00:17+02:00</pubDate>
			<description><![CDATA[id:	10643208<br />first:	1367654417<br />last:	0<br />md5:	d7311ce97f5d86885d69747457c13735<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d7311ce97f5d86885d69747457c13735<br />vt_score:	7/31 (22.6%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-inf<br />url:	http://bavshvi.ge/index_rus.html<br />recent:	up<br />response:	alive<br />ip:	80.241.247.195<br />as:	AS12497<br />review:	80.241.247.195<br />domain:	bavshvi.ge<br />country:	GE<br />source:	RIPE<br />email:	ib@caucasus.net<br />inetnum:	80.241.244.0 - 80.241.247.255<br />netname:	SANET-ADSL-BLOCK4<br />descr:	Caucasus Online LLCCaucasus Online LLC<br />ns1:	ns1.hosting.ge<br />ns2:	ns2.hosting.ge<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ayubmed.edu.pk/Admissions/2012/Position.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10643020</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10643020</guid>
			<pubDate>2013-05-04T09:30:06+02:00</pubDate>
			<description><![CDATA[id:	10643020<br />first:	1367652606<br />last:	0<br />md5:	4b044dcbb4e211723d8995d6b5c7420b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4b044dcbb4e211723d8995d6b5c7420b<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://ayubmed.edu.pk/Admissions/2012/Position.htm<br />recent:	up<br />response:	alive<br />ip:	174.37.198.140<br />as:	AS36351<br />review:	174.37.198.140<br />domain:	ayubmed.edu.pk<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	174.36.0.0 - 174.37.255.255<br />netname:	SOFTLAYER-4-7<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	dns1.serverquality.com<br />ns2:	dns2.serverquality.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://36.duote.com.cn/taoxiaobai.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10641102</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Worm.Win32.Dropper.RA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10641102</guid>
			<pubDate>2013-05-04T03:10:08+02:00</pubDate>
			<description><![CDATA[id:	10641102<br />first:	1367629808<br />last:	0<br />md5:	3902f8d5022dcbe134ef9832f053851f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3902f8d5022dcbe134ef9832f053851f<br />vt_score:	15/45 (33.3%)<br />scanner:	Comodo<br />virusname:	Worm.Win32.Dropper.RA<br />url:	http://36.duote.com.cn/taoxiaobai.zip<br />recent:	up<br />response:	alive<br />ip:	61.147.127.199<br />as:	AS23650<br />review:	61.147.127.199<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@jsinfo.net<br />inetnum:	61.147.0.0 - 61.147.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://36.duote.com.cn/qqkongjianrqjl.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10641101</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.905216.7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10641101</guid>
			<pubDate>2013-05-04T03:10:08+02:00</pubDate>
			<description><![CDATA[id:	10641101<br />first:	1367629808<br />last:	0<br />md5:	72e23c2c9cfc766e389199e5c85275c7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=72e23c2c9cfc766e389199e5c85275c7<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	TR/Agent.905216.7<br />url:	http://36.duote.com.cn/qqkongjianrqjl.zip<br />recent:	up<br />response:	alive<br />ip:	61.147.127.199<br />as:	AS23650<br />review:	61.147.127.199<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@jsinfo.net<br />inetnum:	61.147.0.0 - 61.147.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://33.duote.com.cn/qqlthzq.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10641100</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/Genetic.gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10641100</guid>
			<pubDate>2013-05-04T03:10:07+02:00</pubDate>
			<description><![CDATA[id:	10641100<br />first:	1367629807<br />last:	0<br />md5:	3f49f854132b14a95f1b69574873d4eb<br />virustotal:	<br />vt_score:	26/45 (57.8%)<br />scanner:	undef<br />virusname:	Trj/Genetic.gen<br />url:	http://33.duote.com.cn/qqlthzq.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.198<br />as:	AS132524<br />review:	60.209.5.198<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	<br />inetnum:	60.208.0.0 - 60.215.255.255<br />netname:	<br />descr:	<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://32.duote.org/indukdjfiqikdie.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10641099</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADSPY/Lop.BAJ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10641099</guid>
			<pubDate>2013-05-04T03:10:06+02:00</pubDate>
			<description><![CDATA[id:	10641099<br />first:	1367629806<br />last:	0<br />md5:	381a587de529b1958414cd239d55061e<br />virustotal:	<br />vt_score:	19/46 (41.3%)<br />scanner:	avira<br />virusname:	ADSPY/Lop.BAJ<br />url:	http://32.duote.org/indukdjfiqikdie.zip<br />recent:	up<br />response:	alive<br />ip:	122.194.229.99<br />as:	AS4837<br />review:	122.194.229.99<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	122.192.0.0 - 122.195.255.255<br />netname:	UNICOM-JS<br />descr:	China Unicom Jiangsu province networkChina UnicomCNC Group CHINA169 Jiangsu Province Network<br />ns1:	dns3.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://2.duote.org/windowswgsc.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10640775</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Obfuscate.EH.204]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10640775</guid>
			<pubDate>2013-05-04T02:40:12+02:00</pubDate>
			<description><![CDATA[id:	10640775<br />first:	1367628012<br />last:	0<br />md5:	7b6a9b6f1454ae4cc45c7c3aa1e0fd4a<br />virustotal:	<br />vt_score:	23/46 (50%)<br />scanner:	avira<br />virusname:	TR/Obfuscate.EH.204<br />url:	http://2.duote.org/windowswgsc.zip<br />recent:	up<br />response:	alive<br />ip:	221.130.29.184<br />as:	AS9808<br />review:	221.130.29.184<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	socadmin@js.chinamobile.com<br />inetnum:	221.130.0.0 - 221.130.31.255<br />netname:	CMNET-jiangsu<br />descr:	China Mobile Communications Corporation - jiangsu<br />ns1:	dns2.kabasiji.com<br />ns2:	dns1.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://2.duote.com.cn/qqyinshck.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10640774</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.QQLogger.cgt.13]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10640774</guid>
			<pubDate>2013-05-04T02:40:12+02:00</pubDate>
			<description><![CDATA[id:	10640774<br />first:	1367628012<br />last:	0<br />md5:	5bd52f4baf4a7f48dada2055475fdd2b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4b3a2e93368f8f019f8b84936ea71242<br />vt_score:	16/41 (39%)<br />scanner:	avira<br />virusname:	TR/Spy.QQLogger.cgt.13<br />url:	http://2.duote.com.cn/qqyinshck.zip<br />recent:	up<br />response:	alive<br />ip:	122.228.248.4<br />as:	AS4809<br />review:	122.228.248.4<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	122.224.0.0 - 122.239.255.255<br />netname:	CHINANET-ZJ<br />descr:	CHINANET Zhejiang province networkChina TelecomNo.31,jingrong streetBeijing 100032China Telecom Zhejiang Province<br />ns1:	dns3.50bang.org<br />ns2:	dns1.kabasiji.com<br />ns3:	dns4.50bang.org<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://218.95.46.68/jmx/upload/PersonalDisk.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10640771</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Keymake]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10640771</guid>
			<pubDate>2013-05-04T02:40:05+02:00</pubDate>
			<description><![CDATA[id:	10640771<br />first:	1367628005<br />last:	0<br />md5:	d0770813af2a54d5d31c6d0db8d94994<br />virustotal:	<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	SPR/Keymake<br />url:	http://218.95.46.68/jmx/upload/PersonalDisk.rar<br />recent:	up<br />response:	alive<br />ip:	218.95.46.68<br />as:	AS4134<br />review:	218.95.46.68<br />domain:	218.95.46.68<br />country:	CN<br />source:	APNIC<br />email:	hostmaster@public1.nc.jx.cn<br />inetnum:	218.95.0.0 - 218.95.127.255<br />netname:	CHINANET-JX<br />descr:	CHINANET jiangxi province networkChina TelecomNo.31,jingrong streetBeijing 100032<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://210.34.80.109/jwc/file_2011/szk/yyzg13.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10640770</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W2000M/Xaler.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10640770</guid>
			<pubDate>2013-05-04T02:40:05+02:00</pubDate>
			<description><![CDATA[id:	10640770<br />first:	1367628005<br />last:	0<br />md5:	4e352c53a2d70f8c6193a03a30e20439<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4e352c53a2d70f8c6193a03a30e20439<br />vt_score:	31/35 (88.6%)<br />scanner:	avira<br />virusname:	W2000M/Xaler.B<br />url:	http://210.34.80.109/jwc/file_2011/szk/yyzg13.rar<br />recent:	up<br />response:	alive<br />ip:	210.34.80.109<br />as:	AS132524<br />review:	210.34.80.109<br />domain:	210.34.80.109<br />country:	CN<br />source:	APNIC<br />email:	<br />inetnum:	210.32.0.0 - 210.35.255.255<br />netname:	<br />descr:	<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://1.duote.com.cn/qqshengrihaosqq.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10640515</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10640515</guid>
			<pubDate>2013-05-04T02:10:02+02:00</pubDate>
			<description><![CDATA[id:	10640515<br />first:	1367626202<br />last:	0<br />md5:	c35a8e2acc6d5964c26f1a2235397f6e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c35a8e2acc6d5964c26f1a2235397f6e<br />vt_score:	16/46 (34.8%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://1.duote.com.cn/qqshengrihaosqq.zip<br />recent:	up<br />response:	alive<br />ip:	122.228.248.6<br />as:	AS4809<br />review:	122.228.248.6<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	122.224.0.0 - 122.239.255.255<br />netname:	CHINANET-ZJ<br />descr:	CHINANET Zhejiang province networkChina TelecomNo.31,jingrong streetBeijing 100032China Telecom Zhejiang Province<br />ns1:	dns2.kabasiji.com<br />ns2:	dns1.kabasiji.com<br />ns3:	dns4.50bang.org<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://xxx-files.de/rezepte1]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10639712</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10639712</guid>
			<pubDate>2013-05-03T23:00:30+02:00</pubDate>
			<description><![CDATA[id:	10639712<br />first:	1367614830<br />last:	0<br />md5:	658f05b770bcd05c92d5fc03833cc0cb<br />virustotal:	<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/Redirect.AC<br />url:	http://xxx-files.de/rezepte1<br />recent:	up<br />response:	alive<br />ip:	212.172.221.8<br />as:	AS12312<br />review:	212.172.221.8<br />domain:	xxx-files.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@webhoster.de<br />inetnum:	212.172.221.0 - 212.172.221.255<br />netname:	TIS-D406966-NET<br />descr:	webhoster.de AG<br />ns1:	w2.dnsservice.net<br />ns2:	w1.dnsservice.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://welfenwebdesign.de/impressum.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10639611</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.GH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10639611</guid>
			<pubDate>2013-05-03T22:40:25+02:00</pubDate>
			<description><![CDATA[id:	10639611<br />first:	1367613625<br />last:	0<br />md5:	7a9e9cf29b8d789f24ee6602a79ca386<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7a9e9cf29b8d789f24ee6602a79ca386<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.GH<br />url:	http://welfenwebdesign.de/impressum.html<br />recent:	up<br />response:	alive<br />ip:	31.47.251.18<br />as:	AS45012<br />review:	31.47.251.18<br />domain:	welfenwebdesign.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@mediawebline.de<br />inetnum:	31.47.240.0 - 31.47.255.255<br />netname:	DE-MEDIAWEBLINE-20110322<br />descr:	mediamedia<br />ns1:	ns2-tec.de<br />ns2:	ns1-tec.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://usmcwhiskey1-12.org/scrapbk54.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10638709</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.yor]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10638709</guid>
			<pubDate>2013-05-03T21:40:14+02:00</pubDate>
			<description><![CDATA[id:	10638709<br />first:	1367610014<br />last:	0<br />md5:	3ff6958d15f4c415caaf8472601b88a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3ff6958d15f4c415caaf8472601b88a3<br />vt_score:	21/46 (45.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.yor<br />url:	http://usmcwhiskey1-12.org/scrapbk54.html<br />recent:	up<br />response:	alive<br />ip:	199.204.248.106<br />as:	AS19730<br />review:	199.204.248.106<br />domain:	usmcwhiskey1-12.org<br />country:	US<br />source:	ARIN<br />email:	netops@hostican.com<br />inetnum:	199.204.248.0 - 199.204.255.255<br />netname:	HOSTICAN-NETWORK<br />descr:	HostICan HOSTI-15 9700 Atlee Commons Drive Ashland VA 23005<br />ns1:	NS1.MYHOSTCENTER.COM<br />ns2:	NS2.MYHOSTCENTER.COM<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://users.online.be/cosybrassquartet/dirk.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10638708</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10638708</guid>
			<pubDate>2013-05-03T21:40:09+02:00</pubDate>
			<description><![CDATA[id:	10638708<br />first:	1367610009<br />last:	0<br />md5:	e57cce3b968c7461232ef19dcc5bbcf8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e57cce3b968c7461232ef19dcc5bbcf8<br />vt_score:	20/46 (43.5%)<br />scanner:	undef<br />virusname:	HTML/Framer<br />url:	http://users.online.be/cosybrassquartet/dirk.html<br />recent:	up<br />response:	alive<br />ip:	194.88.108.79<br />as:	AS6696<br />review:	194.88.108.79<br />domain:	online.be<br />country:	BE<br />source:	RIPE<br />email:	p.verwerft@online.be<br />inetnum:	194.88.96.0 - 194.88.127.255<br />netname:	BE-GLOBE-960723<br />descr:	Provider Local RegistryOnline Internet nv/sa<br />ns1:	ns.csdg.org<br />ns2:	ns.online.be<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://u.115.la/downfile-16027-yal9tazc.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10637035</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Hupigon.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10637035</guid>
			<pubDate>2013-05-03T21:14:26+02:00</pubDate>
			<description><![CDATA[id:	10637035<br />first:	1367608466<br />last:	0<br />md5:	36b3bab53c45cc3046002347d5dea96e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36b3bab53c45cc3046002347d5dea96e<br />vt_score:	29/35 (82.9%)<br />scanner:	avira<br />virusname:	BDS/Hupigon.Gen<br />url:	http://u.115.la/downfile-16027-yal9tazc.html<br />recent:	up<br />response:	alive<br />ip:	113.105.157.2<br />as:	AS4134<br />review:	113.105.157.2<br />domain:	115.la<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	113.96.0.0 - 113.111.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tuttinscena.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10637034</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10637034</guid>
			<pubDate>2013-05-03T21:14:26+02:00</pubDate>
			<description><![CDATA[id:	10637034<br />first:	1367608466<br />last:	0<br />md5:	1cacdf7000d8037f85c90f8aa9afcb8f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1cacdf7000d8037f85c90f8aa9afcb8f<br />vt_score:	23/45 (51.1%)<br />scanner:	undef<br />virusname:	HTML/Framer<br />url:	http://tuttinscena.it/<br />recent:	up<br />response:	alive<br />ip:	151.1.129.89<br />as:	AS3242<br />review:	151.1.129.89<br />domain:	tuttinscena.it<br />country:	IT<br />source:	RIPE<br />email:	registry@it.net<br />inetnum:	151.1.0.0 - 151.1.255.255<br />netname:	ITNET-WAN<br />descr:	ITnet S.p.A. - Genova - Italia<br />ns1:	ns1.serverwindowsperte.com<br />ns2:	ns2.serverwindowsperte.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://supercrew.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10637032</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10637032</guid>
			<pubDate>2013-05-03T21:14:04+02:00</pubDate>
			<description><![CDATA[id:	10637032<br />first:	1367608444<br />last:	0<br />md5:	96c13a1922d00f46bc162bb35548922c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=96c13a1922d00f46bc162bb35548922c<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.2<br />url:	http://supercrew.de/<br />recent:	up<br />response:	alive<br />ip:	194.116.187.130<br />as:	AS34496<br />review:	194.116.187.130<br />domain:	supercrew.de<br />country:	DE<br />source:	RIPE<br />email:	support@ps-webhosting.de<br />inetnum:	194.116.186.0 - 194.116.187.255<br />netname:	DE-PS-WEBHOSTING<br />descr:	planet school webhosting IP NetworkPlanet School Webhosting e.K.PS-WEBHOSTING-NETPlanet School Webhosting e.K.<br />ns1:	b.ps-dns.net<br />ns2:	a.ps-dns.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://southeast.com.cn/product/product.asp?category_id=57]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10637031</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInject.S]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10637031</guid>
			<pubDate>2013-05-03T21:13:44+02:00</pubDate>
			<description><![CDATA[id:	10637031<br />first:	1367608424<br />last:	0<br />md5:	4cc6597bcf0f70a092618b4e44420ca2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4cc6597bcf0f70a092618b4e44420ca2<br />vt_score:	18/46 (39.1%)<br />scanner:	avira<br />virusname:	HTML/ScrInject.S<br />url:	http://southeast.com.cn/product/product.asp?category_id=57<br />recent:	up<br />response:	alive<br />ip:	219.136.251.49<br />as:	AS4134<br />review:	219.136.251.49<br />domain:	southeast.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse_gdnoc@189.cn<br />inetnum:	219.128.0.0 - 219.137.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	web001.cyberway.net.cn<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sivagiri.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10637030</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10637030</guid>
			<pubDate>2013-05-03T21:13:37+02:00</pubDate>
			<description><![CDATA[id:	10637030<br />first:	1367608417<br />last:	0<br />md5:	abb9bb9f2da3c18b1de24f4352d01933<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=abb9bb9f2da3c18b1de24f4352d01933<br />vt_score:	6/16 (37.5%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://sivagiri.org/<br />recent:	up<br />response:	alive<br />ip:	97.74.215.89<br />as:	AS26496<br />review:	97.74.215.89<br />domain:	sivagiri.org<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns28.domaincontrol.com<br />ns2:	ns27.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://seswa.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10631831</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10631831</guid>
			<pubDate>2013-05-03T16:00:35+02:00</pubDate>
			<description><![CDATA[id:	10631831<br />first:	1367589635<br />last:	0<br />md5:	50b96411d7c7c208a4ef3a1c9ffbeeba<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50b96411d7c7c208a4ef3a1c9ffbeeba<br />vt_score:	16/46 (34.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://seswa.nl/<br />recent:	up<br />response:	alive<br />ip:	70.84.52.153<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	70.84.52.153<br />domain:	seswa.nl<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	70.84.0.0 - 70.87.255.255<br />netname:	NETBLK-THEPLANET-BLK-13<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns216.websitewelcome.com<br />ns2:	ns215.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://qtang.org/soft/UploadFile/2012-2/%D5%A8%B7%BF.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10624241</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Offend.6784461.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10624241</guid>
			<pubDate>2013-05-03T14:10:04+02:00</pubDate>
			<description><![CDATA[id:	10624241<br />first:	1367583004<br />last:	0<br />md5:	6664b65160893bff46aa73a9ce7f722e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6664b65160893bff46aa73a9ce7f722e<br />vt_score:	30/35 (85.7%)<br />scanner:	avira<br />virusname:	TR/Offend.6784461.2<br />url:	http://qtang.org/soft/UploadFile/2012-2/%D5%A8%B7%BF.zip<br />recent:	up<br />response:	alive<br />ip:	116.255.199.92<br />as:	AS4837<br />review:	116.255.199.92<br />domain:	qtang.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	116.255.128.0 - 116.255.255.255<br />netname:	GIANT<br />descr:	ZhengZhou GIANT Computer Network Technology Co., LtdRoom 701 Information Building NO.144 Garden Road, ZhenzhouHenan, P.R.ChinaCNC Group CHINA169 Henan Province NetworkAddresses from CNNIC(GIANT)<br />ns1:	dns28.hichina.com<br />ns2:	dns27.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://promocje.opel.id.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10624151</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.3375]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10624151</guid>
			<pubDate>2013-05-03T13:46:27+02:00</pubDate>
			<description><![CDATA[id:	10624151<br />first:	1367581587<br />last:	0<br />md5:	c21bed650645bdebf43f4f465ac7cd17<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c21bed650645bdebf43f4f465ac7cd17<br />vt_score:	23/45 (51.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.3375<br />url:	http://promocje.opel.id.pl/<br />recent:	up<br />response:	alive<br />ip:	194.0.211.140<br />as:	AS15694<br />review:	194.0.211.140<br />domain:	id.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@contium.pl<br />inetnum:	194.0.211.0 - 194.0.211.255<br />netname:	CDCNET<br />descr:	CDC Sp. z o.oInternet software developerand application provider<br />ns1:	dns1.contium.pl<br />ns2:	dns2.contium.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://marcodibuono.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10621974</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.gkb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10621974</guid>
			<pubDate>2013-05-03T07:00:23+02:00</pubDate>
			<description><![CDATA[id:	10621974<br />first:	1367557223<br />last:	0<br />md5:	94e0077e4d24b2c6ad5d663faffb8622<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=94e0077e4d24b2c6ad5d663faffb8622<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	JS/Agent.gkb<br />url:	http://marcodibuono.it/<br />recent:	up<br />response:	alive<br />ip:	194.242.61.21<br />as:	AS24994<br />review:	194.242.61.21<br />domain:	marcodibuono.it<br />country:	IT<br />source:	RIPE<br />email:	info@genesysinformatica.it<br />inetnum:	194.242.61.0 - 194.242.61.255<br />netname:	GENESYS-NET<br />descr:	HostingSolutions.itGenesys Informatica S.r.l.<br />ns1:	dns1.hostek.it<br />ns2:	dns2.hostek.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3ddescargar]]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10621890</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/StartPage.879411]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10621890</guid>
			<pubDate>2013-05-03T06:00:26+02:00</pubDate>
			<description><![CDATA[id:	10621890<br />first:	1367553626<br />last:	0<br />md5:	a31862d025b7e96a20956b6824547335<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a31862d025b7e96a20956b6824547335<br />vt_score:	28/34 (82.4%)<br />scanner:	avira<br />virusname:	TR/StartPage.879411<br />url:	http://ld.download-guru.com?s=3ddescargar]<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p180p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10621675</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10621675</guid>
			<pubDate>2013-05-03T03:41:04+02:00</pubDate>
			<description><![CDATA[id:	10621675<br />first:	1367545264<br />last:	0<br />md5:	ba00666b11c24dedcf9ddfa631422b05<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ba00666b11c24dedcf9ddfa631422b05<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p180p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jensgundermann.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10621649</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[EXP/JS.Iframe.AG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10621649</guid>
			<pubDate>2013-05-03T03:40:41+02:00</pubDate>
			<description><![CDATA[id:	10621649<br />first:	1367545241<br />last:	0<br />md5:	8f196247f778c477dec997aa34d61a9c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8f196247f778c477dec997aa34d61a9c<br />vt_score:	20/46 (43.5%)<br />scanner:	avira<br />virusname:	EXP/JS.Iframe.AG<br />url:	http://jensgundermann.de/<br />recent:	up<br />response:	alive<br />ip:	46.30.211.50<br />as:	AS51468<br />review:	46.30.211.50<br />domain:	jensgundermann.de<br />country:	DK<br />source:	RIPE<br />email:	abuse@one.com<br />inetnum:	46.30.211.32 - 46.30.211.63<br />netname:	ONE-COM<br />descr:	Webcluster services for One.com<br />ns1:	ns02.one.com<br />ns2:	ns03.one.com<br />ns3:	ns01.one.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://homepizza.com.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10621400</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10621400</guid>
			<pubDate>2013-05-03T01:40:12+02:00</pubDate>
			<description><![CDATA[id:	10621400<br />first:	1367538012<br />last:	0<br />md5:	37bd5267d1fb54bceb43670dd86337eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=37bd5267d1fb54bceb43670dd86337eb<br />vt_score:	13/35 (37.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://homepizza.com.pl/<br />recent:	up<br />response:	alive<br />ip:	79.96.186.82<br />as:	AS12824<br />review:	79.96.186.82<br />domain:	homepizza.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	nextflame-studio.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	dns2.home.pl<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://danjuyurim.org/bbs.asp?Page_Mode=R&Mode=M&No=131&page=3]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10616764</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Redirector.luz]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10616764</guid>
			<pubDate>2013-05-02T18:10:19+02:00</pubDate>
			<description><![CDATA[id:	10616764<br />first:	1367511019<br />last:	0<br />md5:	dcbb4afbc767d83e41b65a1cff6db776<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dcbb4afbc767d83e41b65a1cff6db776<br />vt_score:	19/46 (41.3%)<br />scanner:	avira<br />virusname:	HTML/Redirector.luz<br />url:	http://danjuyurim.org/bbs.asp?Page_Mode=R&Mode=M&No=131&page=3<br />recent:	up<br />response:	alive<br />ip:	61.72.254.231<br />as:	AS132524<br />review:	61.72.254.231<br />domain:	danjuyurim.org<br />country:	KR<br />source:	APNIC<br />email:	<br />inetnum:	61.72.0.0 - 61.75.255.255<br />netname:	<br />descr:	<br />ns1:	ns2.dothost.co.kr<br />ns2:	ns1.dothost.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://czatkam.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10616762</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10616762</guid>
			<pubDate>2013-05-02T18:10:17+02:00</pubDate>
			<description><![CDATA[id:	10616762<br />first:	1367511017<br />last:	0<br />md5:	a0512dff553be9b41e795ce380813142<br />virustotal:	<br />vt_score:	21/45 (46.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://czatkam.pl/<br />recent:	up<br />response:	alive<br />ip:	91.204.161.100<br />as:	AS47482<br />review:	91.204.161.100<br />domain:	czatkam.pl<br />country:	PL<br />source:	RIPE<br />email:	bok@livenet.pl<br />inetnum:	91.204.160.0 - 91.204.163.255<br />netname:	LIVENET-PL<br />descr:	LiveNet.plLIVENET-PLLIVENET-PLNetwork Communication Sp. z o.o.<br />ns1:	ns2.hotservers.pl<br />ns2:	a569.dedyki-dns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://czarnkow.pl/album/index-frame2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10616761</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10616761</guid>
			<pubDate>2013-05-02T18:10:17+02:00</pubDate>
			<description><![CDATA[id:	10616761<br />first:	1367511017<br />last:	0<br />md5:	421f6080944ee7d3be51eea414a55085<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=421f6080944ee7d3be51eea414a55085<br />vt_score:	32/45 (71.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://czarnkow.pl/album/index-frame2.html<br />recent:	up<br />response:	alive<br />ip:	212.85.119.193<br />as:	AS12824<br />review:	212.85.119.193<br />domain:	czarnkow.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.114.0 - 212.85.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://certificazione-energetica-economica.it/js/dnn.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10614834</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.QO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10614834</guid>
			<pubDate>2013-05-02T15:40:41+02:00</pubDate>
			<description><![CDATA[id:	10614834<br />first:	1367502041<br />last:	0<br />md5:	ef6d509830cedc49c32d4571f944c439<br />virustotal:	<br />vt_score:	28/46 (60.9%)<br />scanner:	avira<br />virusname:	JS/Redirector.QO<br />url:	http://certificazione-energetica-economica.it/js/dnn.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	certificazione-energetica-economica.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns2.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bruckbauer.at/mathematik/diff_einfuehrung/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10613735</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10613735</guid>
			<pubDate>2013-05-02T14:50:11+02:00</pubDate>
			<description><![CDATA[id:	10613735<br />first:	1367499011<br />last:	0<br />md5:	08ecc62b024c6949eb6f857a4ecabc65<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=08ecc62b024c6949eb6f857a4ecabc65<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/Redirect.AC<br />url:	http://bruckbauer.at/mathematik/diff_einfuehrung/index.htm<br />recent:	up<br />response:	alive<br />ip:	195.70.232.194<br />as:	AS8437<br />review:	195.70.232.194<br />domain:	bruckbauer.at<br />country:	AT<br />source:	RIPE<br />email:	abuse@uta.at<br />inetnum:	195.70.232.192 - 195.70.232.223<br />netname:	AT-XWEB-2<br />descr:	xweb OGGuglgasse 14/4181110 WienUTA Telekom AG<br />ns1:	ns2.xvveb.net<br />ns2:	ns1.xvveb.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bestpolishstaff.co.uk/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10609025</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/PhoexRef.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10609025</guid>
			<pubDate>2013-05-02T13:20:22+02:00</pubDate>
			<description><![CDATA[id:	10609025<br />first:	1367493622<br />last:	0<br />md5:	257c5a9f01e3941817ca9f07e8fbe681<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=257c5a9f01e3941817ca9f07e8fbe681<br />vt_score:	31/45 (68.9%)<br />scanner:	avira<br />virusname:	JS/PhoexRef.E<br />url:	http://bestpolishstaff.co.uk/index.html<br />recent:	up<br />response:	alive<br />ip:	89.161.170.94<br />as:	AS12824<br />review:	89.161.170.94<br />domain:	bestpolishstaff.co.uk<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ajansgiresun.org/ajans/default.asp?menu=detay1]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10602623</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.40]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10602623</guid>
			<pubDate>2013-05-02T09:10:12+02:00</pubDate>
			<description><![CDATA[id:	10602623<br />first:	1367478612<br />last:	0<br />md5:	d072cd602211a6b4a1eda968df36cdc1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=79461661a81e6f0c7f5b1afbec99df47<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.40<br />url:	http://ajansgiresun.org/ajans/default.asp?menu=detay1<br />recent:	up<br />response:	alive<br />ip:	69.43.161.157<br />as:	AS22489<br />review:	69.43.161.157<br />domain:	ajansgiresun.org<br />country:	AU<br />source:	ARIN<br />email:	hostmaster@trellian.com<br />inetnum:	69.43.161.0 - 69.43.161.255<br />netname:	NET-69-43-161-0-1<br />descr:	Trellian Pty Ltd TRELL-4 8 East Concourse Beaumaris VIC 3193<br />ns1:	ns1.above.com<br />ns2:	ns2.above.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://9.duote.com.cn/qqpass.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10601879</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Age.whps.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10601879</guid>
			<pubDate>2013-05-02T08:40:12+02:00</pubDate>
			<description><![CDATA[id:	10601879<br />first:	1367476812<br />last:	0<br />md5:	b74bf7cc82edc3641b6156d151008d24<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b74bf7cc82edc3641b6156d151008d24<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/Dldr.Age.whps.1<br />url:	http://9.duote.com.cn/qqpass.zip<br />recent:	up<br />response:	alive<br />ip:	61.147.127.195<br />as:	AS23650<br />review:	61.147.127.195<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@jsinfo.net<br />inetnum:	61.147.0.0 - 61.147.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns1.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://88.duote.com.cn/ieesetup.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10601365</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADSPY/Agent.616156]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10601365</guid>
			<pubDate>2013-05-02T08:20:13+02:00</pubDate>
			<description><![CDATA[id:	10601365<br />first:	1367475613<br />last:	0<br />md5:	9eee63017a91f960bb3dea5a2b207709<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9eee63017a91f960bb3dea5a2b207709<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	ADSPY/Agent.616156<br />url:	http://88.duote.com.cn/ieesetup.zip<br />recent:	up<br />response:	alive<br />ip:	221.180.22.211<br />as:	AS56042<br />review:	221.180.22.211<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	hostmaster@chinamobile.com<br />inetnum:	221.176.0.0 - 221.183.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in China<br />ns1:	dns2.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://75.duote.org/chxf.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10601364</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10601364</guid>
			<pubDate>2013-05-02T08:20:13+02:00</pubDate>
			<description><![CDATA[id:	10601364<br />first:	1367475613<br />last:	0<br />md5:	101de6dc6b052f482a0fc05efb8573c0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=101de6dc6b052f482a0fc05efb8573c0<br />vt_score:	9/45 (20%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://75.duote.org/chxf.zip<br />recent:	up<br />response:	alive<br />ip:	58.215.133.147<br />as:	AS4134<br />review:	58.215.133.147<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	ip@jsinfo.net<br />inetnum:	58.208.0.0 - 58.223.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://68.duote.com.cn/bfbtbwwqf.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10601363</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.wgt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10601363</guid>
			<pubDate>2013-05-02T08:20:11+02:00</pubDate>
			<description><![CDATA[id:	10601363<br />first:	1367475611<br />last:	0<br />md5:	425271caefab4adf5c4bbdc358f073de<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=425271caefab4adf5c4bbdc358f073de<br />vt_score:	14/34 (41.2%)<br />scanner:	avira<br />virusname:	TR/Agent.wgt<br />url:	http://68.duote.com.cn/bfbtbwwqf.zip<br />recent:	up<br />response:	alive<br />ip:	61.164.109.226<br />as:	AS4134<br />review:	61.164.109.226<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@wz.zj.cn<br />inetnum:	61.164.108.0 - 61.164.111.255<br />netname:	RUIAN-TELECOM<br />descr:	Ruian Telecom<br />ns1:	dns3.50bang.org<br />ns2:	dns1.kabasiji.com<br />ns3:	dns4.50bang.org<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://47.duote.com.cn/qqqunfa.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10599926</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.552960.14]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10599926</guid>
			<pubDate>2013-05-02T07:30:09+02:00</pubDate>
			<description><![CDATA[id:	10599926<br />first:	1367472609<br />last:	0<br />md5:	846f0f6c18be1b07c42fc712eac63f12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=846f0f6c18be1b07c42fc712eac63f12<br />vt_score:	17/36 (47.2%)<br />scanner:	AntiVir<br />virusname:	TR/Agent.552960.14<br />url:	http://47.duote.com.cn/qqqunfa.zip<br />recent:	up<br />response:	alive<br />ip:	59.51.114.114<br />as:	AS4134<br />review:	59.51.114.114<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	59.51.0.0 - 59.51.127.255<br />netname:	CHINANET-HN<br />descr:	CHINANET Hunan province networkChina TelecomNo1,jin-rong StreetBeijing 100032<br />ns1:	dns4.50bang.org<br />ns2:	dns3.50bang.org<br />ns3:	dns1.kabasiji.com<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://40.duote.org/eyebaohu.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10599925</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Age.whps.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10599925</guid>
			<pubDate>2013-05-02T07:30:08+02:00</pubDate>
			<description><![CDATA[id:	10599925<br />first:	1367472608<br />last:	0<br />md5:	03bb0c4b1e170ad70d7f556deeb67fd6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=03bb0c4b1e170ad70d7f556deeb67fd6<br />vt_score:	8/46 (17.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Age.whps.1<br />url:	http://40.duote.org/eyebaohu.zip<br />recent:	up<br />response:	alive<br />ip:	211.162.121.149<br />as:	AS17623<br />review:	211.162.121.149<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	speed0822@sina.com<br />inetnum:	211.162.112.0 - 211.162.127.255<br />netname:	GWBN-SHENZHEN<br />descr:	FOR GREAT WALL BROADBAND NETWORK SERVICE ACCESS IN SHENZHEN<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns1.kabasiji.com<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://22.duote.com.cn/hao123gjt.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10599884</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Riskware/Toolbar]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10599884</guid>
			<pubDate>2013-05-02T07:01:08+02:00</pubDate>
			<description><![CDATA[id:	10599884<br />first:	1367470868<br />last:	0<br />md5:	435881b48cc8c3f7f14853758670ecd8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=435881b48cc8c3f7f14853758670ecd8<br />vt_score:	10/46 (21.7%)<br />scanner:	undef<br />virusname:	Riskware/Toolbar<br />url:	http://22.duote.com.cn/hao123gjt.zip<br />recent:	up<br />response:	alive<br />ip:	58.211.23.175<br />as:	AS4134<br />review:	58.211.23.175<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	ip@jsinfo.net<br />inetnum:	58.208.0.0 - 58.223.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://183.60.204.122:6888/CF%E5%85%B3%E5%85%AC.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10599377</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10599377</guid>
			<pubDate>2013-05-02T06:40:03+02:00</pubDate>
			<description><![CDATA[id:	10599377<br />first:	1367469603<br />last:	0<br />md5:	bc788beae95b057631538cecc76110fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bc788beae95b057631538cecc76110fa<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://183.60.204.122:6888/CF%E5%85%B3%E5%85%AC.rar<br />recent:	up<br />response:	alive<br />ip:	183.60.204.122<br />as:	AS4134<br />review:	183.60.204.122<br />domain:	183.60.204.122<br />country:	CN<br />source:	APNIC<br />email:	abuse_gdnoc@189.cn<br />inetnum:	183.0.0.0 - 183.63.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lenhart.i-networx.de/sets/feedbackkopf.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10598447</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Framer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10598447</guid>
			<pubDate>2013-05-02T05:40:19+02:00</pubDate>
			<description><![CDATA[id:	10598447<br />first:	1367466019<br />last:	0<br />md5:	3cf8ee92f0e8545ebb612ffd1789292b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3cf8ee92f0e8545ebb612ffd1789292b<br />vt_score:	24/46 (52.2%)<br />scanner:	undef<br />virusname:	HTML/Framer<br />url:	http://lenhart.i-networx.de/sets/feedbackkopf.htm<br />recent:	up<br />response:	alive<br />ip:	217.70.142.36<br />as:	AS15366<br />review:	217.70.142.36<br />domain:	i-networx.de<br />country:	DE<br />source:	RIPE<br />email:	noc@dns-net.de<br />inetnum:	217.70.142.0 -  217.70.142.255<br />netname:	DE-INTERNETWORX-NET-1<br />descr:	InterNetworX Ltd. & Co. KGUffizio Internet Services RIPE block<br />ns1:	ns3.inwx.de<br />ns2:	ns.inwx.de<br />ns3:	ns2.inwx.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://korneliuszmatauszek.pl/kazania/wipo/pas4.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10597935</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10597935</guid>
			<pubDate>2013-05-02T05:00:09+02:00</pubDate>
			<description><![CDATA[id:	10597935<br />first:	1367463609<br />last:	0<br />md5:	f76b9e31ac3d061189432ebb01a73f1b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f76b9e31ac3d061189432ebb01a73f1b<br />vt_score:	24/45 (53.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://korneliuszmatauszek.pl/kazania/wipo/pas4.html<br />recent:	up<br />response:	alive<br />ip:	89.161.179.213<br />as:	AS12824<br />review:	89.161.179.213<br />domain:	korneliuszmatauszek.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://apitsd.org/upl_doc/mp3/2417.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10596371</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10596371</guid>
			<pubDate>2013-05-02T04:10:13+02:00</pubDate>
			<description><![CDATA[id:	10596371<br />first:	1367460613<br />last:	0<br />md5:	9c113d699ed8a3b7b576fde9d35a0281<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9c113d699ed8a3b7b576fde9d35a0281<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://apitsd.org/upl_doc/mp3/2417.html<br />recent:	up<br />response:	alive<br />ip:	94.155.15.10<br />as:	AS49226<br />review:	94.155.15.10<br />domain:	apitsd.org<br />country:	BG<br />source:	RIPE<br />email:	abuse@itdnet.net<br />inetnum:	94.155.15.0 - 94.155.15.255<br />netname:	IRISVISIA<br />descr:	Iris Visia Ltd.<br />ns1:	ns11.irisvisia.com<br />ns2:	ns10.irisvisia.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://apitsd.org/upl_doc/mp3/1500.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10596370</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10596370</guid>
			<pubDate>2013-05-02T04:10:12+02:00</pubDate>
			<description><![CDATA[id:	10596370<br />first:	1367460612<br />last:	0<br />md5:	73278a1d5d0cb16ef7f6915ae3119acb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=73278a1d5d0cb16ef7f6915ae3119acb<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://apitsd.org/upl_doc/mp3/1500.html<br />recent:	up<br />response:	alive<br />ip:	94.155.15.10<br />as:	AS49226<br />review:	94.155.15.10<br />domain:	apitsd.org<br />country:	BG<br />source:	RIPE<br />email:	abuse@itdnet.net<br />inetnum:	94.155.15.0 - 94.155.15.255<br />netname:	IRISVISIA<br />descr:	Iris Visia Ltd.<br />ns1:	ns11.irisvisia.com<br />ns2:	ns10.irisvisia.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zc.97down.info/avzc.rar?qqdrsign=10845]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10595197</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.VB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10595197</guid>
			<pubDate>2013-05-02T03:30:21+02:00</pubDate>
			<description><![CDATA[id:	10595197<br />first:	1367458221<br />last:	0<br />md5:	a284cd3fd6c93d859e68c78faac1ab34<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a284cd3fd6c93d859e68c78faac1ab34<br />vt_score:	2/46 (4.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.VB<br />url:	http://zc.97down.info/avzc.rar?qqdrsign=10845<br />recent:	up<br />response:	alive<br />ip:	103.15.104.173<br />as:	AS55720<br />review:	103.15.104.173<br />domain:	97down.info<br />country:	HK<br />source:	APNIC<br />email:	support@thegigabit.com<br />inetnum:	103.15.104.0 - 103.15.104.255<br />netname:	MYTEK-MY<br />descr:	Hong Kong IDC<br />ns1:	ns231.dnsever.com<br />ns2:	ns259.dnsever.com<br />ns3:	ns16.dnsever.com<br />ns4:	ns68.dnsever.com<br />ns5:	ns27.dnsever.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wiesn-traumpaar.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10593957</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Decode-ADH Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10593957</guid>
			<pubDate>2013-05-02T02:10:11+02:00</pubDate>
			<description><![CDATA[id:	10593957<br />first:	1367453411<br />last:	0<br />md5:	4c2a3d4f8d191e0061b526108a41720f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4c2a3d4f8d191e0061b526108a41720f<br />vt_score:	4/35 (11.4%)<br />scanner:	Avast<br />virusname:	JS:Decode-ADH Trj<br />url:	http://wiesn-traumpaar.de/<br />recent:	up<br />response:	alive<br />ip:	95.142.64.10<br />as:	AS51483<br />review:	95.142.64.10<br />domain:	wiesn-traumpaar.de<br />country:	DE<br />source:	RIPE<br />email:	heidenreich@sasg.de<br />inetnum:	95.142.64.0 - 95.142.66.41<br />netname:	SASG-NET<br />descr:	SaSG GmbH & Co. KGCecinastr. 7082205 GilchingSaSG GmbH & Co. KG<br />ns1:	ns3.sasg.de<br />ns2:	ns1.sasg.de<br />ns3:	ns2.sasg.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sokut.ir/images/.uploads/l.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10587179</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/IRCBOT.K]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10587179</guid>
			<pubDate>2013-05-01T21:10:26+02:00</pubDate>
			<description><![CDATA[id:	10587179<br />first:	1367435426<br />last:	0<br />md5:	4ef4e54b52c9818f205483b4c03c35fb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4ef4e54b52c9818f205483b4c03c35fb<br />vt_score:	19/40 (47.5%)<br />scanner:	avira<br />virusname:	PHP/IRCBOT.K<br />url:	http://sokut.ir/images/.uploads/l.jpg<br />recent:	up<br />response:	alive<br />ip:	79.175.160.24<br />as:	AS25184<br />review:	79.175.160.24<br />domain:	sokut.ir<br />country:	IR<br />source:	RIPE<br />email:	AFR@NET<br />inetnum:	79.175.128.0 - 79.175.191.255<br />netname:	IR-AFRANET-20071112<br />descr:	AfranetAFranet Co<br />ns1:	ns1.linux.aryanic.org<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery4/pages/Pict0085.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10586432</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10586432</guid>
			<pubDate>2013-05-01T20:20:09+02:00</pubDate>
			<description><![CDATA[id:	10586432<br />first:	1367432409<br />last:	0<br />md5:	7bbe7dee1656588a5db05f3f7d515712<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7bbe7dee1656588a5db05f3f7d515712<br />vt_score:	25/45 (55.6%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery4/pages/Pict0085.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://s111.org/s111.org/app/cfgsrv102.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10583214</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Adware.Agent-1575]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10583214</guid>
			<pubDate>2013-05-01T18:01:12+02:00</pubDate>
			<description><![CDATA[id:	10583214<br />first:	1367424072<br />last:	0<br />md5:	b51f260509df2734560a6f95d937c534<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b51f260509df2734560a6f95d937c534<br />vt_score:	25/46 (54.3%)<br />scanner:	clamav<br />virusname:	Win.Adware.Agent-1575<br />url:	http://s111.org/s111.org/app/cfgsrv102.zip<br />recent:	up<br />response:	alive<br />ip:	219.151.8.70<br />as:	AS4134<br />review:	219.151.8.70<br />domain:	s111.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	219.151.0.0 - 219.151.31.255<br />netname:	CHINANET-GZ<br />descr:	CHINANET Guizhou province networkData Communication DivisionChina Telecom<br />ns1:	ns17.xincache.com<br />ns2:	ns18.xincache.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://restaurantdrugstore.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10582679</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.US]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10582679</guid>
			<pubDate>2013-05-01T17:32:30+02:00</pubDate>
			<description><![CDATA[id:	10582679<br />first:	1367422350<br />last:	0<br />md5:	c16267a89266e5c4e624fe8709adbec3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c16267a89266e5c4e624fe8709adbec3<br />vt_score:	16/45 (35.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.US<br />url:	http://restaurantdrugstore.de/<br />recent:	up<br />response:	alive<br />ip:	213.160.86.71<br />as:	AS12574<br />review:	213.160.86.71<br />domain:	restaurantdrugstore.de<br />country:	DE<br />source:	RIPE<br />email:	support@knallhart.de<br />inetnum:	213.160.86.0 -  213.160.87.255<br />netname:	KNALLHART1<br />descr:	Knallhart Marketing GmbHVoltastrasse 513355 Berlinrouting.net<br />ns1:	ns1.knallhart.de<br />ns2:	ns2.knallhart.de<br />ns3:	ns3.knallhart.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://raum-kunst-lehre.de/templates/home/js/OIE.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10581959</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10581959</guid>
			<pubDate>2013-05-01T17:00:38+02:00</pubDate>
			<description><![CDATA[id:	10581959<br />first:	1367420438<br />last:	0<br />md5:	0de680f16712446b04c134ff4c368082<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0de680f16712446b04c134ff4c368082<br />vt_score:	12/33 (36.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://raum-kunst-lehre.de/templates/home/js/OIE.js<br />recent:	up<br />response:	alive<br />ip:	85.13.147.27<br />as:	AS34788<br />review:	85.13.147.27<br />domain:	raum-kunst-lehre.de<br />country:	DE<br />source:	RIPE<br />email:	ip@all-inkl.com<br />inetnum:	85.13.128.0 - 85.13.191.255<br />netname:	DE-ALL-INKL-20050405<br />descr:	Neue Medien Muennich<br />ns1:	ns5.kasserver.com<br />ns2:	ns6.kasserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ragverp.nl/images/aankeuring2006-1/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10581958</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.azb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10581958</guid>
			<pubDate>2013-05-01T17:00:37+02:00</pubDate>
			<description><![CDATA[id:	10581958<br />first:	1367420437<br />last:	0<br />md5:	1155cba7e70f15ec02aa901c9ed3e4e8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2424ee2c60e56f9ebe899647e5dc5fba<br />vt_score:	13/36 (36.1%)<br />scanner:	undef<br />virusname:	HTML/IFrame.azb<br />url:	http://ragverp.nl/images/aankeuring2006-1/index.html<br />recent:	up<br />response:	alive<br />ip:	188.93.150.31<br />as:	AS21155<br />review:	188.93.150.31<br />domain:	ragverp.nl<br />country:	NL<br />source:	ARIN<br />email:	noc@mijndomein.nl<br />inetnum:	188.93.144.0 - 188.93.151.255<br />netname:	NL-MIJNDOMEIN-20090514<br />descr:	mijndomein.nl BVmijndomein.nl BV<br />ns1:	ns1.metaregistrar.nl<br />ns2:	ns2.metaregistrar.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mircclub.org/addon/msnmirc.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10572568</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.prt.9]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10572568</guid>
			<pubDate>2013-05-01T08:50:07+02:00</pubDate>
			<description><![CDATA[id:	10572568<br />first:	1367391007<br />last:	0<br />md5:	d8efaff21b062a4e056801298c40f7f5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d8efaff21b062a4e056801298c40f7f5<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	TR/Agent.prt.9<br />url:	http://mircclub.org/addon/msnmirc.zip<br />recent:	up<br />response:	alive<br />ip:	176.53.58.159<br />as:	AS42926<br />review:	176.53.58.159<br />domain:	mircclub.org<br />country:	TR<br />source:	RIPE<br />email:	abuse@as42926.net<br />inetnum:	176.53.0.0 - 176.53.127.255<br />netname:	TR-RADORE-20110526<br />descr:	Radore Hosting Telekomunikasyon Hizmetleri San. ve Tic. Ltd. Sti.AS42926-NETWORK<br />ns1:	ns2.nidosa.com<br />ns2:	ns1.nidosa.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://margutti.eu/media/system/js/mootools-core.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10572196</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZK Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10572196</guid>
			<pubDate>2013-05-01T08:10:18+02:00</pubDate>
			<description><![CDATA[id:	10572196<br />first:	1367388618<br />last:	0<br />md5:	cf58a30ea9b7a731712baede90b790ec<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=32a91b99ed9e1cdd8f611aea5c2fb427<br />vt_score:	20/36 (55.6%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZK Trj<br />url:	http://margutti.eu/media/system/js/mootools-core.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	margutti.eu<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns.technorail.com<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=aventura]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10570606</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10570606</guid>
			<pubDate>2013-05-01T06:50:15+02:00</pubDate>
			<description><![CDATA[id:	10570606<br />first:	1367383815<br />last:	0<br />md5:	325b154d33ab44c6ce434e9405fe425c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=325b154d33ab44c6ce434e9405fe425c<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=aventura<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3dgtasanandreaspc&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10570605</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10570605</guid>
			<pubDate>2013-05-01T06:50:15+02:00</pubDate>
			<description><![CDATA[id:	10570605<br />first:	1367383815<br />last:	0<br />md5:	36c63cd9f6e35e79e5de0cbf01147999<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36c63cd9f6e35e79e5de0cbf01147999<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3dgtasanandreaspc&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3d3d3d%]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10570494</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/StartPage.879411]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10570494</guid>
			<pubDate>2013-05-01T06:30:53+02:00</pubDate>
			<description><![CDATA[id:	10570494<br />first:	1367382653<br />last:	0<br />md5:	b82cc33f32342fdc790813c5496ed435<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b82cc33f32342fdc790813c5496ed435<br />vt_score:	37/46 (80.4%)<br />scanner:	avira<br />virusname:	TR/StartPage.879411<br />url:	http://ld.download-guru.com?s=3d3d3d%<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kticopper.co.kr/images/indexpd_09.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10570493</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/PicFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10570493</guid>
			<pubDate>2013-05-01T06:30:46+02:00</pubDate>
			<description><![CDATA[id:	10570493<br />first:	1367382646<br />last:	0<br />md5:	d9cb0c807d8007b3eb8210ad39c0f0b9<br />virustotal:	<br />vt_score:	24/42 (57.1%)<br />scanner:	avira<br />virusname:	HTML/PicFrame.Gen<br />url:	http://kticopper.co.kr/images/indexpd_09.jpg<br />recent:	up<br />response:	alive<br />ip:	112.216.119.230<br />as:	AS3786<br />review:	112.216.119.230<br />domain:	kticopper.co.kr<br />country:	KR<br />source:	APNIC<br />email:	shkim082@chol.com<br />inetnum:	112.216.0.0 - 112.223.255.255<br />netname:	BORANET-KR<br />descr:	LG DACOM Corporation<br />ns1:	yjchul<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p92p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566425</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566425</guid>
			<pubDate>2013-05-01T03:40:09+02:00</pubDate>
			<description><![CDATA[id:	10566425<br />first:	1367372409<br />last:	0<br />md5:	a60aa0574e891a30abed5fe0078b92c2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a60aa0574e891a30abed5fe0078b92c2<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p92p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p918p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566424</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566424</guid>
			<pubDate>2013-05-01T03:40:09+02:00</pubDate>
			<description><![CDATA[id:	10566424<br />first:	1367372409<br />last:	0<br />md5:	f6f6b38d2f159cb6bf72d8dc8a6f1eb3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f6f6b38d2f159cb6bf72d8dc8a6f1eb3<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p918p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p752p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566423</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566423</guid>
			<pubDate>2013-05-01T03:40:09+02:00</pubDate>
			<description><![CDATA[id:	10566423<br />first:	1367372409<br />last:	0<br />md5:	d7b1ac20b4e55ccacdf78af2814da3d7<br />virustotal:	<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p752p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566422</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ku.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566422</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566422<br />first:	1367372405<br />last:	0<br />md5:	8c240c71ae5f2769aec8c32fe9766006<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8c240c71ae5f2769aec8c32fe9766006<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.ku.1<br />url:	http://jong1025.com.ne.kr/html/sbr32<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p672p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566421</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566421</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566421<br />first:	1367372405<br />last:	0<br />md5:	1026506ce811e681a1aef77cb5b4e193<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1026506ce811e681a1aef77cb5b4e193<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p672p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p492p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566420</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566420</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566420<br />first:	1367372405<br />last:	0<br />md5:	5e384af1656c229abd210820dc939ea3<br />virustotal:	<br />vt_score:	29/44 (65.9%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p492p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p353p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566419</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566419</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566419<br />first:	1367372405<br />last:	0<br />md5:	8519c49ecf5bde84dcfd586a56c38ae4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8519c49ecf5bde84dcfd586a56c38ae4<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p353p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p30p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566418</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566418</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566418<br />first:	1367372405<br />last:	0<br />md5:	f86e9e564b004b726e8d8c827b3b8687<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f86e9e564b004b726e8d8c827b3b8687<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p30p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p23p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566417</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566417</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566417<br />first:	1367372405<br />last:	0<br />md5:	f20a47e28e9a45b92b143e0cb2fcecb3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f20a47e28e9a45b92b143e0cb2fcecb3<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p23p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p103p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10566416</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10566416</guid>
			<pubDate>2013-05-01T03:40:05+02:00</pubDate>
			<description><![CDATA[id:	10566416<br />first:	1367372405<br />last:	0<br />md5:	f6f56249e34adc8602d18ed5cd84dff0<br />virustotal:	<br />vt_score:	30/45 (66.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p103p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://home.tinp.net.tw/mypage/00126507/exe/dbe.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10564040</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/SPY.KeyLogger.ihx.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10564040</guid>
			<pubDate>2013-05-01T01:40:22+02:00</pubDate>
			<description><![CDATA[id:	10564040<br />first:	1367365222<br />last:	0<br />md5:	6efd2c3030a183debbd1ef70bf4f1596<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6efd2c3030a183debbd1ef70bf4f1596<br />vt_score:	23/45 (51.1%)<br />scanner:	avira<br />virusname:	TR/SPY.KeyLogger.ihx.1<br />url:	http://home.tinp.net.tw/mypage/00126507/exe/dbe.zip<br />recent:	up<br />response:	alive<br />ip:	61.60.224.22<br />as:	AS18049<br />review:	61.60.224.22<br />domain:	tinp.net.tw<br />country:	TW<br />source:	APNIC<br />email:	kevinlo@tinp.com.tw<br />inetnum:	61.60.224.0 - 61.60.239.255<br />netname:	TINP-NET<br />descr:	Taiwan Infrastructure Network Technologies3F, No. 259, Sec. 2, Kuo-Kung Rd.Da-Li City , Taichung Taiwan<br />ns1:	dns.tinp.net.tw<br />ns2:	ns.tinp.net.tw<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://graphic-design.ca/~tpaul]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10562880</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.HC.23]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10562880</guid>
			<pubDate>2013-05-01T00:20:13+02:00</pubDate>
			<description><![CDATA[id:	10562880<br />first:	1367360413<br />last:	0<br />md5:	a0a20090f6241066923c53a9dfb76c75<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a0a20090f6241066923c53a9dfb76c75<br />vt_score:	23/31 (74.2%)<br />scanner:	avira<br />virusname:	JS/Redirector.HC.23<br />url:	http://graphic-design.ca/~tpaul<br />recent:	up<br />response:	alive<br />ip:	205.211.140.114<br />as:	AS393253<br />review:	205.211.140.114<br />domain:	graphic-design.ca<br />country:	CA<br />source:	ARIN<br />email:	<br />inetnum:	205.211.140.0 - 205.211.141.255<br />netname:	<br />descr:	<br />ns1:	ns1.fanshawec.ca<br />ns2:	dns1.largnet.on.ca<br />ns3:	ns2.fanshawec.ca<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://exportconsultants.co.th/file/eDM/OSP0802BM/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10559896</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.VJ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10559896</guid>
			<pubDate>2013-04-30T22:00:35+02:00</pubDate>
			<description><![CDATA[id:	10559896<br />first:	1367352035<br />last:	0<br />md5:	b46d8687e1c7ad6a3fff134dbe938f7f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.VJ<br />url:	http://exportconsultants.co.th/file/eDM/OSP0802BM/<br />recent:	up<br />response:	alive<br />ip:	122.155.168.142<br />as:	AS9931<br />review:	122.155.168.142<br />domain:	exportconsultants.co.th<br />country:	TH<br />source:	APNIC<br />email:	abuse@idc.cattelecom.com<br />inetnum:	122.155.160.0 - 122.155.191.255<br />netname:	CAT-IDC2-Service<br />descr:	CAT IDC2 14th floor<br />ns1:	ns.exportconsultants.co.th<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://erkelmuvhaz.hu/2011_december.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10559680</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.20]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10559680</guid>
			<pubDate>2013-04-30T21:40:29+02:00</pubDate>
			<description><![CDATA[id:	10559680<br />first:	1367350829<br />last:	0<br />md5:	0cdb887b19f526df2002a60e6048e8b5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0cdb887b19f526df2002a60e6048e8b5<br />vt_score:	22/35 (62.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.BS.20<br />url:	http://erkelmuvhaz.hu/2011_december.html<br />recent:	up<br />response:	alive<br />ip:	81.0.104.141<br />as:	AS12301<br />review:	81.0.104.141<br />domain:	erkelmuvhaz.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@invitel.net<br />inetnum:	81.0.104.0 - 81.0.104.255<br />netname:	VTH<br />descr:	Datacenter Hosting Internet<br />ns1:	ns1.dotroll.com<br />ns2:	ns2.dotroll.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://erayat.org/kbpp/8s.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10559679</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10559679</guid>
			<pubDate>2013-04-30T21:40:29+02:00</pubDate>
			<description><![CDATA[id:	10559679<br />first:	1367350829<br />last:	0<br />md5:	b4e14c27ac18d2ea788993a252d236af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b4e14c27ac18d2ea788993a252d236af<br />vt_score:	0/45 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://erayat.org/kbpp/8s.htm<br />recent:	up<br />response:	alive<br />ip:	103.247.151.151<br />as:	AS56202<br />review:	103.247.151.151<br />domain:	erayat.org<br />country:	IN<br />source:	APNIC<br />email:	bhanu@datagalaxy.in<br />inetnum:	103.247.148.0 - 103.247.151.255<br />netname:	RIA-INFOSOLUTIONS-IN<br />descr:	RIA Infosolutions Private LimitedSuite no 10, Level 5; C WingPanchshil Tech Park OneAirport Road, Yedwada103.247.148.0/24<br />ns1:	ns6.fastdcservers.net<br />ns2:	ns5.fastdcservers.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://domashnie-kinoteatry.nabook.com.ua/js/jquery.cookie.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542450</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.QO.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542450</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542450<br />first:	1354459802<br />last:	0<br />md5:	1892d1f5ac389b39ec0c17468b1518b9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1892d1f5ac389b39ec0c17468b1518b9<br />vt_score:	27/44 (61.4%)<br />scanner:	avira<br />virusname:	JS/Redirector.QO.2<br />url:	http://domashnie-kinoteatry.nabook.com.ua/js/jquery.cookie.js<br />recent:	up<br />response:	alive<br />ip:	77.88.208.131<br />as:	AS21011<br />review:	77.88.208.131<br />domain:	nabook.com.ua<br />country:	UA<br />source:	RIPE<br />email:	abuse@top.net.ua<br />inetnum:	77.88.192.0 - 77.88.255.255<br />netname:	UA-TOPNET-20070321<br />descr:	"TOP NET" PJSC<br />ns1:	ns2.imena.com.ua<br />ns2:	ns3.imena.com.ua<br />ns3:	ns1.imena.com.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bber.info/wp-content/uploads/2008/08/it_policy.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542443</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.184062]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542443</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542443<br />first:	1354459802<br />last:	0<br />md5:	470b78b665975f07fbef0dd5945777d2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=470b78b665975f07fbef0dd5945777d2<br />vt_score:	15/41 (36.6%)<br />scanner:	avira<br />virusname:	TR/Agent.184062<br />url:	http://bber.info/wp-content/uploads/2008/08/it_policy.rar<br />recent:	up<br />response:	alive<br />ip:	180.86.72.161<br />as:	AS4808<br />review:	180.86.72.161<br />domain:	bber.info<br />country:	CN<br />source:	APNIC<br />email:	donglin@xrnet.cn<br />inetnum:	180.86.0.0 - 180.86.255.255<br />netname:	XRNET<br />descr:	Beijing XiRang Media Cultural Co., Ltd.Build A6-1702,Fenghuahaojing,No.6 Guanganmennei RoadXuanwu, Beijing, China, 100053<br />ns1:	f1g1ns1.dnspod.net<br />ns2:	f1g1ns2.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://artegrafica.ind.br/js/tiracontrole.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542442</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542442</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542442<br />first:	1354459802<br />last:	0<br />md5:	0f7eb832fb12c889b3a9265e0534c3ae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0f7eb832fb12c889b3a9265e0534c3ae<br />vt_score:	28/43 (65.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://artegrafica.ind.br/js/tiracontrole.js<br />recent:	up<br />response:	alive<br />ip:	189.113.5.67<br />as:	AS28209<br />review:	189.113.5.67<br />domain:	ind.br<br />country:	BR<br />source:	LACNIC<br />email:	desenvolve@gmail.com<br />inetnum:	189.113.0.0 - 189.113.15.255<br />netname:	005.501.732/0001-89<br />descr:	Desenvolve Solucoes de Internet Ltda<br />ns1:	a.dns.br<br />ns2:	b.dns.br<br />ns3:	c.dns.br<br />ns4:	d.dns.br<br />ns5:	e.dns.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aquapuremultiservicios.es/01_menu/aquapure_menu.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542439</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542439</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542439<br />first:	1354459802<br />last:	0<br />md5:	f100d97c6d28f615af790624576eeb83<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f100d97c6d28f615af790624576eeb83<br />vt_score:	9/44 (20.5%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-inf<br />url:	http://aquapuremultiservicios.es/01_menu/aquapure_menu.html<br />recent:	up<br />response:	alive<br />ip:	85.238.8.132<br />as:	AS41721<br />review:	85.238.8.132<br />domain:	aquapuremultiservicios.es<br />country:	es<br />source:	RIPE<br />email:	ripe@cartagon.com<br />inetnum:	85.238.8.0  -  85.238.8.255<br />netname:	CartagonNET<br />descr:	CARTAGON 85.238.8.0/24Cartagon, S.L.Cartagon, S.L.<br />ns1:	ns2.evs7.net<br />ns2:	ns1.evs7.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aaadelhi.org/css.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542436</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ER.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542436</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542436<br />first:	1354459802<br />last:	0<br />md5:	4c3e6703feb35a90435f9e4a465fb448<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.ER.1<br />url:	http://aaadelhi.org/css.js<br />recent:	up<br />response:	alive<br />ip:	97.74.144.146<br />as:	AS26496<br />review:	97.74.144.146<br />domain:	aaadelhi.org<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns51.domaincontrol.com<br />ns2:	ns52.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://6.duote.com.cn/qqqunfa.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542435</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542435</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542435<br />first:	1354459802<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://6.duote.com.cn/qqqunfa.zip<br />recent:	up<br />response:	alive<br />ip:	218.75.155.216<br />as:	AS4134<br />review:	218.75.155.240<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	218.75.128.0 - 218.75.159.255<br />netname:	CHINANET-HN-CD<br />descr:	CHINANET-HN changde node networkhunan Telecom<br />ns1:	dns1.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://5.duote.com.cn/fantizizhh.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542430</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542430</guid>
			<pubDate>2012-12-02T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8542430<br />first:	1354459802<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://5.duote.com.cn/fantizizhh.zip<br />recent:	up<br />response:	alive<br />ip:	122.96.50.42<br />as:	AS4837<br />review:	61.177.91.9<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	122.96.0.0 - 122.97.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	dns1.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://28.duote.org/dashidingshidshuen.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8542428</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Hupigon-1313]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8542428</guid>
			<pubDate>2012-12-02T15:50:01+01:00</pubDate>
			<description><![CDATA[id:	8542428<br />first:	1354459801<br />last:	0<br />md5:	b7a214b429f2e8d325b7e9b3ab3b07af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beae84fce01014df2490bb72ba2e7660<br />vt_score:	7/36 (19.4%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Hupigon-1313<br />url:	http://28.duote.org/dashidingshidshuen.zip<br />recent:	up<br />response:	alive<br />ip:	221.180.22.214<br />as:	AS56042<br />review:	221.180.22.214<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	hostmaster@chinamobile.com<br />inetnum:	221.176.0.0 - 221.183.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in China<br />ns1:	dns4.50bang.org<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yvonne.pl/galeria/glowna/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8539325</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8539325</guid>
			<pubDate>2012-12-02T04:40:22+01:00</pubDate>
			<description><![CDATA[id:	8539325<br />first:	1354419622<br />last:	0<br />md5:	51498d6c1b472fe6c98fa11fb9793608<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=51498d6c1b472fe6c98fa11fb9793608<br />vt_score:	9/36 (25%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://yvonne.pl/galeria/glowna/index.html<br />recent:	up<br />response:	alive<br />ip:	178.19.104.18<br />as:	AS39869<br />review:	178.19.104.18<br />domain:	yvonne.pl<br />country:	PL<br />source:	RIPE<br />email:	tomek@sitel.net.pl<br />inetnum:	178.19.104.0 - 178.19.111.255<br />netname:	LIVENET<br />descr:	Livenet sp. z o.o.SITELLIVENET-PL<br />ns1:	dns3.slaskdatacenter.pl<br />ns2:	dns1.slaskdatacenter.pl<br />ns3:	dns2.slaskdatacenter.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://youxia.org/upload/2008/10/ms08-067.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8539324</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8539324</guid>
			<pubDate>2012-12-02T04:40:22+01:00</pubDate>
			<description><![CDATA[id:	8539324<br />first:	1354419622<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://youxia.org/upload/2008/10/ms08-067.rar<br />recent:	up<br />response:	alive<br />ip:	117.34.91.5<br />as:	AS4134<br />review:	117.34.91.13<br />domain:	youxia.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	117.32.0.0 - 117.39.255.255<br />netname:	CHINANET-SN<br />descr:	CHINANET Shanxi(SN) province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	ns2.anquanbao.com<br />ns2:	ns1.anquanbao.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wolfinternet.asia/top-webcatalog.de.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8539025</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8539025</guid>
			<pubDate>2012-12-02T03:40:32+01:00</pubDate>
			<description><![CDATA[id:	8539025<br />first:	1354416032<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://wolfinternet.asia/top-webcatalog.de.zip<br />recent:	up<br />response:	alive<br />ip:	94.102.213.184<br />as:	AS41078<br />review:	94.102.213.184<br />domain:	wolfinternet.asia<br />country:	DE<br />source:	RIPE<br />email:	abuse@antagus.de<br />inetnum:	94.102.208.0 - 94.102.215.255<br />netname:	ANTAGUS-HOUSING1-NET<br />descr:	Antagus ServerhousingAntagus GmbH<br />ns1:	ns2.antagus.de<br />ns2:	ns1.antagus.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://websfarm.org/tecnosud07/index.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538953</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/PhoexRef.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538953</guid>
			<pubDate>2012-12-02T03:31:27+01:00</pubDate>
			<description><![CDATA[id:	8538953<br />first:	1354415487<br />last:	0<br />md5:	0ea6430d76f43c44c10efc0ad0cc8147<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9c1a20da685431d383a68e302971d056<br />vt_score:	26/46 (56.5%)<br />scanner:	avira<br />virusname:	JS/PhoexRef.A<br />url:	http://websfarm.org/tecnosud07/index.asp<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.72<br />domain:	websfarm.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns3.arubadns.net<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vastera.it/rivista/42/pagine%2042/festa_medievale.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538950</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538950</guid>
			<pubDate>2012-12-02T03:31:27+01:00</pubDate>
			<description><![CDATA[id:	8538950<br />first:	1354415487<br />last:	0<br />md5:	1d41bef64992cf7c2583e9b4e7f942a9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1d41bef64992cf7c2583e9b4e7f942a9<br />vt_score:	22/44 (50%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://vastera.it/rivista/42/pagine%2042/festa_medievale.htm<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	vastera.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns.technorail.com<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ssmet.in/includes1/jquery.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538580</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.FZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538580</guid>
			<pubDate>2012-12-02T03:00:07+01:00</pubDate>
			<description><![CDATA[id:	8538580<br />first:	1354413607<br />last:	0<br />md5:	5b3e60e64dcd9c1bd4f3593750a0ba30<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5b3e60e64dcd9c1bd4f3593750a0ba30<br />vt_score:	16/42 (38.1%)<br />scanner:	avira<br />virusname:	JS/Redirector.FZ<br />url:	http://ssmet.in/includes1/jquery.min.js<br />recent:	up<br />response:	alive<br />ip:	74.39.238.76<br />as:	AS7011, AS5650, AS30064, AS26127, AS3593<br />review:	216.55.178.48<br />domain:	ssmet.in<br />country:	US<br />source:	ARIN<br />email:	abuse@frontiernet.net<br />inetnum:	74.32.0.0 - 74.47.255.255<br />netname:	FRONTIER-COMMUNICATIONS<br />descr:	Frontier Communications of America, Inc. FRTR 180 South Clinton AVE Rochester NY 14646<br />ns1:	nserver1.terrasite.com<br />ns2:	nserver2.terrasite.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://solmet-slusarstwo.jaw.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538578</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.qub]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538578</guid>
			<pubDate>2012-12-02T03:00:07+01:00</pubDate>
			<description><![CDATA[id:	8538578<br />first:	1354413607<br />last:	0<br />md5:	accfaa21fd351b9e4e90a4148f279c69<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=accfaa21fd351b9e4e90a4148f279c69<br />vt_score:	10/44 (22.7%)<br />scanner:	avira<br />virusname:	JS/Agent.qub<br />url:	http://solmet-slusarstwo.jaw.pl/<br />recent:	up<br />response:	alive<br />ip:	94.246.129.64<br />as:	AS33923<br />review:	94.246.129.64<br />domain:	jaw.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@artcom.pl<br />inetnum:	94.246.128.0 - 94.246.191.255<br />netname:	PL-ARTCOM-20081119<br />descr:	ART-COM Sp. z o.o.ART-COM Sp. z o.o. LIR<br />ns1:	ns.artcom.pl<br />ns2:	ns3.artcom.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://serciudadano.com.ar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538139</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Iframe-TR Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538139</guid>
			<pubDate>2012-12-02T01:40:05+01:00</pubDate>
			<description><![CDATA[id:	8538139<br />first:	1354408805<br />last:	0<br />md5:	9aec436aa1be95e7d1580d4cf74f4114<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9aec436aa1be95e7d1580d4cf74f4114<br />vt_score:	13/46 (28.3%)<br />scanner:	Avast<br />virusname:	JS:Iframe-TR Trj<br />url:	http://serciudadano.com.ar<br />recent:	up<br />response:	alive<br />ip:	201.216.232.12<br />as:	AS16814<br />review:	201.216.232.12<br />domain:	serciudadano.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	abuse@iplan.com.ar<br />inetnum:	201.216.224.0 - 201.216.255.255<br />netname:	AR-NSSA-LACNIC<br />descr:	NSS S.A.Reconquista, 865, 2C1003ABQ - Buenos Aires - CFReconquista, 865,1003 - Buenos Aires -<br />ns1:	dns2.grupoxmundo.com<br />ns2:	dns1.grupoxmundo.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sensix.org/templates/greenapplev2/js/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538138</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538138</guid>
			<pubDate>2012-12-02T01:40:05+01:00</pubDate>
			<description><![CDATA[id:	8538138<br />first:	1354408805<br />last:	0<br />md5:	e15609c100ef8bf39ba54e4b5d85a875<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e15609c100ef8bf39ba54e4b5d85a875<br />vt_score:	13/40 (32.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://sensix.org/templates/greenapplev2/js/jquery.js<br />recent:	up<br />response:	alive<br />ip:	213.208.132.51<br />as:	AS1764<br />review:	213.208.132.51<br />domain:	sensix.org<br />country:	AT<br />source:	RIPE<br />email:	abuse@unixsecurity.at<br />inetnum:	213.208.132.0 - 213.208.132.255<br />netname:	WEBMACHINE-NET-2<br />descr:	WebMachine Unixsecurity Network 2 VIE-IX<br />ns1:	bluemoon.webma.net<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://seekersbooks.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538136</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538136</guid>
			<pubDate>2012-12-02T01:40:05+01:00</pubDate>
			<description><![CDATA[id:	8538136<br />first:	1354408805<br />last:	0<br />md5:	5282264a9bc8cd59c58ee66140e34b7e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5282264a9bc8cd59c58ee66140e34b7e<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://seekersbooks.org/<br />recent:	up<br />response:	alive<br />ip:	174.133.19.130<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.133.19.130<br />domain:	seekersbooks.org<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.132.0.0 - 174.133.255.255<br />netname:	NETBLK-THEPLANET-BLK-15<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1.sslcatacombnetworking.com<br />ns2:	ns2.sslcatacombnetworking.com<br />ns3:	ns3.sslcatacombnetworking.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pnxx.mhedu.sh.cn/images/data/1039/meiti.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538052</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scar]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538052</guid>
			<pubDate>2012-12-02T01:00:11+01:00</pubDate>
			<description><![CDATA[id:	8538052<br />first:	1354406411<br />last:	0<br />md5:	413abef0e3f9208dd794195bc1319304<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scar<br />url:	http://pnxx.mhedu.sh.cn/images/data/1039/meiti.rar<br />recent:	up<br />response:	alive<br />ip:	202.158.162.73<br />as:	AS23850<br />review:	202.158.162.73<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@mgtd.com.cn<br />inetnum:	202.158.160.0 - 202.158.167.255<br />netname:	MGTDNET<br />descr:	MGTD Network<br />ns1:	b.dns.cn<br />ns2:	c.dns.cn<br />ns3:	d.dns.cn<br />ns4:	e.dns.cn<br />ns5:	cns.cernet.net<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://organicwine.be/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8538051</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8538051</guid>
			<pubDate>2012-12-02T01:00:11+01:00</pubDate>
			<description><![CDATA[id:	8538051<br />first:	1354406411<br />last:	0<br />md5:	aa397c6c7e20aebb3743c1785472f1ae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aa397c6c7e20aebb3743c1785472f1ae<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.axm<br />url:	http://organicwine.be/<br />recent:	up<br />response:	alive<br />ip:	193.219.98.33<br />as:	AS41604<br />review:	193.219.98.33<br />domain:	organicwine.be<br />country:	BE<br />source:	RIPE<br />email:	info@tsc.be<br />inetnum:	193.219.98.0 - 193.219.98.255<br />netname:	TSC-TINET<br />descr:	TSC Communication GroupTSC<br />ns1:	ns2.tophosting.be<br />ns2:	ns1.tophosting.be<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mindpark.com.tr/gnc.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537994</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537994</guid>
			<pubDate>2012-12-02T00:08:35+01:00</pubDate>
			<description><![CDATA[id:	8537994<br />first:	1354403315<br />last:	0<br />md5:	fbc695920d2d760a11a6f35cb2b068cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fbc695920d2d760a11a6f35cb2b068cc<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://mindpark.com.tr/gnc.htm<br />recent:	up<br />response:	alive<br />ip:	72.29.75.207<br />as:	AS33182<br />review:	72.29.75.207<br />domain:	mindpark.com.tr<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns101.dizinc.com<br />ns2:	ns100.dizinc.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://loetfreund.de/assets/rollover.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537986</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.cqi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537986</guid>
			<pubDate>2012-12-02T00:08:34+01:00</pubDate>
			<description><![CDATA[id:	8537986<br />first:	1354403314<br />last:	0<br />md5:	525badb8a62d375e3be77073d1100df1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=525badb8a62d375e3be77073d1100df1<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.cqi<br />url:	http://loetfreund.de/assets/rollover.js<br />recent:	up<br />response:	alive<br />ip:	82.165.75.120<br />as:	AS8560<br />review:	82.165.75.120<br />domain:	loetfreund.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns26.schlund.de<br />ns2:	ns25.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=qbasic&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537985</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537985</guid>
			<pubDate>2012-12-02T00:08:34+01:00</pubDate>
			<description><![CDATA[id:	8537985<br />first:	1354403314<br />last:	0<br />md5:	bb267644d4286be05883b8beefb07303<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb267644d4286be05883b8beefb07303<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=qbasic&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3dmandi]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537984</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADWARE/Adware.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537984</guid>
			<pubDate>2012-12-02T00:08:34+01:00</pubDate>
			<description><![CDATA[id:	8537984<br />first:	1354403314<br />last:	0<br />md5:	b9637ad63bf436f04cd68d6e73c8b927<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b9637ad63bf436f04cd68d6e73c8b927<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	ADWARE/Adware.Gen<br />url:	http://ld.download-guru.com?s=3dmandi<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld2.download-guru.com?s=3d3d3dthevoye]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537983</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADWARE/Adware.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537983</guid>
			<pubDate>2012-12-02T00:08:33+01:00</pubDate>
			<description><![CDATA[id:	8537983<br />first:	1354403313<br />last:	0<br />md5:	6e1b39f0a486bdaee77d67bc6033fce5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6e1b39f0a486bdaee77d67bc6033fce5<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	ADWARE/Adware.Gen<br />url:	http://ld2.download-guru.com?s=3d3d3dthevoye<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p674p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537508</guid>
			<pubDate>2012-12-01T21:30:02+01:00</pubDate>
			<description><![CDATA[id:	8537508<br />first:	1354393802<br />last:	0<br />md5:	2fb04d2c53f04ca7eb12a4e0b9ccc8c2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2fb04d2c53f04ca7eb12a4e0b9ccc8c2<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p674p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p589p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537507</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537507</guid>
			<pubDate>2012-12-01T21:30:02+01:00</pubDate>
			<description><![CDATA[id:	8537507<br />first:	1354393802<br />last:	0<br />md5:	75518274a495be417dc47fb11c8c5b8f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=75518274a495be417dc47fb11c8c5b8f<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p589p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p444p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537506</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537506</guid>
			<pubDate>2012-12-01T21:30:02+01:00</pubDate>
			<description><![CDATA[id:	8537506<br />first:	1354393802<br />last:	0<br />md5:	de5bcc7add8cbebe69fd937fd136ec4b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=de5bcc7add8cbebe69fd937fd136ec4b<br />vt_score:	24/31 (77.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p444p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://instituutkuyper.nl/heftruckopleiding.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537309</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537309</guid>
			<pubDate>2012-12-01T21:10:18+01:00</pubDate>
			<description><![CDATA[id:	8537309<br />first:	1354392618<br />last:	0<br />md5:	8350f1e543fa9f04e4869a77817e161c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8350f1e543fa9f04e4869a77817e161c<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://instituutkuyper.nl/heftruckopleiding.htm<br />recent:	up<br />response:	alive<br />ip:	213.188.129.112<br />as:	AS12994<br />review:	213.188.129.112<br />domain:	instituutkuyper.nl<br />country:	NO<br />source:	RIPE<br />email:	abuse@mamutactive24.com<br />inetnum:	213.188.128.0 - 213.188.134.255<br />netname:	COM-ACTIVEISP<br />descr:	Active 24 ASA. Region Norway<br />ns1:	dns12.activeisp.com<br />ns2:	dns10.activeisp.com<br />ns3:	dns11.activeisp.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://heritageresorts.es/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8537286</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.VU.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8537286</guid>
			<pubDate>2012-12-01T20:50:02+01:00</pubDate>
			<description><![CDATA[id:	8537286<br />first:	1354391402<br />last:	0<br />md5:	e09b27632ceda6d305034d1706fa50bd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e09b27632ceda6d305034d1706fa50bd<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/Expack.VU.1<br />url:	http://heritageresorts.es/<br />recent:	up<br />response:	alive<br />ip:	80.91.80.9<br />as:	AS174<br />review:	80.91.80.9<br />domain:	heritageresorts.es<br />country:	ES<br />source:	RIPE<br />email:	abuse@cogentco.com<br />inetnum:	80.91.80.0 - 80.91.83.255<br />netname:	CARRIER_ENABLER-COGENT<br />descr:	Carrier EnablerCogent Communications Espana, S.A.<br />ns1:	ns.heritageresorts.es<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fahrschulefriedel.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8536280</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8536280</guid>
			<pubDate>2012-12-01T20:30:04+01:00</pubDate>
			<description><![CDATA[id:	8536280<br />first:	1354390204<br />last:	0<br />md5:	5b8dc116a75b4da7f94f0103a32f5ca1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=46cfd6a2e857181e040f7bc49ef5149e<br />vt_score:	28/44 (63.6%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://fahrschulefriedel.de/<br />recent:	up<br />response:	alive<br />ip:	85.88.7.3<br />as:	AS33984<br />review:	85.88.7.3<br />domain:	fahrschulefriedel.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@united-hoster.com<br />inetnum:	85.88.7.0 - 85.88.7.255<br />netname:	UNITEDHOSTER_CGN_NET<br />descr:	WEB/Mail/DB-Servers<br />ns1:	ns2.provider-dns3.de<br />ns2:	ns1.provider-dns3.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cheapweb.com.au/common.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8536022</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Infected.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8536022</guid>
			<pubDate>2012-12-01T17:50:03+01:00</pubDate>
			<description><![CDATA[id:	8536022<br />first:	1354380603<br />last:	0<br />md5:	c1bcaad9124484fa083dd0bd1a3fc394<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c1bcaad9124484fa083dd0bd1a3fc394<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	JS/Infected.B<br />url:	http://cheapweb.com.au/common.js<br />recent:	up<br />response:	alive<br />ip:	66.40.52.74<br />as:	AS11388<br />review:	198.23.57.65<br />domain:	cheapweb.com.au<br />country:	US<br />source:	ARIN<br />email:	abuse@propersupport.com<br />inetnum:	66.40.0.0 - 66.40.255.255<br />netname:	LIQUIDNET-HOSTING<br />descr:	LiquidNet US LLC LUL-5 1500 University Drive Coral Springs FL 33071<br />ns1:	dns2.freehostia.com<br />ns2:	dns1.freehostia.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://canexpol.waw.pl/RUS/desire-pheromone.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535843</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.csf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535843</guid>
			<pubDate>2012-12-01T17:20:02+01:00</pubDate>
			<description><![CDATA[id:	8535843<br />first:	1354378802<br />last:	0<br />md5:	4e2f6884de0d11ddb1a6ae9230082ccb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4e2f6884de0d11ddb1a6ae9230082ccb<br />vt_score:	18/45 (40%)<br />scanner:	avira<br />virusname:	JS/iFrame.csf<br />url:	http://canexpol.waw.pl/RUS/desire-pheromone.html<br />recent:	up<br />response:	alive<br />ip:	79.96.83.230<br />as:	AS12824<br />review:	79.96.83.230<br />domain:	waw.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	a-dns.pl<br />ns2:	e-dns.pl<br />ns3:	f-dns.pl<br />ns4:	h-dns.pl<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://brabantvoorbrabant.nl/Scripts/AC_RunActiveContent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535837</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.P]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535837</guid>
			<pubDate>2012-12-01T17:20:02+01:00</pubDate>
			<description><![CDATA[id:	8535837<br />first:	1354378802<br />last:	0<br />md5:	febbc94b4403a64f0d5b7c246a9bc5f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=febbc94b4403a64f0d5b7c246a9bc5f2<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	JS/Blacole.P<br />url:	http://brabantvoorbrabant.nl/Scripts/AC_RunActiveContent.js<br />recent:	up<br />response:	alive<br />ip:	46.235.44.98<br />as:	AS34233<br />review:	46.235.44.98<br />domain:	brabantvoorbrabant.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@webreus.nl<br />inetnum:	46.235.43.0 - 46.235.47.255<br />netname:	WEBREUS<br />descr:	WebReus WebhostingWebReus @ Superior<br />ns1:	ns1.webreus.nl<br />ns2:	ns3.webreus.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bansheebikes.cz/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535789</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.brb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535789</guid>
			<pubDate>2012-12-01T16:30:03+01:00</pubDate>
			<description><![CDATA[id:	8535789<br />first:	1354375803<br />last:	0<br />md5:	a3a5c1940bfd5c9156e6fd54c0d31382<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a3a5c1940bfd5c9156e6fd54c0d31382<br />vt_score:	19/44 (43.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.brb<br />url:	http://bansheebikes.cz/<br />recent:	up<br />response:	alive<br />ip:	81.2.194.166<br />as:	AS24806<br />review:	81.2.194.166<br />domain:	bansheebikes.cz<br />country:	CZ<br />source:	RIPE<br />email:	abuse@forpsi.com<br />inetnum:	81.2.194.0 - 81.2.195.255<br />netname:	CZ-INTERNET<br />descr:	webhosting servicesFORPSI www.forpsi.comFORSI www.forpsi.skFORPSI www.forpsi.plFORPSI www.forpsi.hu<br />ns1:	ns.forpsi.net<br />ns2:	ns.forpsi.it<br />ns3:	ns.forpsi.cz<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ayayes.com.tr/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535765</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.DC.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535765</guid>
			<pubDate>2012-12-01T16:20:03+01:00</pubDate>
			<description><![CDATA[id:	8535765<br />first:	1354375203<br />last:	0<br />md5:	d40dbc0e5a9e2acf9697869ffb2ccf48<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d40dbc0e5a9e2acf9697869ffb2ccf48<br />vt_score:	27/43 (62.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.DC.2<br />url:	http://ayayes.com.tr/<br />recent:	up<br />response:	alive<br />ip:	84.51.37.36<br />as:	AS34104<br />review:	84.51.37.36<br />domain:	ayayes.com.tr<br />country:	TR<br />source:	RIPE<br />email:	destek@markum.net<br />inetnum:	84.51.37.0 - 84.51.37.255<br />netname:	MARKUM_BILISIM<br />descr:	Markum Bilisim Teknolojileri Tic.Ltd.Sti.Global Iletisim Hizmetleri A.S.<br />ns1:	dns1.markum.net<br />ns2:	dns2.markum.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://attitude-incorporated-ltd.co.uk/label_copy_ups.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535764</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Kuluoz.B.48]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535764</guid>
			<pubDate>2012-12-01T16:20:03+01:00</pubDate>
			<description><![CDATA[id:	8535764<br />first:	1354375203<br />last:	0<br />md5:	c8f4a34b5516e78fb3e19aef21b821a5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c8f4a34b5516e78fb3e19aef21b821a5<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Kuluoz.B.48<br />url:	http://attitude-incorporated-ltd.co.uk/label_copy_ups.zip<br />recent:	up<br />response:	alive<br />ip:	82.165.79.35<br />as:	AS8560<br />review:	82.165.79.35<br />domain:	attitude-incorporated-ltd.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns68.1and1.co.uk<br />ns2:	ns67.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://anjabien.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535651</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535651</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535651<br />first:	1354373402<br />last:	0<br />md5:	9e7b2cd25fefb5b15d05d228154dc1cf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9e7b2cd25fefb5b15d05d228154dc1cf<br />vt_score:	27/44 (61.4%)<br />scanner:	avira<br />virusname:	JS/Twetti.E<br />url:	http://anjabien.de/<br />recent:	up<br />response:	alive<br />ip:	95.129.51.174<br />as:	AS48823<br />review:	95.129.51.174<br />domain:	anjabien.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@twooit.de<br />inetnum:	95.129.48.0 - 95.129.51.255<br />netname:	TWOOIT-GMBH<br />descr:	Network for TwooIT GmbH<br />ns1:	trinity.twooit.com<br />ns2:	sparks.twooit.com<br />ns3:	tank.twooit.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://americashottestfranchises.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535648</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.HC.23]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535648</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535648<br />first:	1354373402<br />last:	0<br />md5:	e6b479c84ed9a7d4f033f99295d20f1f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e6b479c84ed9a7d4f033f99295d20f1f<br />vt_score:	26/43 (60.5%)<br />scanner:	avira<br />virusname:	JS/Redirector.HC.23<br />url:	http://americashottestfranchises.org/<br />recent:	up<br />response:	alive<br />ip:	68.178.254.3<br />as:	AS26496<br />review:	68.178.254.3<br />domain:	americashottestfranchises.org<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	68.178.128.0 - 68.178.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns05.domaincontrol.com<br />ns2:	ns06.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://alborde.com.ar/escalada1/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535647</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535647</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535647<br />first:	1354373402<br />last:	0<br />md5:	9528ad7b8cc6df9c117b8aac9dd22030<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9528ad7b8cc6df9c117b8aac9dd22030<br />vt_score:	17/43 (39.5%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://alborde.com.ar/escalada1/index.htm<br />recent:	up<br />response:	alive<br />ip:	200.69.135.247<br />as:	AS11664<br />review:	200.69.135.247<br />domain:	alborde.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	netmaster-ar@telmex.com<br />inetnum:	200.69.128.0 - 200.69.159.255<br />netname:	AR-TLCI-LACNIC<br />descr:	Techtel LMDS Comunicaciones Interactivas S.A.Garay, 34,C1063AB - Buenos Aires -Av. Juan de Garay, 34,C1063ABN - Buenos Aires -<br />ns1:	dns1.ipaddress.com.ar<br />ns2:	dns2.ipaddress.com.ar<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aegisedu.org/aec/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535642</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535642</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535642<br />first:	1354373402<br />last:	0<br />md5:	aa07f8b9edd9ddac2fb0405e06590657<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aa07f8b9edd9ddac2fb0405e06590657<br />vt_score:	27/42 (64.3%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://aegisedu.org/aec/index.html<br />recent:	up<br />response:	alive<br />ip:	174.133.199.203<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.133.199.203<br />domain:	aegisedu.org<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.132.0.0 - 174.133.255.255<br />netname:	NETBLK-THEPLANET-BLK-15<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1.egiwebhost.com<br />ns2:	ns1.egiprimus.com<br />ns3:	ns2.egiprimus.com<br />ns4:	ns2.egiwebhost.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ae6rs.org/hacked_page]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535641</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Badscr.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535641</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535641<br />first:	1354373402<br />last:	0<br />md5:	7fd260931f2e23ed6b80bd1a1d67cfb2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7fd260931f2e23ed6b80bd1a1d67cfb2<br />vt_score:	11/43 (25.6%)<br />scanner:	avira<br />virusname:	JS/Badscr.A<br />url:	http://ae6rs.org/hacked_page<br />recent:	up<br />response:	alive<br />ip:	205.134.240.228<br />as:	AS17139<br />review:	205.134.240.228<br />domain:	ae6rs.org<br />country:	US<br />source:	ARIN<br />email:	abuse@corporatecolo.com<br />inetnum:	205.134.240.128 - 205.134.240.255<br />netname:	CORPCOLO-NET-205-134-240-128-25<br />descr:	2211 Corinth Ave Suite 100 Santa Monica CA 90064<br />ns1:	ns2.inmotionhosting.com<br />ns2:	ns.inmotionhosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://9.duote.org/vlyuvlss.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535635</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Graybird.A.1766]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535635</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535635<br />first:	1354373402<br />last:	0<br />md5:	6f499a7c107a6b7fc6fd6697a4e5006c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=286cd8cbaef7fad6dad391127010840e<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	BDS/Graybird.A.1766<br />url:	http://9.duote.org/vlyuvlss.zip<br />recent:	up<br />response:	alive<br />ip:	218.75.159.164<br />as:	AS4134<br />review:	218.75.155.245<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	218.75.128.0 - 218.75.159.255<br />netname:	CHINANET-HN-CD<br />descr:	CHINANET-HN changde node networkhunan Telecom<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://96.9.11.199/Postal-Receipt.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535634</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Kuluoz.B.17]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535634</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535634<br />first:	1354373402<br />last:	0<br />md5:	bb27486ecc230fe1c44054745e2af2b1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb27486ecc230fe1c44054745e2af2b1<br />vt_score:	25/46 (54.3%)<br />scanner:	avira<br />virusname:	TR/Dldr.Kuluoz.B.17<br />url:	http://96.9.11.199/Postal-Receipt.zip<br />recent:	up<br />response:	alive<br />ip:	96.9.11.199<br />as:	AS13910<br />review:	96.9.11.199<br />domain:	96.9.11.199<br />country:	US<br />source:	ARIN<br />email:	support@register.com<br />inetnum:	96.9.0.0 - 96.9.63.255<br />netname:	RCOM-3BLK<br />descr:	Register.com, Inc REG 575 8th Avenue New York NY 10018<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://71.duote.org/vpsetup.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535630</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.648961]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535630</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535630<br />first:	1354373402<br />last:	0<br />md5:	3af50856d2c1cd5b91c8eb131b5fd334<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3af50856d2c1cd5b91c8eb131b5fd334<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	TR/Agent.648961<br />url:	http://71.duote.org/vpsetup.zip<br />recent:	up<br />response:	alive<br />ip:	60.191.223.3<br />as:	AS4134<br />review:	60.191.223.3<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@mail.jhptt.zj.cn<br />inetnum:	60.191.223.0 - 60.191.223.255<br />netname:	JINHUA-TELECOM-LTD<br />descr:	Jinhua Telecom Co.,ltd IDC Center<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://69.duote.com.cn/qqhj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535629</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent2.ddok]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535629</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535629<br />first:	1354373402<br />last:	0<br />md5:	a7b677734d2073ad9afdd49d15daf04c<br />virustotal:	<br />vt_score:	21/43 (48.8%)<br />scanner:	avira<br />virusname:	TR/Agent2.ddok<br />url:	http://69.duote.com.cn/qqhj.zip<br />recent:	up<br />response:	alive<br />ip:	61.164.109.138<br />as:	AS4134<br />review:	61.164.109.138<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@wz.zj.cn<br />inetnum:	61.164.108.0 - 61.164.111.255<br />netname:	RUIAN-TELECOM<br />descr:	Ruian Telecom<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://68.duote.com.cn/qq2011xipcj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535628</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.7533185]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535628</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535628<br />first:	1354373402<br />last:	0<br />md5:	b6c3c1505f5f01469fdf0cb16136f900<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b6c3c1505f5f01469fdf0cb16136f900<br />vt_score:	16/35 (45.7%)<br />scanner:	avira<br />virusname:	TR/Rogue.7533185<br />url:	http://68.duote.com.cn/qq2011xipcj.zip<br />recent:	up<br />response:	alive<br />ip:	61.164.109.226<br />as:	AS4134<br />review:	61.164.109.226<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti_spam@wz.zj.cn<br />inetnum:	61.164.108.0 - 61.164.111.255<br />netname:	RUIAN-TELECOM<br />descr:	Ruian Telecom<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://66.duote.com.cn/qqxiucxq.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535626</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dynamer.dtc.8134]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535626</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535626<br />first:	1354373402<br />last:	0<br />md5:	6c948e533caa4c28596696b79adc1950<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6c948e533caa4c28596696b79adc1950<br />vt_score:	14/23 (60.9%)<br />scanner:	avira<br />virusname:	TR/Dynamer.dtc.8134<br />url:	http://66.duote.com.cn/qqxiucxq.zip<br />recent:	up<br />response:	alive<br />ip:	60.191.150.43<br />as:	AS4134<br />review:	60.191.150.43<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	antispam@dcb.hz.zj.cn<br />inetnum:	60.176.0.0 - 60.191.255.255<br />netname:	CHINANET-ZJ-HZ<br />descr:	CHINANET-ZJ Hangzhou node networkZhejiang Telecom<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://5.duote.com.cn/mfqmsjrj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535624</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UnclassifiedMalware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535624</guid>
			<pubDate>2012-12-01T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535624<br />first:	1354373402<br />last:	0<br />md5:	3cf91cff19c241cecafcc391f572bb2c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3cf91cff19c241cecafcc391f572bb2c<br />vt_score:	2/46 (4.3%)<br />scanner:	Comodo<br />virusname:	UnclassifiedMalware<br />url:	http://5.duote.com.cn/mfqmsjrj.zip<br />recent:	up<br />response:	alive<br />ip:	122.96.50.42<br />as:	AS4837<br />review:	61.177.91.9<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	122.96.0.0 - 122.97.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088CHINANET jiangsu province network<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://51zjjj.com.cn/qspace/hompy_index_main.asp?username=]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535305</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.abx.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535305</guid>
			<pubDate>2012-12-01T14:00:04+01:00</pubDate>
			<description><![CDATA[id:	8535305<br />first:	1354366804<br />last:	0<br />md5:	70686c3449d2a3fa9c3ad91509398b77<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=70686c3449d2a3fa9c3ad91509398b77<br />vt_score:	9/39 (23.1%)<br />scanner:	avira<br />virusname:	JS/Redirector.abx.1<br />url:	http://51zjjj.com.cn/qspace/hompy_index_main.asp?username=<br />recent:	up<br />response:	alive<br />ip:	210.83.81.99<br />as:	AS9929<br />review:	210.83.81.99<br />domain:	51zjjj.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	210.82.0.0 - 210.83.255.255<br />netname:	UNICOM-CN<br />descr:	China Unicom IP networkChina UnicomChina Unicom CncNet<br />ns1:	dns17.hichina.com<br />ns2:	dns18.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://51.duote.org/passview.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535304</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535304</guid>
			<pubDate>2012-12-01T14:00:04+01:00</pubDate>
			<description><![CDATA[id:	8535304<br />first:	1354366804<br />last:	0<br />md5:	1cd96f7bf00522d7896e663f5dec7bc3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1cd96f7bf00522d7896e663f5dec7bc3<br />vt_score:	28/46 (60.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Gen<br />url:	http://51.duote.org/passview.zip<br />recent:	up<br />response:	alive<br />ip:	218.75.159.5<br />as:	AS4134<br />review:	218.75.155.253<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	218.75.128.0 - 218.75.159.255<br />netname:	CHINANET-HN-CD<br />descr:	CHINANET-HN changde node networkhunan Telecom<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://45.duote.org/dashidingshidshuen.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535299</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Hupigon-1313]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535299</guid>
			<pubDate>2012-12-01T14:00:04+01:00</pubDate>
			<description><![CDATA[id:	8535299<br />first:	1354366804<br />last:	0<br />md5:	b7a214b429f2e8d325b7e9b3ab3b07af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beae84fce01014df2490bb72ba2e7660<br />vt_score:	7/36 (19.4%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Hupigon-1313<br />url:	http://45.duote.org/dashidingshidshuen.zip<br />recent:	up<br />response:	alive<br />ip:	221.180.22.252<br />as:	AS56042<br />review:	221.180.22.252<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	hostmaster@chinamobile.com<br />inetnum:	221.176.0.0 - 221.183.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in China<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://36.duote.org/driver/sjusbwnqd.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535296</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.798720.19]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535296</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535296<br />first:	1354366202<br />last:	0<br />md5:	69472a70faa634d6fac995ff269e424c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=69472a70faa634d6fac995ff269e424c<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	TR/Agent.798720.19<br />url:	http://36.duote.org/driver/sjusbwnqd.zip<br />recent:	up<br />response:	alive<br />ip:	58.215.240.102<br />as:	AS4134<br />review:	58.215.240.102<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	ip@jsinfo.net<br />inetnum:	58.208.0.0 - 58.223.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://35.duote.com.cn/qqzrszzgj.zip?qqdrsign=02052]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535295</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Backdoor/Win32.BlackHole]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535295</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535295<br />first:	1354366202<br />last:	0<br />md5:	358b7778ece60ddf85699922b36798f6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=358b7778ece60ddf85699922b36798f6<br />vt_score:	28/36 (77.8%)<br />scanner:	AhnLab_V3<br />virusname:	Backdoor/Win32.BlackHole<br />url:	http://35.duote.com.cn/qqzrszzgj.zip?qqdrsign=02052<br />recent:	up<br />response:	alive<br />ip:	222.135.144.12<br />as:	AS4837<br />review:	222.135.144.12<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	222.132.0.0 - 222.135.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns4.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://31.duote.com.cn/qqltjlq.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535293</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.QQLogger.ljn]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535293</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535293<br />first:	1354366202<br />last:	0<br />md5:	0b5e66488d6f5d01ee9e3f45c0e5e768<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0b5e66488d6f5d01ee9e3f45c0e5e768<br />vt_score:	24/40 (60%)<br />scanner:	avira<br />virusname:	TR/Spy.QQLogger.ljn<br />url:	http://31.duote.com.cn/qqltjlq.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.52<br />as:	AS4837<br />review:	60.209.5.52<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://29.duote.org/autoclose.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535292</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/win32.agent.gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535292</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535292<br />first:	1354366202<br />last:	0<br />md5:	e500a0b73b1d83fcd76167798153fe01<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e500a0b73b1d83fcd76167798153fe01<br />vt_score:	14/36 (38.9%)<br />scanner:	Antiy_AVL<br />virusname:	Trojan/win32.agent.gen<br />url:	http://29.duote.org/autoclose.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.48<br />as:	AS4837<br />review:	60.209.5.48<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://27.duote.org:8080/driver/soundsetup.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535291</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535291</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535291<br />first:	1354366202<br />last:	0<br />md5:	4c9d3d914f2b6e5fbc1680110fc8e937<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://27.duote.org:8080/driver/soundsetup.zip<br />recent:	up<br />response:	alive<br />ip:	218.57.11.39<br />as:	AS4837<br />review:	218.57.11.39<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	218.56.0.0 - 218.59.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://25.duote.com.cn/txwbstz.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535290</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Spyware-gen [Spy]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535290</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535290<br />first:	1354366202<br />last:	0<br />md5:	4e2158cecdf80bc82198bbd870be3016<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4e2158cecdf80bc82198bbd870be3016<br />vt_score:	14/35 (40%)<br />scanner:	Avast<br />virusname:	Win32:Spyware-gen [Spy]<br />url:	http://25.duote.com.cn/txwbstz.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.195<br />as:	AS4837<br />review:	60.209.5.195<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://25.duote.com.cn/qqltjlq.zip?qqdrsign=09433]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535289</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.QQLogger.ljn]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535289</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535289<br />first:	1354366202<br />last:	0<br />md5:	0b5e66488d6f5d01ee9e3f45c0e5e768<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0b5e66488d6f5d01ee9e3f45c0e5e768<br />vt_score:	24/40 (60%)<br />scanner:	avira<br />virusname:	TR/Spy.QQLogger.ljn<br />url:	http://25.duote.com.cn/qqltjlq.zip?qqdrsign=09433<br />recent:	up<br />response:	alive<br />ip:	60.209.5.195<br />as:	AS4837<br />review:	60.209.5.195<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://25.duote.com.cn/qqlsbldq.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535288</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Drop.Binder.ggv]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535288</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535288<br />first:	1354366202<br />last:	0<br />md5:	8b7110fb3ba78f68d550e15b52a5b06b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8b7110fb3ba78f68d550e15b52a5b06b<br />vt_score:	18/46 (39.1%)<br />scanner:	avira<br />virusname:	TR/Drop.Binder.ggv<br />url:	http://25.duote.com.cn/qqlsbldq.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.195<br />as:	AS4837<br />review:	60.209.5.195<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://21.duote.org:8080/wyfzqnzj.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535287</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Agent.aaq.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535287</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535287<br />first:	1354366202<br />last:	0<br />md5:	f7f81bc9a8b5fc7c79f3934a6da74a7f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f7f81bc9a8b5fc7c79f3934a6da74a7f<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.Agent.aaq.3<br />url:	http://21.duote.org:8080/wyfzqnzj.zip<br />recent:	up<br />response:	alive<br />ip:	111.74.238.216<br />as:	AS4134<br />review:	111.74.238.216<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	111.72.0.0 - 111.79.255.255<br />netname:	CHINANET-JX<br />descr:	CHINANET JIANGXI PROVINCE NETWORKChina TelecomNo.31,jingrong streetBeijing 100032<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://20.duote.org/vlyuvlss.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535285</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Graybird.A.1766]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535285</guid>
			<pubDate>2012-12-01T13:50:02+01:00</pubDate>
			<description><![CDATA[id:	8535285<br />first:	1354366202<br />last:	0<br />md5:	6f499a7c107a6b7fc6fd6697a4e5006c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=286cd8cbaef7fad6dad391127010840e<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	BDS/Graybird.A.1766<br />url:	http://20.duote.org/vlyuvlss.zip<br />recent:	up<br />response:	alive<br />ip:	60.209.5.201<br />as:	AS4837<br />review:	60.209.5.201<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.208.0.0 - 60.217.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://16.duote.org/vlyuvlss.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535244</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Graybird.A.1766]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535244</guid>
			<pubDate>2012-12-01T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8535244<br />first:	1354365002<br />last:	0<br />md5:	6f499a7c107a6b7fc6fd6697a4e5006c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=286cd8cbaef7fad6dad391127010840e<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	BDS/Graybird.A.1766<br />url:	http://16.duote.org/vlyuvlss.zip<br />recent:	up<br />response:	alive<br />ip:	123.131.165.206<br />as:	AS4837<br />review:	218.59.175.51<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	123.128.0.0 - 123.135.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns3.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://13.duote.com.cn/tjqqgamedk.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535243</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.217092.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535243</guid>
			<pubDate>2012-12-01T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8535243<br />first:	1354365002<br />last:	0<br />md5:	75d5f25e9ed2f7314f3c65b5d5fe15fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=75d5f25e9ed2f7314f3c65b5d5fe15fa<br />vt_score:	9/46 (19.6%)<br />scanner:	avira<br />virusname:	TR/Agent.217092.1<br />url:	http://13.duote.com.cn/tjqqgamedk.zip<br />recent:	up<br />response:	alive<br />ip:	59.51.114.238<br />as:	AS4134<br />review:	59.51.114.238<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	59.51.0.0 - 59.51.127.255<br />netname:	CHINANET-HN<br />descr:	CHINANET Hunan province networkChina TelecomNo1,jin-rong StreetBeijing 100032<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns1.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://12.duote.com.cn/qqncmcsjy.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535242</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.851968.18]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535242</guid>
			<pubDate>2012-12-01T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8535242<br />first:	1354365002<br />last:	0<br />md5:	30ce8ee4dd6669114528ca10f27a73f3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30ce8ee4dd6669114528ca10f27a73f3<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	TR/Agent.851968.18<br />url:	http://12.duote.com.cn/qqncmcsjy.zip<br />recent:	up<br />response:	alive<br />ip:	218.57.11.50<br />as:	AS4837<br />review:	218.57.11.50<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	218.56.0.0 - 218.59.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong province networkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns1.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://122.224.9.35:85/tt/4.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8535241</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8535241</guid>
			<pubDate>2012-12-01T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8535241<br />first:	1354365002<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://122.224.9.35:85/tt/4.exe<br />recent:	up<br />response:	alive<br />ip:	122.224.9.35<br />as:	AS4134<br />review:	122.224.9.35<br />domain:	122.224.9.35<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@mail.sxptt.zj.cn<br />inetnum:	122.224.9.0 - 122.224.9.255<br />netname:	NINBO-LANZHONG-LTD<br />descr:	Ninbo Lanzhong Network Ltd<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zv-vivalo.nl/schoolslag.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8532535</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8532535</guid>
			<pubDate>2012-11-30T23:50:04+01:00</pubDate>
			<description><![CDATA[id:	8532535<br />first:	1354315804<br />last:	0<br />md5:	cb86578a07d398e9d78432073bd4a041<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cb86578a07d398e9d78432073bd4a041<br />vt_score:	0/45 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.SN<br />url:	http://zv-vivalo.nl/schoolslag.htm<br />recent:	up<br />response:	alive<br />ip:	109.237.219.159<br />as:	AS38930<br />review:	109.237.219.159<br />domain:	zv-vivalo.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@mihos.net<br />inetnum:	109.237.208.0 - 109.237.219.255<br />netname:	MIHOS<br />descr:	Mihos BVrouted by Fiberring<br />ns1:	ns1.vz8.nl<br />ns2:	ns2.vz1.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery/pages/agf00062.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8532405</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8532405</guid>
			<pubDate>2012-11-30T22:20:03+01:00</pubDate>
			<description><![CDATA[id:	8532405<br />first:	1354310403<br />last:	0<br />md5:	737c986b85d58b37b0375f0ee597aad9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=737c986b85d58b37b0375f0ee597aad9<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery/pages/agf00062.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery4/pages/pict0056.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8532402</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8532402</guid>
			<pubDate>2012-11-30T22:20:03+01:00</pubDate>
			<description><![CDATA[id:	8532402<br />first:	1354310403<br />last:	0<br />md5:	81fe8bbe48af1cc9c2f82ad7345a80e8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=81fe8bbe48af1cc9c2f82ad7345a80e8<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery4/pages/pict0056.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://security-labs.org/fred/docs/hotpdfs/thoseWebFor.pdf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8532395</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8532395</guid>
			<pubDate>2012-11-30T21:50:04+01:00</pubDate>
			<description><![CDATA[id:	8532395<br />first:	1354308604<br />last:	0<br />md5:	cd304fa00ac2dc03f13fcfd514cbbfeb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://security-labs.org/fred/docs/hotpdfs/thoseWebFor.pdf<br />recent:	up<br />response:	alive<br />ip:	88.191.95.99<br />as:	AS12322<br />review:	88.191.135.117<br />domain:	security-labs.org<br />country:	FR<br />source:	RIPE<br />email:	abuse@proxad.net<br />inetnum:	88.191.3.0 - 88.191.129.255<br />netname:	FR-DEDIBOX<br />descr:	Dedibox SASCustomersParis, FranceNCC#2007023902<br />ns1:	c.dns.gandi.net<br />ns2:	ns7.zoneedit.com<br />ns3:	ns8.zoneedit.com<br />ns4:	a.dns.gandi.net<br />ns5:	b.dns.gandi.net<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jpkc.nefu.edu.cn/zwx/Get/kcdg/230833400_17.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530946</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AGZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530946</guid>
			<pubDate>2012-11-30T18:30:04+01:00</pubDate>
			<description><![CDATA[id:	8530946<br />first:	1354296604<br />last:	0<br />md5:	173ff5a7b1bc4d9e599e9751f7754eab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=173ff5a7b1bc4d9e599e9751f7754eab<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.AGZ<br />url:	http://jpkc.nefu.edu.cn/zwx/Get/kcdg/230833400_17.htm<br />recent:	up<br />response:	alive<br />ip:	202.118.223.22<br />as:	AS24564<br />review:	202.118.223.22<br />domain:	nefu.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	helpdesk@apnic.net<br />inetnum:	202.0.0.0 - 203.255.255.255<br />netname:	APNIC-AP<br />descr:	Asia Pacific Network Information CentreRegional Internet Registry for the Asia-Pacific Region6 Cordelia StreetPO Box 3646South Brisbane, QLD 4101Australia<br />ns1:	ns3.nefu.edu.cn<br />ns2:	ns1.nefu.edu.cn<br />ns3:	ns4.nefu.edu.cn<br />ns4:	ns2.nefu.edu.cn<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p749p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530945</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530945</guid>
			<pubDate>2012-11-30T18:30:04+01:00</pubDate>
			<description><![CDATA[id:	8530945<br />first:	1354296604<br />last:	0<br />md5:	0bc87dfdd6fac82e568e898cb2d306a8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0bc87dfdd6fac82e568e898cb2d306a8<br />vt_score:	25/34 (73.5%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p749p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jingjia.org/uploadfile/2012/0310/20120310022016252.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530942</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[X97M/Escop.SJ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530942</guid>
			<pubDate>2012-11-30T18:30:04+01:00</pubDate>
			<description><![CDATA[id:	8530942<br />first:	1354296604<br />last:	0<br />md5:	9f22e9fba83a1b4e269269534e2e61cf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9f22e9fba83a1b4e269269534e2e61cf<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	X97M/Escop.SJ<br />url:	http://jingjia.org/uploadfile/2012/0310/20120310022016252.rar<br />recent:	up<br />response:	alive<br />ip:	116.255.216.28<br />as:	AS4837<br />review:	116.255.224.2<br />domain:	jingjia.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	116.255.128.0 - 116.255.255.255<br />netname:	GIANT<br />descr:	ZhengZhou GIANT Computer Network Technology Co., LtdRoom 701 Information Building NO.144 Garden Road, ZhenzhouHenan, P.R.ChinaCNC Group CHINA169 Henan Province NetworkAddresses from CNNIC(GIANT)<br />ns1:	ns1.dnsv2.com<br />ns2:	ns2.dnsv2.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://homegame.org/HG/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530789</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530789</guid>
			<pubDate>2012-11-30T18:00:11+01:00</pubDate>
			<description><![CDATA[id:	8530789<br />first:	1354294811<br />last:	0<br />md5:	6e77c7076f902c837530ff376f3ed5d9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6e77c7076f902c837530ff376f3ed5d9<br />vt_score:	12/24 (50%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://homegame.org/HG/<br />recent:	up<br />response:	alive<br />ip:	69.163.166.142<br />as:	AS26347<br />review:	69.163.166.142<br />domain:	homegame.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=41]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530702</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530702</guid>
			<pubDate>2012-11-30T17:20:50+01:00</pubDate>
			<description><![CDATA[id:	8530702<br />first:	1354292450<br />last:	0<br />md5:	a27063d3c01a6447120a26e10653a538<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=202caef6985acd66dbea6c6f5cc167a8<br />vt_score:	12/35 (34.3%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=41<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	e.dns.cn<br />ns2:	cns.cernet.net<br />ns3:	a.dns.cn<br />ns4:	b.dns.cn<br />ns5:	c.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ghv-bramfeld.de/runactivecontent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530700</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530700</guid>
			<pubDate>2012-11-30T17:20:50+01:00</pubDate>
			<description><![CDATA[id:	8530700<br />first:	1354292450<br />last:	0<br />md5:	e01877c81fabe4dfd9e621fe84fa5c60<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e01877c81fabe4dfd9e621fe84fa5c60<br />vt_score:	18/45 (40%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA [Trj]<br />url:	http://ghv-bramfeld.de/runactivecontent.js<br />recent:	up<br />response:	alive<br />ip:	82.165.93.28<br />as:	AS8560<br />review:	82.165.93.28<br />domain:	ghv-bramfeld.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns13.schlund.de<br />ns2:	ns14.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://file.myfiles.com.cn/Dev/tyshjgszhgj_v30.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530696</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Induc.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530696</guid>
			<pubDate>2012-11-30T17:20:50+01:00</pubDate>
			<description><![CDATA[id:	8530696<br />first:	1354292450<br />last:	0<br />md5:	e94e65ca17f287064996002db4d33867<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e94e65ca17f287064996002db4d33867<br />vt_score:	28/33 (84.8%)<br />scanner:	avira<br />virusname:	W32/Induc.A<br />url:	http://file.myfiles.com.cn/Dev/tyshjgszhgj_v30.zip<br />recent:	up<br />response:	alive<br />ip:	122.143.8.17<br />as:	AS4837<br />review:	70.39.191.54<br />domain:	myfiles.com.cn<br />country:	US<br />source:	ARIN<br />email:	danc@inmotionhosting.com<br />inetnum:	122.136.0.0 - 122.143.255.255<br />netname:	NETBLK-MZIMA-11<br />descr:	Mzima Networks, Inc. MZIMAN-1 707 Wilshire Blvd. Suite 4737 Los Angeles CA 90017 AS25973InMotion Hosting, Inc. INMOT-1 4553 Glencoe Ave Suite 325 Marina Del Rey CA 90292 AS25973<br />ns1:	dns8.hichina.com<br />ns2:	dns7.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/home-garden/heating-cooling-air.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530596</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530596</guid>
			<pubDate>2012-11-30T16:20:03+01:00</pubDate>
			<description><![CDATA[id:	8530596<br />first:	1354288803<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://dollarauctions.ws/home-garden/heating-cooling-air.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns1.stabletransit.com<br />ns2:	dns2.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://clesaarredamenti.it/postal_receipt.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530412</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Strictor.15604]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530412</guid>
			<pubDate>2012-11-30T15:52:47+01:00</pubDate>
			<description><![CDATA[id:	8530412<br />first:	1354287167<br />last:	0<br />md5:	fd48d5f2194888661c89a4fa64f6e394<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fd48d5f2194888661c89a4fa64f6e394<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	TR/Strictor.15604<br />url:	http://clesaarredamenti.it/postal_receipt.zip<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	clesaarredamenti.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns.technorail.com<br />ns3:	dns2.technorail.com<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://68.duote.org/zhunvwo.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8530005</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8530005</guid>
			<pubDate>2012-11-30T13:50:13+01:00</pubDate>
			<description><![CDATA[id:	8530005<br />first:	1354279813<br />last:	0<br />md5:	67ef8a4cc4a592ee3e4a39b52f2ecbb2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=67ef8a4cc4a592ee3e4a39b52f2ecbb2<br />vt_score:	12/46 (26.1%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://68.duote.org/zhunvwo.zip<br />recent:	up<br />response:	alive<br />ip:	111.10.24.43<br />as:	AS9808<br />review:	111.10.24.43<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	sunjinxia@chinamobile.com<br />inetnum:	111.0.0.0 - 111.63.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in ChinaChina Mobile communications corporation<br />ns1:	dns3.50bang.org<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://47.duote.com.cn/qqhucai.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8529987</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Worm/Win32.AutoRun]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8529987</guid>
			<pubDate>2012-11-30T13:30:03+01:00</pubDate>
			<description><![CDATA[id:	8529987<br />first:	1354278603<br />last:	0<br />md5:	aa045313c52c5673f435bf0fc813d6c1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AhnLab_V3<br />virusname:	Worm/Win32.AutoRun<br />url:	http://47.duote.com.cn/qqhucai.zip<br />recent:	up<br />response:	alive<br />ip:	59.51.114.114<br />as:	AS4134<br />review:	59.51.114.114<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	59.51.0.0 - 59.51.127.255<br />netname:	CHINANET-HN<br />descr:	CHINANET Hunan province networkChina TelecomNo1,jin-rong StreetBeijing 100032<br />ns1:	dns4.50bang.org<br />ns2:	dns1.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://33.duote.org/xzczav.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8529984</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:VB-ADKJ Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8529984</guid>
			<pubDate>2012-11-30T13:30:03+01:00</pubDate>
			<description><![CDATA[id:	8529984<br />first:	1354278603<br />last:	0<br />md5:	02dabaf0d01c2be708bce97839f3b5ac<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02dabaf0d01c2be708bce97839f3b5ac<br />vt_score:	8/36 (22.2%)<br />scanner:	Avast<br />virusname:	Win32:VB-ADKJ Trj<br />url:	http://33.duote.org/xzczav.zip<br />recent:	up<br />response:	alive<br />ip:	119.184.120.44<br />as:	AS4837<br />review:	119.184.120.138<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	119.176.0.0 - 119.191.255.255<br />netname:	UNICOM-SD<br />descr:	China Unicom Shandong Province NetworkChina UnicomCNC Group CHINA169 Shandong Province Network<br />ns1:	dns2.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://21.duote.org:8080/rcbnwread.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8529981</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdv.626279]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8529981</guid>
			<pubDate>2012-11-30T13:30:03+01:00</pubDate>
			<description><![CDATA[id:	8529981<br />first:	1354278603<br />last:	0<br />md5:	94837872953de8915908945ca4b8904b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=94837872953de8915908945ca4b8904b<br />vt_score:	23/38 (60.5%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdv.626279<br />url:	http://21.duote.org:8080/rcbnwread.zip<br />recent:	up<br />response:	alive<br />ip:	111.74.238.216<br />as:	AS4134<br />review:	111.74.238.216<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	111.72.0.0 - 111.79.255.255<br />netname:	CHINANET-JX<br />descr:	CHINANET JIANGXI PROVINCE NETWORKChina TelecomNo.31,jingrong streetBeijing 100032<br />ns1:	dns2.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns4.50bang.org<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://1.duote.com.cn/renqizhushou.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8529978</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Agent.67016.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8529978</guid>
			<pubDate>2012-11-30T13:20:02+01:00</pubDate>
			<description><![CDATA[id:	8529978<br />first:	1354278002<br />last:	0<br />md5:	7bc49c70ab133d7e2f06b2866b8a8c3a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7bc49c70ab133d7e2f06b2866b8a8c3a<br />vt_score:	14/46 (30.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Agent.67016.1<br />url:	http://1.duote.com.cn/renqizhushou.zip<br />recent:	up<br />response:	alive<br />ip:	60.191.187.3<br />as:	AS4134<br />review:	122.228.248.6<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	60.191.187.0 - 60.191.187.31<br />netname:	CHINANET-ZJ<br />descr:	CHINANET Zhejiang province networkChina TelecomNo.31,jingrong streetBeijing 100032China Telecom Zhejiang Province<br />ns1:	dns4.50bang.org<br />ns2:	dns1.kabasiji.com<br />ns3:	dns3.50bang.org<br />ns4:	dns2.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://122.224.9.35:85/tt/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8529975</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8529975</guid>
			<pubDate>2012-11-30T13:20:02+01:00</pubDate>
			<description><![CDATA[id:	8529975<br />first:	1354278002<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://122.224.9.35:85/tt/1.exe<br />recent:	up<br />response:	alive<br />ip:	122.224.9.35<br />as:	AS4134<br />review:	122.224.9.35<br />domain:	122.224.9.35<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@mail.sxptt.zj.cn<br />inetnum:	122.224.9.0 - 122.224.9.255<br />netname:	NINBO-LANZHONG-LTD<br />descr:	Ninbo Lanzhong Network Ltd<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://winnerwideworld.co.th/images/2008-07-23-oxy34/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8526340</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Dldr.Agent.axc]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8526340</guid>
			<pubDate>2012-11-30T01:20:22+01:00</pubDate>
			<description><![CDATA[id:	8526340<br />first:	1354234822<br />last:	0<br />md5:	fa5da6c6107a68b08b35c3bae8d28869<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	HTML/Dldr.Agent.axc<br />url:	http://winnerwideworld.co.th/images/2008-07-23-oxy34/<br />recent:	up<br />response:	alive<br />ip:	61.19.252.138<br />as:	AS9931<br />review:	61.19.252.138<br />domain:	winnerwideworld.co.th<br />country:	TH<br />source:	APNIC<br />email:	abuse@idc.cattelecom.com<br />inetnum:	61.19.240.0 - 61.19.255.255<br />netname:	CAT-IDC-Service<br />descr:	CAT TELECOM Data Comm. Dept, IDC Office***send spam abuse to support@idc.cattelecom.com and  abuse@idc.cattelecom.com***<br />ns1:	ns1.siamhosting.com<br />ns2:	ns2.siamhosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://teelanovela.de/alte%20schule/tc/it10.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525992</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525992</guid>
			<pubDate>2012-11-30T00:40:16+01:00</pubDate>
			<description><![CDATA[id:	8525992<br />first:	1354232416<br />last:	0<br />md5:	87f3fe695f106dc048838a0365fe9da6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=87f3fe695f106dc048838a0365fe9da6<br />vt_score:	23/35 (65.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://teelanovela.de/alte%20schule/tc/it10.htm<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	teelanovela.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://teelanovela.de/alte%20schule/tc/5.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525991</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525991</guid>
			<pubDate>2012-11-30T00:40:16+01:00</pubDate>
			<description><![CDATA[id:	8525991<br />first:	1354232416<br />last:	0<br />md5:	a6f5584ca9239746e241b2c95fe38191<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a6f5584ca9239746e241b2c95fe38191<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://teelanovela.de/alte%20schule/tc/5.htm<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	teelanovela.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://szlm.hu/interaktiv/hirelevel/szsz-oktober/index_h.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525990</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-S [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525990</guid>
			<pubDate>2012-11-30T00:40:16+01:00</pubDate>
			<description><![CDATA[id:	8525990<br />first:	1354232416<br />last:	0<br />md5:	13c84b8488965f98c6d8c1b2e4d5b429<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=13c84b8488965f98c6d8c1b2e4d5b429<br />vt_score:	8/36 (22.2%)<br />scanner:	Avast<br />virusname:	JS:Illredir-S [Trj]<br />url:	http://szlm.hu/interaktiv/hirelevel/szsz-oktober/index_h.htm<br />recent:	up<br />response:	alive<br />ip:	195.70.35.14<br />as:	AS8358<br />review:	195.70.35.14<br />domain:	szlm.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@interware.hu<br />inetnum:	195.70.35.0 - 195.70.35.255<br />netname:	INTERWARE<br />descr:	InterWare Inc.IPs for Server Hosting<br />ns1:	ns.toolpontos.hu<br />ns2:	ns2.interware.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://szlm.hu/interaktiv/hirelevel/szsz-jun/index_e.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525989</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-S [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525989</guid>
			<pubDate>2012-11-30T00:40:16+01:00</pubDate>
			<description><![CDATA[id:	8525989<br />first:	1354232416<br />last:	0<br />md5:	905622dab0841269c46bb5256517c3c9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=905622dab0841269c46bb5256517c3c9<br />vt_score:	8/36 (22.2%)<br />scanner:	Avast<br />virusname:	JS:Illredir-S [Trj]<br />url:	http://szlm.hu/interaktiv/hirelevel/szsz-jun/index_e.htm<br />recent:	up<br />response:	alive<br />ip:	195.70.35.14<br />as:	AS8358<br />review:	195.70.35.14<br />domain:	szlm.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@interware.hu<br />inetnum:	195.70.35.0 - 195.70.35.255<br />netname:	INTERWARE<br />descr:	InterWare Inc.IPs for Server Hosting<br />ns1:	ns.toolpontos.hu<br />ns2:	ns2.interware.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://stadler.pl/actions.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525976</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PH.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525976</guid>
			<pubDate>2012-11-30T00:20:06+01:00</pubDate>
			<description><![CDATA[id:	8525976<br />first:	1354231206<br />last:	0<br />md5:	fa5235e8c35105642207c014279dd5b5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fa5235e8c35105642207c014279dd5b5<br />vt_score:	16/34 (47.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.PH.3<br />url:	http://stadler.pl/actions.js<br />recent:	up<br />response:	alive<br />ip:	212.85.102.151<br />as:	AS12824<br />review:	212.85.102.151<br />domain:	stadler.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.96.0 - 212.85.113.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery4/pages/pict0032.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525971</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525971</guid>
			<pubDate>2012-11-30T00:20:05+01:00</pubDate>
			<description><![CDATA[id:	8525971<br />first:	1354231205<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://siwik.pl/blaszczak2005/galery4/pages/pict0032.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sailorvgame.org/mg/hen/pl2/PL2FrontEnd_v01.4.5.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8525968</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8525968</guid>
			<pubDate>2012-11-30T00:20:05+01:00</pubDate>
			<description><![CDATA[id:	8525968<br />first:	1354231205<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://sailorvgame.org/mg/hen/pl2/PL2FrontEnd_v01.4.5.rar<br />recent:	up<br />response:	alive<br />ip:	74.220.207.119<br />as:	AS11798<br />review:	74.220.207.119<br />domain:	sailorvgame.org<br />country:	US<br />source:	ARIN<br />email:	abuse@bluehost.com<br />inetnum:	74.220.192.0 - 74.220.207.255<br />netname:	BLUEHOST-NETWORK-2<br />descr:	Bluehost Inc. BLUEH-2 1548 North Technology Way #D13 Orem UT 84097<br />ns1:	ns2.hostmonster.com<br />ns2:	ns1.hostmonster.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mdxh.com.cn/old/mlhjg.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8524099</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.avu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8524099</guid>
			<pubDate>2012-11-29T20:40:28+01:00</pubDate>
			<description><![CDATA[id:	8524099<br />first:	1354218028<br />last:	0<br />md5:	06ed216e94525b3ed5062f2f594e6304<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=06ed216e94525b3ed5062f2f594e6304<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.avu<br />url:	http://mdxh.com.cn/old/mlhjg.htm<br />recent:	up<br />response:	alive<br />ip:	125.77.197.11<br />as:	AS4134<br />review:	125.77.197.11<br />domain:	mdxh.com.cn<br />country:	CN<br />source:	APNIC<br />email:	fjnic@fjdcb.fz.fj.cn<br />inetnum:	125.77.0.0 - 125.77.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET Fujian province networkChina Telecom7,East Street ,Fuzhou ,Fujian ,PRC<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p767p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8524053</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8524053</guid>
			<pubDate>2012-11-29T20:20:03+01:00</pubDate>
			<description><![CDATA[id:	8524053<br />first:	1354216803<br />last:	0<br />md5:	0cb76b6fb6e72787ee7f6e4938a9c159<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0cb76b6fb6e72787ee7f6e4938a9c159<br />vt_score:	16/23 (69.6%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p767p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://erkelmuvhaz.hu/katalogus.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8523542</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8523542</guid>
			<pubDate>2012-11-29T17:50:03+01:00</pubDate>
			<description><![CDATA[id:	8523542<br />first:	1354207803<br />last:	0<br />md5:	ad6aadbb33e1a02160642fceddf842d3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=416206be2e9be49db3bc15f0f0948faf<br />vt_score:	25/45 (55.6%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://erkelmuvhaz.hu/katalogus.html<br />recent:	up<br />response:	alive<br />ip:	81.0.104.141<br />as:	AS12301<br />review:	81.0.104.141<br />domain:	erkelmuvhaz.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@invitel.net<br />inetnum:	81.0.104.0 - 81.0.104.255<br />netname:	VTH<br />descr:	Datacenter Hosting Internet<br />ns1:	ns1.interlink.hu<br />ns2:	ns0.interlink.hu<br />ns3:	ns2.interlink.hu<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dogs-at-home.gmxhome.de/hpkontakt.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8523242</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/PhoexRef.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8523242</guid>
			<pubDate>2012-11-29T17:27:25+01:00</pubDate>
			<description><![CDATA[id:	8523242<br />first:	1354206445<br />last:	0<br />md5:	51bdc0738eba44bcdb81841d2e7a7867<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=51bdc0738eba44bcdb81841d2e7a7867<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/PhoexRef.E<br />url:	http://dogs-at-home.gmxhome.de/hpkontakt.htm<br />recent:	up<br />response:	alive<br />ip:	82.165.58.83<br />as:	AS8560<br />review:	82.165.58.83<br />domain:	gmxhome.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.48.0 - 82.165.63.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns10.schlund.de<br />ns2:	ns9.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://divani.al/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8523241</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Script.474610.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8523241</guid>
			<pubDate>2012-11-29T17:27:25+01:00</pubDate>
			<description><![CDATA[id:	8523241<br />first:	1354206445<br />last:	0<br />md5:	376f6f9f7a5c5ad7182756e9b861157b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=376f6f9f7a5c5ad7182756e9b861157b<br />vt_score:	16/44 (36.4%)<br />scanner:	avira<br />virusname:	TR/Script.474610.1<br />url:	http://divani.al/<br />recent:	up<br />response:	alive<br />ip:	209.217.226.237<br />as:	AS3595<br />review:	209.217.226.237<br />domain:	divani.al<br />country:	US<br />source:	ARIN<br />email:	greg@jaguarpc.com<br />inetnum:	209.217.224.0 - 209.217.239.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns1-briscoe.nswebhost.com<br />ns2:	ns2-briscoe.nswebhost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://carmignanoprimo.it/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8523111</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8523111</guid>
			<pubDate>2012-11-29T16:24:58+01:00</pubDate>
			<description><![CDATA[id:	8523111<br />first:	1354202698<br />last:	0<br />md5:	73071e687f226e83330ad2caccce3e12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=73071e687f226e83330ad2caccce3e12<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://carmignanoprimo.it/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	carmignanoprimo.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://agrigelateria.eu/jcms/image/pulsanti/DAL-1-MAGGIO-.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8521600</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/C99Shell.AI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8521600</guid>
			<pubDate>2012-11-29T14:00:05+01:00</pubDate>
			<description><![CDATA[id:	8521600<br />first:	1354194005<br />last:	0<br />md5:	3b545877f0bddb7955744296ae0a87d2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b545877f0bddb7955744296ae0a87d2<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	PHP/C99Shell.AI<br />url:	http://agrigelateria.eu/jcms/image/pulsanti/DAL-1-MAGGIO-.jpg<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.72<br />domain:	agrigelateria.eu<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns3.arubadns.net<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://66.duote.com.cn/qqkjhc.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8521308</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8521308</guid>
			<pubDate>2012-11-29T13:40:23+01:00</pubDate>
			<description><![CDATA[id:	8521308<br />first:	1354192823<br />last:	0<br />md5:	7afbf06c6d944a7a1d78623c90ef8f39<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7afbf06c6d944a7a1d78623c90ef8f39<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://66.duote.com.cn/qqkjhc.zip<br />recent:	up<br />response:	alive<br />ip:	60.191.150.43<br />as:	AS4134<br />review:	60.191.150.43<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	antispam@dcb.hz.zj.cn<br />inetnum:	60.176.0.0 - 60.191.255.255<br />netname:	CHINANET-ZJ-HZ<br />descr:	CHINANET-ZJ Hangzhou node networkZhejiang Telecom<br />ns1:	dns4.50bang.org<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns1.kabasiji.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://women-experts.de/incs/AC_RunActiveContent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517196</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.AP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517196</guid>
			<pubDate>2012-11-29T00:50:06+01:00</pubDate>
			<description><![CDATA[id:	8517196<br />first:	1354146606<br />last:	0<br />md5:	ae56d02f42b582e11647155fef36ceda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7c81bc46679413e9c20c9fb108cf5f55<br />vt_score:	13/43 (30.2%)<br />scanner:	avira<br />virusname:	JS/Kryptik.AP<br />url:	http://women-experts.de/incs/AC_RunActiveContent.js<br />recent:	up<br />response:	alive<br />ip:	80.237.153.71<br />as:	AS20773<br />review:	80.237.153.71<br />domain:	women-experts.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.153.0 - 80.237.153.127<br />netname:	HE-DS-153-CGN2-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.de<br />ns1:	ns1.hans.hosteurope.de<br />ns2:	ns2.hans.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wielkilukwarty.pl/dni_konopnicy.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517193</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.16]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517193</guid>
			<pubDate>2012-11-29T00:40:06+01:00</pubDate>
			<description><![CDATA[id:	8517193<br />first:	1354146006<br />last:	0<br />md5:	1a982e740f91951481ca56b05160f7e6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.BS.16<br />url:	http://wielkilukwarty.pl/dni_konopnicy.html<br />recent:	up<br />response:	alive<br />ip:	89.161.243.136<br />as:	AS12824<br />review:	89.161.243.136<br />domain:	wielkilukwarty.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.192.0 - 89.161.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://viverolaarbequina.com.ar/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Afriem.U]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517192</guid>
			<pubDate>2012-11-29T00:40:06+01:00</pubDate>
			<description><![CDATA[id:	8517192<br />first:	1354146006<br />last:	0<br />md5:	588cf1abdb35860448b169ed9ce04f75<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=588cf1abdb35860448b169ed9ce04f75<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	HTML/Afriem.U<br />url:	http://viverolaarbequina.com.ar/home.html<br />recent:	up<br />response:	alive<br />ip:	200.110.135.131<br />as:	AS18747<br />review:	200.110.135.131<br />domain:	viverolaarbequina.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	operaciones.arin@ifxnw.com.ar<br />inetnum:	200.110.128.0 - 200.110.135.255<br />netname:	AR-INAS-LACNIC<br />descr:	IFX Networks Argentina S.R.L.Av. Belgrano, 1586, Piso 11C1093AAQ - Buenos Aires -Av. Belgrano, 1586, Piso 11C1093AAQ - Buenos Aires -<br />ns1:	ns1.lineadns.com<br />ns2:	ns2.lineadns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ura2.webcrow.jp/nodvd/maounodvd.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517147</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517147</guid>
			<pubDate>2012-11-29T00:30:05+01:00</pubDate>
			<description><![CDATA[id:	8517147<br />first:	1354145405<br />last:	0<br />md5:	1f51cabe9040275364661940aacd03fc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f51cabe9040275364661940aacd03fc<br />vt_score:	20/44 (45.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://ura2.webcrow.jp/nodvd/maounodvd.rar<br />recent:	up<br />response:	alive<br />ip:	112.78.117.142<br />as:	AS9371<br />review:	112.78.117.142<br />domain:	webcrow.jp<br />country:	JP<br />source:	APNIC<br />email:	jpnic@netowl.jp<br />inetnum:	112.78.117.0 - 112.78.117.255<br />netname:	NETOWL<br />descr:	netowl,Inc<br />ns1:	ns1.webcrow.jp<br />ns2:	ns2.webcrow.jp<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://triaxiontms.com.au/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517142</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Crypt.GG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517142</guid>
			<pubDate>2012-11-29T00:30:05+01:00</pubDate>
			<description><![CDATA[id:	8517142<br />first:	1354145405<br />last:	0<br />md5:	7a131d797dbcdc942b6acf5a12e07800<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7a131d797dbcdc942b6acf5a12e07800<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	JS/Crypt.GG<br />url:	http://triaxiontms.com.au/<br />recent:	up<br />response:	alive<br />ip:	182.50.134.128<br />as:	AS26496<br />review:	182.50.130.35<br />domain:	triaxiontms.com.au<br />country:	SG<br />source:	APNIC<br />email:	gschwimer@godaddy.com<br />inetnum:	182.50.128.0 - 182.50.159.255<br />netname:	GODADDY-NET-SG<br />descr:	8 Cross Street#11-00 PWC Building<br />ns1:	ns01.domaincontrol.com<br />ns2:	ns02.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://titlewyx16888.bookonline.com.cn/images/ad/435_62.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517140</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517140</guid>
			<pubDate>2012-11-29T00:30:05+01:00</pubDate>
			<description><![CDATA[id:	8517140<br />first:	1354145405<br />last:	0<br />md5:	0dc4c77c7f3593fc7a584c7b10684cd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0dc4c77c7f3593fc7a584c7b10684cd2<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://titlewyx16888.bookonline.com.cn/images/ad/435_62.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sukurs.palatyn.pl/sukurs/ofirmie.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517136</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517136</guid>
			<pubDate>2012-11-29T00:30:04+01:00</pubDate>
			<description><![CDATA[id:	8517136<br />first:	1354145404<br />last:	0<br />md5:	55ecb3bd3ea5228e72d7faaccf1b4c22<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=55ecb3bd3ea5228e72d7faaccf1b4c22<br />vt_score:	20/43 (46.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://sukurs.palatyn.pl/sukurs/ofirmie.htm<br />recent:	up<br />response:	alive<br />ip:	212.85.120.195<br />as:	AS12824<br />review:	212.85.120.195<br />domain:	palatyn.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.114.0 - 212.85.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery5/pages/pict0665.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517132</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517132</guid>
			<pubDate>2012-11-29T00:30:04+01:00</pubDate>
			<description><![CDATA[id:	8517132<br />first:	1354145404<br />last:	0<br />md5:	90f78133afc902a7b8d05e4e6de86961<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=90f78133afc902a7b8d05e4e6de86961<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery5/pages/pict0665.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery4/pages/pict0042.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8517131</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8517131</guid>
			<pubDate>2012-11-29T00:30:04+01:00</pubDate>
			<description><![CDATA[id:	8517131<br />first:	1354145404<br />last:	0<br />md5:	eddfbf97e54031d6187667e55195edae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eddfbf97e54031d6187667e55195edae<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery4/pages/pict0042.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pacc.info/slideshow.asp?catid=3]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515744</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/IFrame]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515744</guid>
			<pubDate>2012-11-28T21:50:04+01:00</pubDate>
			<description><![CDATA[id:	8515744<br />first:	1354135804<br />last:	0<br />md5:	7c1014e820e9b37c08db36e2a9030012<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ec96f463e2f27d45a90687a5cf59f8db<br />vt_score:	15/45 (33.3%)<br />scanner:	AhnLab_V3<br />virusname:	JS/IFrame<br />url:	http://pacc.info/slideshow.asp?catid=3<br />recent:	up<br />response:	alive<br />ip:	64.64.214.138<br />as:	AS1616<br />review:	64.64.214.138<br />domain:	pacc.info<br />country:	US<br />source:	ARIN<br />email:	ipadmin@corelink.com<br />inetnum:	64.64.214.128 - 64.64.214.159<br />netname:	LAS01-SUBSTREAM-001<br />descr:	5858 S. Pecos Rd. Suite 400a Las Vegas NV 89120<br />ns1:	ns2.substorm.com<br />ns2:	ns1.substorm.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://muratlabunishti.mk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515634</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515634</guid>
			<pubDate>2012-11-28T21:00:09+01:00</pubDate>
			<description><![CDATA[id:	8515634<br />first:	1354132809<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://muratlabunishti.mk/<br />recent:	up<br />response:	alive<br />ip:	85.30.92.2<br />as:	AS16333<br />review:	85.30.92.2<br />domain:	muratlabunishti.mk<br />country:	MK<br />source:	RIPE<br />email:	vesnald@on.net.mk<br />inetnum:	85.30.83.0 - 85.30.92.255<br />netname:	MK-ONNET<br />descr:	PPPoE Broadband InternetON NET ISPSkopje, Macedonia<br />ns1:	ns4.gratisdns.dk<br />ns2:	ns3.gratisdns.dk<br />ns3:	ns1.gratisdns.dk<br />ns4:	ns5.gratisdns.dk<br />ns5:	ns2.gratisdns.dk<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mostwatched.ws/crafts/spinning.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515633</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515633</guid>
			<pubDate>2012-11-28T21:00:09+01:00</pubDate>
			<description><![CDATA[id:	8515633<br />first:	1354132809<br />last:	0<br />md5:	a775cad0b1fb1e801f60bde2ed046093<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a775cad0b1fb1e801f60bde2ed046093<br />vt_score:	11/36 (30.6%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://mostwatched.ws/crafts/spinning.html<br />recent:	up<br />response:	alive<br />ip:	208.109.46.211<br />as:	AS26496<br />review:	208.109.46.211<br />domain:	mostwatched.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns43.domaincontrol.com<br />ns2:	ns44.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://magicprinting.ca/contact.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515469</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_CLICKER.SH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515469</guid>
			<pubDate>2012-11-28T19:50:22+01:00</pubDate>
			<description><![CDATA[id:	8515469<br />first:	1354128622<br />last:	0<br />md5:	31ae88930b87f9290c0facad7f01c9ab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=31ae88930b87f9290c0facad7f01c9ab<br />vt_score:	10/36 (27.8%)<br />scanner:	trendmicro<br />virusname:	JS_CLICKER.SH<br />url:	http://magicprinting.ca/contact.html<br />recent:	up<br />response:	alive<br />ip:	97.74.215.224<br />as:	AS26496<br />review:	97.74.215.224<br />domain:	magicprinting.ca<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns17.domaincontrol.com<br />ns2:	ns18.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://korneliuszmatauszek.pl/kazania/wiel/4nw10.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515439</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515439</guid>
			<pubDate>2012-11-28T19:30:03+01:00</pubDate>
			<description><![CDATA[id:	8515439<br />first:	1354127403<br />last:	0<br />md5:	f1d55cd5db534d4badc8db4d3a030e18<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1d55cd5db534d4badc8db4d3a030e18<br />vt_score:	20/43 (46.5%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://korneliuszmatauszek.pl/kazania/wiel/4nw10.html<br />recent:	up<br />response:	alive<br />ip:	89.161.179.213<br />as:	AS12824<br />review:	89.161.179.213<br />domain:	korneliuszmatauszek.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://homecarefortheholidays.org/seven-steps.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515276</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515276</guid>
			<pubDate>2012-11-28T18:20:03+01:00</pubDate>
			<description><![CDATA[id:	8515276<br />first:	1354123203<br />last:	0<br />md5:	e1740d8842b8c882ef386ae97f8c5f52<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0b8083e3e9965214061fc08caee57471<br />vt_score:	12/36 (33.3%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://homecarefortheholidays.org/seven-steps.htm<br />recent:	up<br />response:	alive<br />ip:	174.123.233.226<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	74.54.90.167<br />domain:	homecarefortheholidays.org<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns2.americanweb.net<br />ns2:	ns1.americanweb.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gasaigon.com.vn/includes/js/extra/js2.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515250</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS.Obfus-31]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515250</guid>
			<pubDate>2012-11-28T18:00:08+01:00</pubDate>
			<description><![CDATA[id:	8515250<br />first:	1354122008<br />last:	0<br />md5:	4b070cf4df2538c572aa11364a9172a6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4b070cf4df2538c572aa11364a9172a6<br />vt_score:	12/37 (32.4%)<br />scanner:	clamav<br />virusname:	JS.Obfus-31<br />url:	http://gasaigon.com.vn/includes/js/extra/js2.htm<br />recent:	up<br />response:	alive<br />ip:	118.69.199.58<br />as:	AS18403<br />review:	14.0.21.30<br />domain:	gasaigon.com.vn<br />country:	VN<br />source:	APNIC<br />email:	dvan@newlifecompany.com<br />inetnum:	118.69.0.0 - 118.69.255.255<br />netname:	NEWLIFE-VNNIC-VN<br />descr:	Newlifecompany Company21 Tran Khac Chan str, P15, Dist Phu Nhuan, TP HCM<br />ns1:	win-4e5b661vpbs<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fuss-und-pedalreisen.de/typo3conf/_img/bord_er.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8515249</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8515249</guid>
			<pubDate>2012-11-28T18:00:08+01:00</pubDate>
			<description><![CDATA[id:	8515249<br />first:	1354122008<br />last:	0<br />md5:	1ffe1e47fe1d536d58d1053d01eeb247<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1ffe1e47fe1d536d58d1053d01eeb247<br />vt_score:	27/44 (61.4%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://fuss-und-pedalreisen.de/typo3conf/_img/bord_er.html<br />recent:	up<br />response:	alive<br />ip:	212.162.52.27<br />as:	AS9829<br />review:	212.162.52.27<br />domain:	fuss-und-pedalreisen.de<br />country:	de<br />source:	RIPE<br />email:	abuse@level3.com<br />inetnum:	212.162.52.0 - 212.162.53.255<br />netname:	SECURENETZ-DE<br />descr:	Secure-Netz<br />ns1:	ns02.nethosting4you.de<br />ns2:	ns04.nethosting4you.de<br />ns3:	ns01.nethosting4you.de<br />ns4:	ns03.nethosting4you.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/jewelry-watches/hair-jewelry.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8512782</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8512782</guid>
			<pubDate>2012-11-28T16:56:11+01:00</pubDate>
			<description><![CDATA[id:	8512782<br />first:	1354118171<br />last:	0<br />md5:	1bffc8cbf25136855ce1ef141423bc77<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1bffc8cbf25136855ce1ef141423bc77<br />vt_score:	14/45 (31.1%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/jewelry-watches/hair-jewelry.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/coins-paper-money/coins-ancient.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8512781</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8512781</guid>
			<pubDate>2012-11-28T16:56:11+01:00</pubDate>
			<description><![CDATA[id:	8512781<br />first:	1354118171<br />last:	0<br />md5:	e35f9259477493ae90710a43ed6624b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e35f9259477493ae90710a43ed6624b3<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/coins-paper-money/coins-ancient.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://china-city.org/~mail/xiangguan1.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511974</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Mal_Hifrm]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511974</guid>
			<pubDate>2012-11-28T15:38:49+01:00</pubDate>
			<description><![CDATA[id:	8511974<br />first:	1354113529<br />last:	0<br />md5:	1f2eb9914300d32aa553c0c2bdc479a9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f2eb9914300d32aa553c0c2bdc479a9<br />vt_score:	8/36 (22.2%)<br />scanner:	trendmicro<br />virusname:	Mal_Hifrm<br />url:	http://china-city.org/~mail/xiangguan1.htm<br />recent:	up<br />response:	alive<br />ip:	103.20.194.21<br />as:	AS3491<br />review:	103.20.194.21<br />domain:	china-city.org<br />country:	HK<br />source:	APNIC<br />email:	83997778@qq.com<br />inetnum:	103.20.192.0 - 103.20.195.255<br />netname:	PCCWME-HK<br />descr:	FLAT 1405,14/F BLK A FUK KEUNG IND BLDG68 TONG MI ROAD MONG<br />ns1:	ns18.xincache.com<br />ns2:	ns17.xincache.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bfzh.com.cn/yanjiuyuanzhuli.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511965</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.AP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511965</guid>
			<pubDate>2012-11-28T15:38:49+01:00</pubDate>
			<description><![CDATA[id:	8511965<br />first:	1354113529<br />last:	0<br />md5:	455d9735e6a6842115aa12fcd4fb9104<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	HTML/IFrame.AP<br />url:	http://bfzh.com.cn/yanjiuyuanzhuli.html<br />recent:	up<br />response:	alive<br />ip:	211.100.61.82<br />as:	AS9803<br />review:	211.100.61.82<br />domain:	bfzh.com.cn<br />country:	CN<br />source:	APNIC<br />email:	zhengym@bjtelecom.net<br />inetnum:	211.100.0.0 - 211.100.63.255<br />netname:	BJTEL<br />descr:	ChinaTelecom Group Beijing Ltd,CoNo.21 Chaoyangmen Beidajie,Dongcheng District,Beijing<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bedbud.pl/galerie/patio]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511695</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511695</guid>
			<pubDate>2012-11-28T15:00:06+01:00</pubDate>
			<description><![CDATA[id:	8511695<br />first:	1354111206<br />last:	0<br />md5:	2cfd0d8000e32686b871cd7791634ab9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2cfd0d8000e32686b871cd7791634ab9<br />vt_score:	10/36 (27.8%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://bedbud.pl/galerie/patio<br />recent:	up<br />response:	alive<br />ip:	91.203.134.184<br />as:	AS43333<br />review:	91.203.134.184<br />domain:	bedbud.pl<br />country:	PL<br />source:	RIPE<br />email:	biuro@nephax.com<br />inetnum:	91.203.132.0 - 91.203.135.255<br />netname:	CIS-NEPHAX<br />descr:	CIS NEPHAXCIS NEPHAX<br />ns1:	ns1.hekko.net.pl<br />ns2:	ns2.hekko.net.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bandadetona.com.br/1.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511694</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511694</guid>
			<pubDate>2012-11-28T15:00:06+01:00</pubDate>
			<description><![CDATA[id:	8511694<br />first:	1354111206<br />last:	0<br />md5:	8d3f5e1c66e520c2b9947666f326683c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=49ab4bf3c0595c030c00ec40ad1c7f49<br />vt_score:	4/42 (9.5%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://bandadetona.com.br/1.html<br />recent:	up<br />response:	alive<br />ip:	187.61.61.219<br />as:	AS15201<br />review:	187.61.61.219<br />domain:	bandadetona.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.61.0.0 - 187.61.63.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns2.bandadetona.com.br<br />ns2:	ns1.bandadetona.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://121.10.105.29:85/ko/16.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511269</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511269</guid>
			<pubDate>2012-11-28T13:20:02+01:00</pubDate>
			<description><![CDATA[id:	8511269<br />first:	1354105202<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://121.10.105.29:85/ko/16.exe<br />recent:	up<br />response:	alive<br />ip:	121.10.105.29<br />as:	AS4134<br />review:	121.10.105.29<br />domain:	121.10.105.29<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	121.8.0.0 - 121.15.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://120.209.128.20:82/down/8944325495.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8511268</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADWARE/Adware.1556480]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8511268</guid>
			<pubDate>2012-11-28T13:20:02+01:00</pubDate>
			<description><![CDATA[id:	8511268<br />first:	1354105202<br />last:	0<br />md5:	947e5c98ec95e9d61a79106208cbcaa6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=947e5c98ec95e9d61a79106208cbcaa6<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	ADWARE/Adware.1556480<br />url:	http://120.209.128.20:82/down/8944325495.zip<br />recent:	up<br />response:	alive<br />ip:	120.209.128.20<br />as:	AS9808<br />review:	120.209.128.20<br />domain:	120.209.128.20<br />country:	CN<br />source:	APNIC<br />email:	sunjinxia@chinamobile.com<br />inetnum:	120.192.0.0 - 120.255.255.255<br />netname:	CMNET<br />descr:	China Mobile Communications CorporationMobile Communications Network Operator in ChinaInternet Service Provider in ChinaChina Mobile communications corporation<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery5/pages/pict0620.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8505122</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8505122</guid>
			<pubDate>2012-11-27T17:17:35+01:00</pubDate>
			<description><![CDATA[id:	8505122<br />first:	1354033055<br />last:	0<br />md5:	291cf4c698490cdb5ab3b2a5105cdbf3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=291cf4c698490cdb5ab3b2a5105cdbf3<br />vt_score:	20/44 (45.5%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery5/pages/pict0620.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/nl/dload.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8505067</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8505067</guid>
			<pubDate>2012-11-27T17:00:11+01:00</pubDate>
			<description><![CDATA[id:	8505067<br />first:	1354032011<br />last:	0<br />md5:	2917b2f2a9d82551d9575a3fcf360197<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2917b2f2a9d82551d9575a3fcf360197<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/nl/dload.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mfpfederation.org/website/content/latest_result1.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504611</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Script-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504611</guid>
			<pubDate>2012-11-27T16:10:06+01:00</pubDate>
			<description><![CDATA[id:	8504611<br />first:	1354029006<br />last:	0<br />md5:	f854ce028d12f807b8cc5c39322a7f8e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ce96432224051ce7b9102f67e60d1131<br />vt_score:	6/36 (16.7%)<br />scanner:	Avast<br />virusname:	HTML:Script-inf<br />url:	http://mfpfederation.org/website/content/latest_result1.asp<br />recent:	up<br />response:	alive<br />ip:	173.0.133.24<br />as:	AS53628<br />review:	173.0.133.24<br />domain:	mfpfederation.org<br />country:	US<br />source:	ARIN<br />email:	abuse@jdnextgen.com<br />inetnum:	173.0.128.0 - 173.0.143.255<br />netname:	APYLI-AS<br />descr:	Apyl Inc APYLI-1 1517 E Hillcrest Street Orlando FL 32803<br />ns1:	ns4.perfectwebspace.com<br />ns2:	ns3.perfectwebspace.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://luzie.gmxhome.de/opinions/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504602</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.cbv]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504602</guid>
			<pubDate>2012-11-27T16:00:07+01:00</pubDate>
			<description><![CDATA[id:	8504602<br />first:	1354028407<br />last:	0<br />md5:	c27edff614ae6366f181fedd3fc4b655<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c27edff614ae6366f181fedd3fc4b655<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.cbv<br />url:	http://luzie.gmxhome.de/opinions/index.htm<br />recent:	up<br />response:	alive<br />ip:	82.165.127.208<br />as:	AS8560<br />review:	82.165.127.208<br />domain:	gmxhome.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns9.schlund.de<br />ns2:	ns10.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=75]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504453</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504453</guid>
			<pubDate>2012-11-27T15:20:03+01:00</pubDate>
			<description><![CDATA[id:	8504453<br />first:	1354026003<br />last:	0<br />md5:	8becf8db67a9d2d7a4768b605f020a65<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2c51e3ea9482b140979d64580c4261b5<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=75<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	e.dns.cn<br />ns2:	cns.cernet.net<br />ns3:	a.dns.cn<br />ns4:	b.dns.cn<br />ns5:	c.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fotoszym.pl/festiwal/album/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504425</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/SrcInject.N]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504425</guid>
			<pubDate>2012-11-27T15:10:04+01:00</pubDate>
			<description><![CDATA[id:	8504425<br />first:	1354025404<br />last:	0<br />md5:	abdb1ebdad9a03ad5f6d3ac2fc9c731c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=abdb1ebdad9a03ad5f6d3ac2fc9c731c<br />vt_score:	10/35 (28.6%)<br />scanner:	avira<br />virusname:	JS/SrcInject.N<br />url:	http://fotoszym.pl/festiwal/album/<br />recent:	up<br />response:	alive<br />ip:	62.129.237.252<br />as:	AS12824<br />review:	62.129.237.252<br />domain:	fotoszym.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.224.0 - 62.129.239.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ethos.org.br/CI2009Dinamico/Mostra/site/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504422</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.qtx.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504422</guid>
			<pubDate>2012-11-27T15:10:04+01:00</pubDate>
			<description><![CDATA[id:	8504422<br />first:	1354025404<br />last:	0<br />md5:	dce85ea4c42600269d487203e168ebaa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dce85ea4c42600269d487203e168ebaa<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/Agent.qtx.1<br />url:	http://ethos.org.br/CI2009Dinamico/Mostra/site/<br />recent:	up<br />response:	alive<br />ip:	200.169.96.111<br />as:	AS21911<br />review:	200.169.96.111<br />domain:	ethos.org.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@dualtec.com.br<br />inetnum:	200.169.96.0 - 200.169.111.255<br />netname:	058.671.835/0001-53<br />descr:	DUALTEC INFORMATICA LTDA<br />ns1:	easydns1.dualtec.com.br<br />ns2:	easydns2.dualtec.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://chlodnictwo.ovh.org/ciekawostki/ciekawostki_index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8504138</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.T]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8504138</guid>
			<pubDate>2012-11-27T14:30:04+01:00</pubDate>
			<description><![CDATA[id:	8504138<br />first:	1354023004<br />last:	0<br />md5:	b963787e28ef5d1b968329ef5ec76d47<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fc0a095fbd71d42f21f7b21bc69fa49d<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/Twetti.T<br />url:	http://chlodnictwo.ovh.org/ciekawostki/ciekawostki_index.htm<br />recent:	up<br />response:	alive<br />ip:	46.105.198.1<br />as:	AS16276<br />review:	46.105.198.1<br />domain:	ovh.org<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	46.105.0.0 - 46.105.255.255<br />netname:	FR-OVH-20101129<br />descr:	Ovh SystemsOVH ISPParis, France<br />ns1:	dns.ovh.net<br />ns2:	ns10.ovh.net<br />ns3:	dns10.ovh.net<br />ns4:	ns.ovh.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://capoti.it/ionica/sx.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8503962</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8503962</guid>
			<pubDate>2012-11-27T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	8503962<br />first:	1354022402<br />last:	0<br />md5:	7252e57943dacb2f3e0cc70da013fc0e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c12caba20c75bcacc237872ba52c2195<br />vt_score:	21/36 (58.3%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.inf<br />url:	http://capoti.it/ionica/sx.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.72<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	capoti.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://blog.kijowski.plnblog.kijowski.pl/ojciec.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8503961</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8503961</guid>
			<pubDate>2012-11-27T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	8503961<br />first:	1354022402<br />last:	0<br />md5:	f178eae080569f399c17ef8409fb05da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8161ab425c7fbbdae0d723cf1034aac9<br />vt_score:	18/40 (45%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://blog.kijowski.plnblog.kijowski.pl/ojciec.html<br />recent:	up<br />response:	alive<br />ip:	77.79.246.200<br />as:	AS15694<br />review:	77.79.247.160<br />domain:	kijowski.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@atman.pl<br />inetnum:	77.79.244.0 - 77.79.247.255<br />netname:	PROGRESO-PL<br />descr:	Progreso #1ul. 1 Maja 744-330 Jastrzebie Zdroj<br />ns1:	d.ns2.pl<br />ns2:	d.ns1.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://absentofi.org/wp-content/uploads/2007/10/ouroboros2.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8503958</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.vk.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8503958</guid>
			<pubDate>2012-11-27T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	8503958<br />first:	1354022402<br />last:	0<br />md5:	070a463ce5c41982129d2d0864a34563<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=070a463ce5c41982129d2d0864a34563<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	TR/Spy.Banker.vk.1<br />url:	http://absentofi.org/wp-content/uploads/2007/10/ouroboros2.jpg<br />recent:	up<br />response:	alive<br />ip:	50.22.14.114<br />as:	AS36351<br />review:	50.22.14.114<br />domain:	absentofi.org<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	50.22.0.0 - 50.23.255.255<br />netname:	SOFTLAYER-4-9<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns1.asmallorange.com<br />ns2:	ns2.asmallorange.com<br />ns3:	ns3.asmallorange.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://69.167.146.230//wp-admin/includes/prototype.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8503955</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.agp]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8503955</guid>
			<pubDate>2012-11-27T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	8503955<br />first:	1354022402<br />last:	0<br />md5:	b0398b10ca345760782f286a78877664<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b0398b10ca345760782f286a78877664<br />vt_score:	25/44 (56.8%)<br />scanner:	avira<br />virusname:	HTML/IFrame.agp<br />url:	http://69.167.146.230//wp-admin/includes/prototype.js<br />recent:	up<br />response:	alive<br />ip:	69.167.146.230<br />as:	AS32244<br />review:	69.167.146.230<br />domain:	69.167.146.230<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	69.167.128.0 - 69.167.191.255<br />netname:	LIQUIDWEB-9<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://55.duote.org/dashidingshidshuen.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8503954</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Hupigon-1313]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8503954</guid>
			<pubDate>2012-11-27T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	8503954<br />first:	1354022402<br />last:	0<br />md5:	b7a214b429f2e8d325b7e9b3ab3b07af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beae84fce01014df2490bb72ba2e7660<br />vt_score:	7/36 (19.4%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Hupigon-1313<br />url:	http://55.duote.org/dashidingshidshuen.zip<br />recent:	up<br />response:	alive<br />ip:	117.25.129.88<br />as:	AS4134<br />review:	117.25.129.88<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@fjdcb.fz.fj.cn<br />inetnum:	117.24.0.0 - 117.31.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET Fujian province networkChina Telecom7,East Street ,Fuzhou ,Fujian ,PRC<br />ns1:	dns1.kabasiji.com<br />ns2:	dns4.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns3.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yvonne.pl/galeria/mikolajki2005/index3.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8499841</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8499841</guid>
			<pubDate>2012-11-26T22:00:08+01:00</pubDate>
			<description><![CDATA[id:	8499841<br />first:	1353963608<br />last:	0<br />md5:	96268cf4c6870a013438058a8e8b5b6d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=96268cf4c6870a013438058a8e8b5b6d<br />vt_score:	9/36 (25%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://yvonne.pl/galeria/mikolajki2005/index3.html<br />recent:	up<br />response:	alive<br />ip:	178.19.104.18<br />as:	AS39869<br />review:	178.19.104.18<br />domain:	yvonne.pl<br />country:	PL<br />source:	RIPE<br />email:	tomek@sitel.net.pl<br />inetnum:	178.19.104.0 - 178.19.111.255<br />netname:	LIVENET<br />descr:	Livenet sp. z o.o.SITELLIVENET-PL<br />ns1:	dns1.slaskdatacenter.pl<br />ns2:	dns3.slaskdatacenter.pl<br />ns3:	dns2.slaskdatacenter.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wczasy-niedzica.pl/niedzica.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8499809</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ZB.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8499809</guid>
			<pubDate>2012-11-26T21:31:57+01:00</pubDate>
			<description><![CDATA[id:	8499809<br />first:	1353961917<br />last:	0<br />md5:	c746a4b1cb385a37a7d8bff2b9806648<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7114900f83a9a6087f153951b13b2fdb<br />vt_score:	21/45 (46.7%)<br />scanner:	undef<br />virusname:	JS/iFrame.ZB.2<br />url:	http://wczasy-niedzica.pl/niedzica.html<br />recent:	up<br />response:	alive<br />ip:	79.96.223.236<br />as:	AS12824<br />review:	79.96.223.236<br />domain:	wczasy-niedzica.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vacaturehuis.nl/screen/regiovacature.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498996</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-XU Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498996</guid>
			<pubDate>2012-11-26T21:20:26+01:00</pubDate>
			<description><![CDATA[id:	8498996<br />first:	1353961226<br />last:	0<br />md5:	affa4e7d2faa7922e5a6661f2e0420c6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=affa4e7d2faa7922e5a6661f2e0420c6<br />vt_score:	14/36 (38.9%)<br />scanner:	Avast<br />virusname:	JS:Redirector-XU Trj<br />url:	http://vacaturehuis.nl/screen/regiovacature.js<br />recent:	up<br />response:	alive<br />ip:	193.239.210.29<br />as:	AS39318<br />review:	193.239.210.29<br />domain:	vacaturehuis.nl<br />country:	BE<br />source:	RIPE<br />email:	info@nucleus.be<br />inetnum:	193.239.210.0 - 193.239.211.255<br />netname:	BE-NUCLEUS<br />descr:	NUCLEUS BVBANucleus BVBA<br />ns1:	ns.vacaturehuis.nl<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://uitvaartverzekering-berekenen.nl/file/js/javascript.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498995</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Script.Packed-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498995</guid>
			<pubDate>2012-11-26T21:20:26+01:00</pubDate>
			<description><![CDATA[id:	8498995<br />first:	1353961226<br />last:	0<br />md5:	8f83afacf1f99550a0f5e72f37a24165<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8f83afacf1f99550a0f5e72f37a24165<br />vt_score:	10/36 (27.8%)<br />scanner:	clamav<br />virusname:	PUA.Script.Packed-2<br />url:	http://uitvaartverzekering-berekenen.nl/file/js/javascript.js<br />recent:	up<br />response:	alive<br />ip:	178.239.59.151<br />as:	AS47869<br />review:	178.239.59.151<br />domain:	uitvaartverzekering-berekenen.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@netrouting.eu<br />inetnum:	178.239.48.0 - 178.239.63.255<br />netname:	NL-NETROUTING-20100803<br />descr:	Netrouting<br />ns1:	ns2.hypotheek-aanvragen.nl<br />ns2:	ns1.hypotheek-aanvragen.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tzonestudio.ca/css.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498994</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.DV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498994</guid>
			<pubDate>2012-11-26T21:20:26+01:00</pubDate>
			<description><![CDATA[id:	8498994<br />first:	1353961226<br />last:	0<br />md5:	46be36908431b807655e365acbdb09f7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6b2370350a07b24448e0a3e7bf30d2be<br />vt_score:	13/37 (35.1%)<br />scanner:	avira<br />virusname:	JS/Blacole.DV<br />url:	http://tzonestudio.ca/css.js<br />recent:	up<br />response:	alive<br />ip:	97.74.144.196<br />as:	AS26496<br />review:	97.74.144.196<br />domain:	tzonestudio.ca<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns51.domaincontrol.com<br />ns2:	ns52.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tux-ce.org/artigos/roteadores.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498993</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498993</guid>
			<pubDate>2012-11-26T21:20:26+01:00</pubDate>
			<description><![CDATA[id:	8498993<br />first:	1353961226<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://tux-ce.org/artigos/roteadores.html<br />recent:	up<br />response:	alive<br />ip:	64.90.37.90<br />as:	AS26347<br />review:	64.90.37.90<br />domain:	tux-ce.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	64.90.32.0 - 64.90.63.255<br />netname:	DREAMHOST-BLK10<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://stu-dent.info/_library/scripts/navigation.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498885</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.J]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498885</guid>
			<pubDate>2012-11-26T20:50:32+01:00</pubDate>
			<description><![CDATA[id:	8498885<br />first:	1353959432<br />last:	0<br />md5:	53db6a5c784b069a05fd2a6950b93eec<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=53db6a5c784b069a05fd2a6950b93eec<br />vt_score:	12/44 (27.3%)<br />scanner:	avira<br />virusname:	HTML/Infected.J<br />url:	http://stu-dent.info/_library/scripts/navigation.js<br />recent:	up<br />response:	alive<br />ip:	195.234.228.210<br />as:	AS25260<br />review:	195.234.228.210<br />domain:	stu-dent.info<br />country:	DE<br />source:	RIPE<br />email:	abuse@de.colt.net<br />inetnum:	195.234.228.0 - 195.234.231.255<br />netname:	DE-COLT-QUALITYHOSTING<br />descr:	QualityHosting GbRZum Wartturm 163571 GelnhausenGermanyabuse/spam  mail to abuse@qualityhosting.deabuse/spam  please do not contact abuse@de.colt.netQUALITYHOSTING, Gelnhausen<br />ns1:	ns1.domainkunden.de<br />ns2:	ns2.domainkunden.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery/pages/agf00058.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498882</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498882</guid>
			<pubDate>2012-11-26T20:50:32+01:00</pubDate>
			<description><![CDATA[id:	8498882<br />first:	1353959432<br />last:	0<br />md5:	67fc0c40638b073440379e1ea295d9f3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=67fc0c40638b073440379e1ea295d9f3<br />vt_score:	21/44 (47.7%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery/pages/agf00058.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://siwik.pl/blaszczak2005/galery5/pages/pict0632.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498881</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498881</guid>
			<pubDate>2012-11-26T20:50:32+01:00</pubDate>
			<description><![CDATA[id:	8498881<br />first:	1353959432<br />last:	0<br />md5:	3a9ef1f4b747652e4baeaba84cce5f9d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3a9ef1f4b747652e4baeaba84cce5f9d<br />vt_score:	20/43 (46.5%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen5<br />url:	http://siwik.pl/blaszczak2005/galery5/pages/pict0632.htm<br />recent:	up<br />response:	alive<br />ip:	79.96.16.42<br />as:	AS12824<br />review:	79.96.16.42<br />domain:	siwik.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://seman.eng.br/Postal_Receipt.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498879</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdv.788447]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498879</guid>
			<pubDate>2012-11-26T20:50:32+01:00</pubDate>
			<description><![CDATA[id:	8498879<br />first:	1353959432<br />last:	0<br />md5:	8b265c32b6dcf2c12b300e36cde90eb6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8b265c32b6dcf2c12b300e36cde90eb6<br />vt_score:	23/35 (65.7%)<br />scanner:	avira<br />virusname:	TR/Rogue.kdv.788447<br />url:	http://seman.eng.br/Postal_Receipt.zip<br />recent:	up<br />response:	alive<br />ip:	208.113.247.103<br />as:	AS26347<br />review:	208.113.247.103<br />domain:	eng.br<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	208.113.128.0 - 208.113.255.255<br />netname:	DREAMHOST-BLK6<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	a.dns.br<br />ns2:	b.dns.br<br />ns3:	c.dns.br<br />ns4:	d.dns.br<br />ns5:	e.dns.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasinos.info/es/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498817</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498817</guid>
			<pubDate>2012-11-26T20:20:19+01:00</pubDate>
			<description><![CDATA[id:	8498817<br />first:	1353957619<br />last:	0<br />md5:	94cf30f6e3e1fe0bc937f4e3026d69b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=94cf30f6e3e1fe0bc937f4e3026d69b3<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasinos.info/es/index.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasinos.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns2.dreamhost.com<br />ns2:	ns1.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/sv/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498816</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498816</guid>
			<pubDate>2012-11-26T20:20:19+01:00</pubDate>
			<description><![CDATA[id:	8498816<br />first:	1353957619<br />last:	0<br />md5:	af27de9d356ee3a48972b8f6f9ebcac5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=af27de9d356ee3a48972b8f6f9ebcac5<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/sv/index.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/it/dload.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498815</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498815</guid>
			<pubDate>2012-11-26T20:20:19+01:00</pubDate>
			<description><![CDATA[id:	8498815<br />first:	1353957619<br />last:	0<br />md5:	058926d41699540b155c75e7b16f48bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=058926d41699540b155c75e7b16f48bc<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/it/dload.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/es/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498814</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498814</guid>
			<pubDate>2012-11-26T20:20:19+01:00</pubDate>
			<description><![CDATA[id:	8498814<br />first:	1353957619<br />last:	0<br />md5:	d32bdc4ed44d83127a71d2bc4f34315f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d32bdc4ed44d83127a71d2bc4f34315f<br />vt_score:	26/34 (76.5%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/es/index.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rivieracasino.info/el/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498813</guid>
			<pubDate>2012-11-26T20:20:18+01:00</pubDate>
			<description><![CDATA[id:	8498813<br />first:	1353957618<br />last:	0<br />md5:	7424bdcecf8ff35b84bb5f017fc25104<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7424bdcecf8ff35b84bb5f017fc25104<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://rivieracasino.info/el/index.html<br />recent:	up<br />response:	alive<br />ip:	69.163.180.113<br />as:	AS26347<br />review:	69.163.180.113<br />domain:	rivieracasino.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	69.163.128.0 - 69.163.191.255<br />netname:	DREAMHOST-BLK9<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rad-sauce.org/gaming/main.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498796</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498796</guid>
			<pubDate>2012-11-26T20:20:18+01:00</pubDate>
			<description><![CDATA[id:	8498796<br />first:	1353957618<br />last:	0<br />md5:	c9d4def568fd12cebc6df48e8a0fd20b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c9d4def568fd12cebc6df48e8a0fd20b<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	JS/Redirect.AO<br />url:	http://rad-sauce.org/gaming/main.html<br />recent:	up<br />response:	alive<br />ip:	173.236.137.101<br />as:	AS26347<br />review:	208.113.199.158<br />domain:	rad-sauce.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	173.236.128.0 - 173.236.255.255<br />netname:	DREAMHOST-BLK6<br />descr:	New Dream Network, LLC NDN 10 Pointe Drive Suite 235 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns1.dreamhost.com<br />ns3:	ns2.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/templates/rt_hyperion_j15/js/rokfonts.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498466</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498466</guid>
			<pubDate>2012-11-26T19:20:04+01:00</pubDate>
			<description><![CDATA[id:	8498466<br />first:	1353954004<br />last:	0<br />md5:	2050ffbbd40033205b4e7c15df4c13fd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2050ffbbd40033205b4e7c15df4c13fd<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/templates/rt_hyperion_j15/js/rokfonts.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.151<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://paskud.pl/mdk/script/stdom.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498465</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Iframe.CBH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498465</guid>
			<pubDate>2012-11-26T19:20:04+01:00</pubDate>
			<description><![CDATA[id:	8498465<br />first:	1353954004<br />last:	0<br />md5:	89422d2cd2af95e18f9d6c97b8dfd65e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=89422d2cd2af95e18f9d6c97b8dfd65e<br />vt_score:	9/32 (28.1%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Iframe.CBH<br />url:	http://paskud.pl/mdk/script/stdom.js<br />recent:	up<br />response:	alive<br />ip:	91.201.153.138<br />as:	AS48446<br />review:	91.201.153.138<br />domain:	paskud.pl<br />country:	PL<br />source:	RIPE<br />email:	biuro@hostersi.pl<br />inetnum:	91.201.152.0 - 91.201.155.255<br />netname:	HOSTERSI<br />descr:	Hostersi Sp. z o.o.HOSTERSI<br />ns1:	dns.hostersi.pl<br />ns2:	dns2.hostersi.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://notkontora.com.ua/wp-admin/tnglej.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498440</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Refresher-A Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498440</guid>
			<pubDate>2012-11-26T18:50:03+01:00</pubDate>
			<description><![CDATA[id:	8498440<br />first:	1353952203<br />last:	0<br />md5:	257975433964712b5d40e15ee45b3c7b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=257975433964712b5d40e15ee45b3c7b<br />vt_score:	10/38 (26.3%)<br />scanner:	Avast<br />virusname:	HTML:Refresher-A Trj<br />url:	http://notkontora.com.ua/wp-admin/tnglej.html<br />recent:	up<br />response:	alive<br />ip:	98.131.56.61<br />as:	AS32392<br />review:	98.131.56.61<br />domain:	notkontora.com.ua<br />country:	US<br />source:	ARIN<br />email:	ipadmin@ecommerce.com<br />inetnum:	98.130.0.0 - 98.131.255.255<br />netname:	ECOMMERCE-HOSTING<br />descr:	Ecommerce Corporation ECOMM-5 1774 Dividend Dr Columbus OH 43228<br />ns1:	ns11.ixwebhosting.com<br />ns2:	ns12.ixwebhosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nlcupc.org/pages/music.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498439</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498439</guid>
			<pubDate>2012-11-26T18:50:03+01:00</pubDate>
			<description><![CDATA[id:	8498439<br />first:	1353952203<br />last:	0<br />md5:	d384a602b60eadb8c49dd71325b7b52a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d384a602b60eadb8c49dd71325b7b52a<br />vt_score:	8/35 (22.9%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://nlcupc.org/pages/music.html<br />recent:	up<br />response:	alive<br />ip:	174.122.175.194<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.122.175.194<br />domain:	nlcupc.org<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-16<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns2.wfdns.com<br />ns2:	ns1.wfdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mirnet.com.my/feedback/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498364</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.aoj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498364</guid>
			<pubDate>2012-11-26T18:00:06+01:00</pubDate>
			<description><![CDATA[id:	8498364<br />first:	1353949206<br />last:	0<br />md5:	19717347f4c873a244a0ea27adec8196<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=19717347f4c873a244a0ea27adec8196<br />vt_score:	7/36 (19.4%)<br />scanner:	avira<br />virusname:	HTML/IFrame.aoj<br />url:	http://mirnet.com.my/feedback/index.html<br />recent:	up<br />response:	alive<br />ip:	210.5.43.162<br />as:	AS45352<br />review:	210.5.43.162<br />domain:	mirnet.com.my<br />country:	MY<br />source:	APNIC<br />email:	ipnoc@ipserverone.com<br />inetnum:	210.5.40.0 - 210.5.47.255<br />netname:	IPSERVERONE-MY<br />descr:	L7-13, Level 7, Brem Mall, Jalan Kepong, 52000 Kuala LumpurIPSERVERONE Hosting Service, Malaysia - 210.5.40.0/21In case of abuse, please contact abuse@ipserverone.com<br />ns1:	homer.mir.com.my<br />ns2:	lisa.mir.com.my<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mavi-ambalaj.com.tr/index.php-p=contact&area=2.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498361</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498361</guid>
			<pubDate>2012-11-26T17:50:03+01:00</pubDate>
			<description><![CDATA[id:	8498361<br />first:	1353948603<br />last:	0<br />md5:	34bd5b4172bc281ca4ee4263ea5dc2da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	HTML/Rce.Gen3<br />url:	http://mavi-ambalaj.com.tr/index.php-p=contact&area=2.htm<br />recent:	up<br />response:	alive<br />ip:	37.77.4.84<br />as:	AS39582<br />review:	37.77.4.84<br />domain:	mavi-ambalaj.com.tr<br />country:	TR<br />source:	RIPE<br />email:	yusuf.alakavuk@grid.com.tr<br />inetnum:	37.77.0.0 - 37.77.31.255<br />netname:	TR-GRID-20120201<br />descr:	Grid Bilisim Teknolojileri A.S.Grid Telekom<br />ns1:	ns.grid.com.tr<br />ns2:	ns1.grid.com.tr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lotusproducts.in/cheap-economical-cotton-bags.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498358</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498358</guid>
			<pubDate>2012-11-26T17:50:02+01:00</pubDate>
			<description><![CDATA[id:	8498358<br />first:	1353948602<br />last:	0<br />md5:	8571846bd38efdf64797b027da0da4f3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8571846bd38efdf64797b027da0da4f3<br />vt_score:	17/43 (39.5%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://lotusproducts.in/cheap-economical-cotton-bags.htm<br />recent:	up<br />response:	alive<br />ip:	76.74.253.192<br />as:	AS13768<br />review:	76.74.253.192<br />domain:	lotusproducts.in<br />country:	US<br />source:	ARIN<br />email:	abuse@serverbeach.com<br />inetnum:	76.74.248.0 - 76.74.255.255<br />netname:	PEER1-SERVERBEACH-08A<br />descr:	ServerBeach SERVER-17 8500 Vicar Drive 8500, Suite 500 San Antonio TX 78218<br />ns1:	ns5.indialinks.com<br />ns2:	ns6.indialinks.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lolism.org/home.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498357</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.yk]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498357</guid>
			<pubDate>2012-11-26T17:50:02+01:00</pubDate>
			<description><![CDATA[id:	8498357<br />first:	1353948602<br />last:	0<br />md5:	a683bfb6f3b9581426dcf0b9fca4cf38<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a683bfb6f3b9581426dcf0b9fca4cf38<br />vt_score:	15/33 (45.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.yk<br />url:	http://lolism.org/home.htm<br />recent:	up<br />response:	alive<br />ip:	89.238.149.71<br />as:	as33970<br />review:	89.238.149.71<br />domain:	lolism.org<br />country:	GB<br />source:	RIPE<br />email:	abuse@openhosting.co.uk<br />inetnum:	89.238.149.0 - 89.238.149.255<br />netname:	OH-BLOCK<br />descr:	Open Hosting Ltd<br />ns1:	ns5.000025.net<br />ns2:	backupdns.000025.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kaltenschnee.de/mkw.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498136</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.QLK]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498136</guid>
			<pubDate>2012-11-26T17:20:04+01:00</pubDate>
			<description><![CDATA[id:	8498136<br />first:	1353946804<br />last:	0<br />md5:	cbac5b686fe49faa639dcccdeb9fd8ac<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cbac5b686fe49faa639dcccdeb9fd8ac<br />vt_score:	7/43 (16.3%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.QLK<br />url:	http://kaltenschnee.de/mkw.js<br />recent:	up<br />response:	alive<br />ip:	82.165.75.68<br />as:	AS8560<br />review:	82.165.75.68<br />domain:	kaltenschnee.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns2.schlund.de<br />ns2:	ns.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=83]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498065</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498065</guid>
			<pubDate>2012-11-26T17:00:05+01:00</pubDate>
			<description><![CDATA[id:	8498065<br />first:	1353945605<br />last:	0<br />md5:	d7c15a2156ee9e965780dcee05d86fde<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=83<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	d.dns.cn<br />ns2:	e.dns.cn<br />ns3:	cns.cernet.net<br />ns4:	a.dns.cn<br />ns5:	b.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=81]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498064</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498064</guid>
			<pubDate>2012-11-26T17:00:05+01:00</pubDate>
			<description><![CDATA[id:	8498064<br />first:	1353945605<br />last:	0<br />md5:	b4b9e4187e8484b02c08a16d674499b5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=81<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	d.dns.cn<br />ns2:	e.dns.cn<br />ns3:	cns.cernet.net<br />ns4:	a.dns.cn<br />ns5:	b.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=56]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498063</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498063</guid>
			<pubDate>2012-11-26T17:00:05+01:00</pubDate>
			<description><![CDATA[id:	8498063<br />first:	1353945605<br />last:	0<br />md5:	809033185c60732e8886f333f112bdb6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=57381a4eb6caf5f5254691a40f83e90e<br />vt_score:	12/35 (34.3%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=56<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	d.dns.cn<br />ns2:	e.dns.cn<br />ns3:	cns.cernet.net<br />ns4:	a.dns.cn<br />ns5:	b.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gesund-im-net.de/saint-germain.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498061</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.gns]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498061</guid>
			<pubDate>2012-11-26T17:00:05+01:00</pubDate>
			<description><![CDATA[id:	8498061<br />first:	1353945605<br />last:	0<br />md5:	b737a386879504bb4f0859430384bae5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b737a386879504bb4f0859430384bae5<br />vt_score:	10/40 (25%)<br />scanner:	avira<br />virusname:	JS/iFrame.gns<br />url:	http://gesund-im-net.de/saint-germain.jpg<br />recent:	up<br />response:	alive<br />ip:	212.162.52.180<br />as:	AS9829<br />review:	212.162.52.180<br />domain:	gesund-im-net.de<br />country:	de<br />source:	RIPE<br />email:	abuse@level3.com<br />inetnum:	212.162.52.0 - 212.162.53.255<br />netname:	SECURENETZ-DE<br />descr:	Secure-Netz<br />ns1:	ns3.nsentry.de<br />ns2:	ns4.nsentry.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://futuresystems.com.sa/kat11/byeuztj.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8498060</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.L]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8498060</guid>
			<pubDate>2012-11-26T17:00:05+01:00</pubDate>
			<description><![CDATA[id:	8498060<br />first:	1353945605<br />last:	0<br />md5:	32607f651186bf3eddea03d6adba81d4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=32607f651186bf3eddea03d6adba81d4<br />vt_score:	21/35 (60%)<br />scanner:	avira<br />virusname:	JS/Kryptik.L<br />url:	http://futuresystems.com.sa/kat11/byeuztj.js<br />recent:	up<br />response:	alive<br />ip:	74.52.152.210<br />as:	AS21844<br />review:	74.52.152.210<br />domain:	futuresystems.com.sa<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	74.52.0.0 - 74.53.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 1333 North Stemmons Freeway Suite 110 Dallas TX 75207<br />ns1:	ns1186.hostgator.com<br />ns2:	ns1185.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://elmo.bombol.pl/design/system_hello.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8497968</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8497968</guid>
			<pubDate>2012-11-26T15:50:13+01:00</pubDate>
			<description><![CDATA[id:	8497968<br />first:	1353941413<br />last:	0<br />md5:	8d636f33ab457328ff355ab08e31abfe<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8d636f33ab457328ff355ab08e31abfe<br />vt_score:	25/44 (56.8%)<br />scanner:	avira<br />virusname:	JS/Redirect.AC<br />url:	http://elmo.bombol.pl/design/system_hello.htm<br />recent:	up<br />response:	alive<br />ip:	77.79.247.160<br />as:	AS15694<br />review:	77.79.247.160<br />domain:	bombol.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@atman.pl<br />inetnum:	77.79.244.0 - 77.79.247.255<br />netname:	PROGRESO-PL<br />descr:	Progreso #1ul. 1 Maja 744-330 Jastrzebie Zdroj<br />ns1:	d.ns1.pl<br />ns2:	d.ns2.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ee.ekt.pl/templates/subsilver/overlib.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8497967</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.JS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8497967</guid>
			<pubDate>2012-11-26T15:50:13+01:00</pubDate>
			<description><![CDATA[id:	8497967<br />first:	1353941413<br />last:	0<br />md5:	1a2336c8b83c507069108f51be9e3a15<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1a2336c8b83c507069108f51be9e3a15<br />vt_score:	30/44 (68.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.JS<br />url:	http://ee.ekt.pl/templates/subsilver/overlib.js<br />recent:	up<br />response:	alive<br />ip:	62.129.199.237<br />as:	AS12824<br />review:	62.129.199.237<br />domain:	ekt.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://download.filecook.com?n=3d3dd3dx9_39.exe&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8497509</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Win32.Packer.SetupExeSection]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8497509</guid>
			<pubDate>2012-11-26T15:40:23+01:00</pubDate>
			<description><![CDATA[id:	8497509<br />first:	1353940823<br />last:	0<br />md5:	81dcce38934fce193bbbbb536a948473<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=90da2a3900572c0946d93b12cd7bf4fb<br />vt_score:	11/38 (28.9%)<br />scanner:	clamav<br />virusname:	PUA.Win32.Packer.SetupExeSection<br />url:	http://download.filecook.com?n=3d3dd3dx9_39.exe&<br />recent:	up<br />response:	alive<br />ip:	211.115.80.56<br />as:	AS3786<br />review:	211.115.80.56<br />domain:	filecook.com<br />country:	KR<br />source:	APNIC<br />email:	ip@kidc.net<br />inetnum:	211.115.64.0 - 211.115.127.255<br />netname:	KIDC-KR<br />descr:	LG DACOM KIDC<br />ns1:	ns1.smartlist.co.kr<br />ns2:	ns2.smartlist.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://czarnkow.pl/remont_basenu/index5.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8497504</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8497504</guid>
			<pubDate>2012-11-26T15:40:23+01:00</pubDate>
			<description><![CDATA[id:	8497504<br />first:	1353940823<br />last:	0<br />md5:	a50b944ce8791da4d6c822149faf57d2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://czarnkow.pl/remont_basenu/index5.html<br />recent:	up<br />response:	alive<br />ip:	212.85.119.193<br />as:	AS12824<br />review:	212.85.119.193<br />domain:	czarnkow.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.114.0 - 212.85.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bedbud.pl/galerie/colormix/index.html?detectflash=false]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8495573</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8495573</guid>
			<pubDate>2012-11-26T14:50:03+01:00</pubDate>
			<description><![CDATA[id:	8495573<br />first:	1353937803<br />last:	0<br />md5:	cd8e441cb1bd0bd89a5bd1b72b7c1401<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cd8e441cb1bd0bd89a5bd1b72b7c1401<br />vt_score:	10/35 (28.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://bedbud.pl/galerie/colormix/index.html?detectflash=false<br />recent:	up<br />response:	alive<br />ip:	91.203.134.184<br />as:	AS43333<br />review:	91.203.134.184<br />domain:	bedbud.pl<br />country:	PL<br />source:	RIPE<br />email:	biuro@nephax.com<br />inetnum:	91.203.132.0 - 91.203.135.255<br />netname:	CIS-NEPHAX<br />descr:	CIS NEPHAXCIS NEPHAX<br />ns1:	ns2.hekko.net.pl<br />ns2:	ns1.hekko.net.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wiga-kolobrzeg.pl/und-was-essen-sie-.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490733</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.76]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490733</guid>
			<pubDate>2012-11-25T17:21:58+01:00</pubDate>
			<description><![CDATA[id:	8490733<br />first:	1353860518<br />last:	0<br />md5:	f7ffcff2db618fb1ad877d6af92c9231<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=694e5f63a548f0fbd731372c2ea78661<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.76<br />url:	http://wiga-kolobrzeg.pl/und-was-essen-sie-.html<br />recent:	up<br />response:	alive<br />ip:	79.96.172.29<br />as:	AS12824<br />review:	79.96.172.29<br />domain:	wiga-kolobrzeg.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://titlein0107.bookonline.com.cn/images/ad/435_62.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490730</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490730</guid>
			<pubDate>2012-11-25T17:21:58+01:00</pubDate>
			<description><![CDATA[id:	8490730<br />first:	1353860518<br />last:	0<br />md5:	0dc4c77c7f3593fc7a584c7b10684cd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0dc4c77c7f3593fc7a584c7b10684cd2<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://titlein0107.bookonline.com.cn/images/ad/435_62.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://psychopath.neostrada.pl/str/9.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490695</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490695</guid>
			<pubDate>2012-11-25T16:52:15+01:00</pubDate>
			<description><![CDATA[id:	8490695<br />first:	1353858735<br />last:	0<br />md5:	471427ec52d88b9244323bf8499f8d87<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=471427ec52d88b9244323bf8499f8d87<br />vt_score:	17/24 (70.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://psychopath.neostrada.pl/str/9.html<br />recent:	up<br />response:	alive<br />ip:	193.110.120.7<br />as:	AS5617<br />review:	193.110.120.7<br />domain:	neostrada.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@telekomunikacja.pl<br />inetnum:	193.110.120.0 - 193.110.123.255<br />netname:	TPNET-TPI<br />descr:	tpWarszawa<br />ns1:	ns1.hosting.tp.pl<br />ns2:	ns2.hosting.tp.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pgdnuithanh.edu.vn/office/data/cv/129/129-baocaoCN.xls]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490693</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[X2000M/Laroux.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490693</guid>
			<pubDate>2012-11-25T16:52:15+01:00</pubDate>
			<description><![CDATA[id:	8490693<br />first:	1353858735<br />last:	0<br />md5:	2f73e2e023444580e476315d6324284d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f73e2e023444580e476315d6324284d<br />vt_score:	33/40 (82.5%)<br />scanner:	avira<br />virusname:	X2000M/Laroux.C<br />url:	http://pgdnuithanh.edu.vn/office/data/cv/129/129-baocaoCN.xls<br />recent:	up<br />response:	alive<br />ip:	112.213.91.95<br />as:	AS45544<br />review:	112.213.91.95<br />domain:	pgdnuithanh.edu.vn<br />country:	VN<br />source:	APNIC<br />email:	pa@pavietnam.vn<br />inetnum:	112.213.80.0 - 112.213.95.255<br />netname:	PAVIETNAM-VNNIC-VN<br />descr:	PAVIETNAM Co Ltd.254A Nguyen Dinh Chieu street,ward 6,District 3,HCMC<br />ns1:	ns-bak.matbao.com<br />ns2:	ns1.matbao.vn<br />ns3:	ns2.matbao.vn<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://krokodylek.com.pl/club/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490427</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.aav]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490427</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490427<br />first:	1353855004<br />last:	0<br />md5:	16be355f2e5c93d7ba365ab5d4e41b31<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=16be355f2e5c93d7ba365ab5d4e41b31<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.aav<br />url:	http://krokodylek.com.pl/club/<br />recent:	up<br />response:	alive<br />ip:	62.129.209.24<br />as:	AS12824<br />review:	62.129.209.24<br />domain:	krokodylek.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKenzoo.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490426</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490426</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490426<br />first:	1353855004<br />last:	0<br />md5:	151cee06b15a1f45a9fe5f6b0a887cd7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=151cee06b15a1f45a9fe5f6b0a887cd7<br />vt_score:	12/34 (35.3%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKenzoo.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdotzdaytona.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490425</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490425</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490425<br />first:	1353855004<br />last:	0<br />md5:	f78c3b5e4cc410c059ffe835292488c6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f78c3b5e4cc410c059ffe835292488c6<br />vt_score:	13/35 (37.1%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdotzdaytona.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdezenth.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490424</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490424</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490424<br />first:	1353855004<br />last:	0<br />md5:	9bac67221e7acb2143fa421da9753650<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9bac67221e7acb2143fa421da9753650<br />vt_score:	14/34 (41.2%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdezenth.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://keja.com.cn/n-page4-15.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490423</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Redlof]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490423</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490423<br />first:	1353855004<br />last:	0<br />md5:	edee58ae802bb17dc7a3fa532ddd3c90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=edee58ae802bb17dc7a3fa532ddd3c90<br />vt_score:	27/42 (64.3%)<br />scanner:	avira<br />virusname:	VBS/Redlof<br />url:	http://keja.com.cn/n-page4-15.htm<br />recent:	up<br />response:	alive<br />ip:	211.100.61.83<br />as:	AS9803<br />review:	211.100.61.83<br />domain:	keja.com.cn<br />country:	CN<br />source:	APNIC<br />email:	zhengym@bjtelecom.net<br />inetnum:	211.100.0.0 - 211.100.63.255<br />netname:	BJTEL<br />descr:	ChinaTelecom Group Beijing Ltd,CoNo.21 Chaoyangmen Beidajie,Dongcheng District,Beijing<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jpkc.nefu.edu.cn/zwx/Get/lshulike/211426845.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490422</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AGZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490422</guid>
			<pubDate>2012-11-25T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	8490422<br />first:	1353855004<br />last:	0<br />md5:	4b31ead9ffac131a215a752e8bf07c92<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4b31ead9ffac131a215a752e8bf07c92<br />vt_score:	19/44 (43.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.AGZ<br />url:	http://jpkc.nefu.edu.cn/zwx/Get/lshulike/211426845.htm<br />recent:	up<br />response:	alive<br />ip:	202.118.223.22<br />as:	AS24564<br />review:	202.118.223.22<br />domain:	nefu.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	helpdesk@apnic.net<br />inetnum:	202.0.0.0 - 203.255.255.255<br />netname:	APNIC-AP<br />descr:	Asia Pacific Network Information CentreRegional Internet Registry for the Asia-Pacific Region6 Cordelia StreetPO Box 3646South Brisbane, QLD 4101Australia<br />ns1:	ns4.nefu.edu.cn<br />ns2:	ns2.nefu.edu.cn<br />ns3:	ns3.nefu.edu.cn<br />ns4:	ns1.nefu.edu.cn<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fuss-und-pedalreisen.de/typo3conf/_img/c__ss.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490288</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490288</guid>
			<pubDate>2012-11-25T15:02:55+01:00</pubDate>
			<description><![CDATA[id:	8490288<br />first:	1353852175<br />last:	0<br />md5:	4920e0100e5fce5f7d43a3660a2eb76e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4920e0100e5fce5f7d43a3660a2eb76e<br />vt_score:	20/33 (60.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://fuss-und-pedalreisen.de/typo3conf/_img/c__ss.html<br />recent:	up<br />response:	alive<br />ip:	212.162.52.27<br />as:	AS9829<br />review:	212.162.52.27<br />domain:	fuss-und-pedalreisen.de<br />country:	de<br />source:	RIPE<br />email:	abuse@level3.com<br />inetnum:	212.162.52.0 - 212.162.53.255<br />netname:	SECURENETZ-DE<br />descr:	Secure-Netz<br />ns1:	ns02.nethosting4you.de<br />ns2:	ns04.nethosting4you.de<br />ns3:	ns03.nethosting4you.de<br />ns4:	ns01.nethosting4you.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://erkelmuvhaz.hu/imsitemap.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490287</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490287</guid>
			<pubDate>2012-11-25T15:02:55+01:00</pubDate>
			<description><![CDATA[id:	8490287<br />first:	1353852175<br />last:	0<br />md5:	13ce22e6ad3b40266d670c40a4fa4d99<br />virustotal:	<br />vt_score:	18/34 (52.9%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://erkelmuvhaz.hu/imsitemap.html<br />recent:	up<br />response:	alive<br />ip:	81.0.104.141<br />as:	AS12301<br />review:	81.0.104.141<br />domain:	erkelmuvhaz.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@invitel.net<br />inetnum:	81.0.104.0 - 81.0.104.255<br />netname:	VTH<br />descr:	Datacenter Hosting Internet<br />ns1:	ns2.interlink.hu<br />ns2:	ns1.interlink.hu<br />ns3:	ns0.interlink.hu<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://121.10.105.29:85/tt/2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490045</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490045</guid>
			<pubDate>2012-11-25T13:11:54+01:00</pubDate>
			<description><![CDATA[id:	8490045<br />first:	1353845514<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://121.10.105.29:85/tt/2.exe<br />recent:	up<br />response:	alive<br />ip:	121.10.105.29<br />as:	AS4134<br />review:	121.10.105.29<br />domain:	121.10.105.29<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	121.8.0.0 - 121.15.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://121.10.105.29:85/tt/0.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8490044</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8490044</guid>
			<pubDate>2012-11-25T13:11:54+01:00</pubDate>
			<description><![CDATA[id:	8490044<br />first:	1353845514<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://121.10.105.29:85/tt/0.exe<br />recent:	up<br />response:	alive<br />ip:	121.10.105.29<br />as:	AS4134<br />review:	121.10.105.29<br />domain:	121.10.105.29<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	121.8.0.0 - 121.15.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lemassifforestierngoyla-mintom.org]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8489053</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8489053</guid>
			<pubDate>2012-11-25T09:20:02+01:00</pubDate>
			<description><![CDATA[id:	8489053<br />first:	1353831602<br />last:	0<br />md5:	3e807f9faad5dc96011502a526c8c1a5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3e807f9faad5dc96011502a526c8c1a5<br />vt_score:	0/36 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/Rce.Gen3<br />url:	http://lemassifforestierngoyla-mintom.org<br />recent:	up<br />response:	alive<br />ip:	74.81.82.162<br />as:	AS27413<br />review:	74.81.82.162<br />domain:	lemassifforestierngoyla-mintom.org<br />country:	US<br />source:	ARIN<br />email:	abuse@gnax.net<br />inetnum:	74.81.64.0 - 74.81.95.255<br />netname:	GNAXNET<br />descr:	Global Net Access, LLC GNAL-2 1100 White St SW Atlanta GA 30310<br />ns1:	ns2.webhostingwax.com<br />ns2:	ns1.webhostingwax.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://xunwei2.3322.org:81/soft/cclserver.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485685</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Hupigon.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485685</guid>
			<pubDate>2012-11-24T19:40:04+01:00</pubDate>
			<description><![CDATA[id:	8485685<br />first:	1353782404<br />last:	0<br />md5:	68b329da9893e34099c7d8ad5cb9c940<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d92feefb4ad86f8f675624ff20e2b40c<br />vt_score:	21/44 (47.7%)<br />scanner:	avira<br />virusname:	BDS/Hupigon.Gen<br />url:	http://xunwei2.3322.org:81/soft/cclserver.exe<br />recent:	up<br />response:	alive<br />ip:	58.54.19.239<br />as:	AS4134<br />review:	221.5.133.18<br />domain:	3322.org<br />country:	CN<br />source:	APNIC<br />email:	abuse@chinaunicom.cn<br />inetnum:	58.48.0.0 - 58.55.255.255<br />netname:	UNICOM-CQ<br />descr:	China Unicom Chongqing province networkChina UnicomCNC Group CHINA169 Chongqing Province Network<br />ns1:	ns1.3322.net<br />ns2:	ns2.3322.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wiga-kolobrzeg.pl/zimmer.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485650</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.76]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485650</guid>
			<pubDate>2012-11-24T19:30:04+01:00</pubDate>
			<description><![CDATA[id:	8485650<br />first:	1353781804<br />last:	0<br />md5:	2a85431a2a7078949d0f24a3dc3096eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=db1bf1d95422e277411091fcfb7b5300<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.76<br />url:	http://wiga-kolobrzeg.pl/zimmer.html<br />recent:	up<br />response:	alive<br />ip:	79.96.172.29<br />as:	AS12824<br />review:	79.96.172.29<br />domain:	wiga-kolobrzeg.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wangyang.com.cn/jianjie.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485647</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.AP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485647</guid>
			<pubDate>2012-11-24T19:30:04+01:00</pubDate>
			<description><![CDATA[id:	8485647<br />first:	1353781804<br />last:	0<br />md5:	e455ce1b64a34a7b44539e25002f6cde<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e455ce1b64a34a7b44539e25002f6cde<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	HTML/IFrame.AP<br />url:	http://wangyang.com.cn/jianjie.htm<br />recent:	up<br />response:	alive<br />ip:	211.100.61.82<br />as:	AS9803<br />review:	211.100.61.82<br />domain:	wangyang.com.cn<br />country:	CN<br />source:	APNIC<br />email:	zhengym@bjtelecom.net<br />inetnum:	211.100.0.0 - 211.100.63.255<br />netname:	BJTEL<br />descr:	ChinaTelecom Group Beijing Ltd,CoNo.21 Chaoyangmen Beidajie,Dongcheng District,Beijing<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pugeograf.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485277</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.SR.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485277</guid>
			<pubDate>2012-11-24T17:50:02+01:00</pubDate>
			<description><![CDATA[id:	8485277<br />first:	1353775802<br />last:	0<br />md5:	6fa99a0e01b3c5018508c8c0d8a67ad4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6fa99a0e01b3c5018508c8c0d8a67ad4<br />vt_score:	8/35 (22.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.SR.1<br />url:	http://pugeograf.pl/<br />recent:	up<br />response:	alive<br />ip:	91.234.217.10<br />as:	AS198453<br />review:	91.234.217.10<br />domain:	pugeograf.pl<br />country:	PL<br />source:	RIPE<br />email:	andrzej@kastelik.pl<br />inetnum:	91.234.217.0 - 91.234.217.255<br />netname:	jee-pl<br />descr:	Firma Uslugowo-Handlowa JEE.PL Kastelik Krzysztof<br />ns1:	dnsa.boo.pl<br />ns2:	dnsb.boo.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mdqvoley.com.ar/diccionario.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485271</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Virut.AI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485271</guid>
			<pubDate>2012-11-24T17:50:02+01:00</pubDate>
			<description><![CDATA[id:	8485271<br />first:	1353775802<br />last:	0<br />md5:	7acaaeae891b37ea670d939b122199ff<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7acaaeae891b37ea670d939b122199ff<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	HTML/Virut.AI<br />url:	http://mdqvoley.com.ar/diccionario.htm<br />recent:	up<br />response:	alive<br />ip:	200.58.115.15<br />as:	ASNA.200.58.112.0 - 200.58.127.255<br />review:	200.58.115.15<br />domain:	mdqvoley.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	ipmaster@hostmar.com<br />inetnum:	200.58.112.0 - 200.58.127.255<br />netname:	AR-DATT-LACNIC<br />descr:	Dattatec.comCordoba, 3753,2000 - Rosario - SFCordoba, 3753,2000 - Rosario - SF<br />ns1:	ns4.hostmar.com<br />ns2:	ns3.hostmar.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://macatawa.org/~hhcrc/mssn/thielkeinfo.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485269</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485269</guid>
			<pubDate>2012-11-24T17:50:02+01:00</pubDate>
			<description><![CDATA[id:	8485269<br />first:	1353775802<br />last:	0<br />md5:	cbb1b1d96b46c0aa676cd787258f8aa7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cbb1b1d96b46c0aa676cd787258f8aa7<br />vt_score:	34/44 (77.3%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://macatawa.org/~hhcrc/mssn/thielkeinfo.html<br />recent:	up<br />response:	alive<br />ip:	204.177.184.101<br />as:	AS4208<br />review:	204.177.184.101<br />domain:	macatawa.org<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	204.176.0.0 - 204.179.255.255<br />netname:	UUNETCBLK176-179<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns.macatawa.org<br />ns2:	ns3.macatawa.org<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/HISTORYuniroyal.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8485101</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8485101</guid>
			<pubDate>2012-11-24T16:30:55+01:00</pubDate>
			<description><![CDATA[id:	8485101<br />first:	1353771055<br />last:	0<br />md5:	a04944581c6b38069622fd7e6d061bf7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a04944581c6b38069622fd7e6d061bf7<br />vt_score:	12/35 (34.3%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/HISTORYuniroyal.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ibericaphp.es/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8484876</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.brb.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8484876</guid>
			<pubDate>2012-11-24T16:00:06+01:00</pubDate>
			<description><![CDATA[id:	8484876<br />first:	1353769206<br />last:	0<br />md5:	ff8cc73a587cbff812e893b9d966400a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ff8cc73a587cbff812e893b9d966400a<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.brb.2<br />url:	http://ibericaphp.es/<br />recent:	up<br />response:	alive<br />ip:	82.98.146.8<br />as:	AS42612<br />review:	82.98.146.8<br />domain:	ibericaphp.es<br />country:	ES<br />source:	RIPE<br />email:	ripe@dinahosting.com<br />inetnum:	82.98.146.0 - 82.98.146.255<br />netname:	DH-J2-NET3<br />descr:	Dinahosting Subred 3J2Dinahosting S.L. prefix<br />ns1:	ns4.dinahosting.com<br />ns2:	ns2.dinahosting.com<br />ns3:	ns.dinahosting.com<br />ns4:	ns3.dinahosting.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gerjenidunarock.hu/border.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8484873</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Exploit-Blacole.gg]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8484873</guid>
			<pubDate>2012-11-24T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8484873<br />first:	1353768602<br />last:	0<br />md5:	1f0a2325d12106a56a7ae5d8a11445b1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f0a2325d12106a56a7ae5d8a11445b1<br />vt_score:	3/36 (8.3%)<br />scanner:	McAfee<br />virusname:	JS/Exploit-Blacole.gg<br />url:	http://gerjenidunarock.hu/border.htm<br />recent:	up<br />response:	alive<br />ip:	209.239.116.173<br />as:	AS30083<br />review:	5.56.34.59<br />domain:	gerjenidunarock.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@hostingsolutionsint.com<br />inetnum:	209.239.112.0 - 209.239.127.255<br />netname:	S4Y-3<br />descr:	Hosting Solutions International, Inc. SERVE-6 710 North Tucker Blvd. Suite 400a Saint Louis MO 63101<br />ns1:	ns1.iworx-host.com<br />ns2:	ns2.iworx-host.com<br />ns3:	ns3.iworx-host.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://8.duote.org/driver/soundsetup.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8484485</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8484485</guid>
			<pubDate>2012-11-24T14:30:02+01:00</pubDate>
			<description><![CDATA[id:	8484485<br />first:	1353763802<br />last:	0<br />md5:	4c9d3d914f2b6e5fbc1680110fc8e937<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://8.duote.org/driver/soundsetup.zip<br />recent:	up<br />response:	alive<br />ip:	218.75.14.90<br />as:	AS4134<br />review:	218.75.14.90<br />domain:	duote.org<br />country:	CN<br />source:	APNIC<br />email:	antispam@dcb.hz.zj.cn<br />inetnum:	218.75.0.0 - 218.75.15.255<br />netname:	CHINANET-ZJ-TZ<br />descr:	CHINANET-ZJ Taizhou node networkZhejiang Telecom<br />ns1:	dns1.kabasiji.com<br />ns2:	dns3.50bang.org<br />ns3:	dns2.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yunus.hacettepe.edu.tr/~suayip06/BTO418_Final/ykb.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8481199</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.73]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8481199</guid>
			<pubDate>2012-11-23T21:50:03+01:00</pubDate>
			<description><![CDATA[id:	8481199<br />first:	1353703803<br />last:	0<br />md5:	a852b6cc8ffb3757f8370ab93235ffad<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6e47b15ef24abe5d5dc2d12bf521e1b9<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.73<br />url:	http://yunus.hacettepe.edu.tr/~suayip06/BTO418_Final/ykb.html<br />recent:	up<br />response:	alive<br />ip:	193.140.216.9<br />as:	AS8517<br />review:	193.140.216.9<br />domain:	hacettepe.edu.tr<br />country:	TR<br />source:	RIPE<br />email:	csirt@ulakbim.gov.tr<br />inetnum:	193.140.216.0 - 193.140.223.255<br />netname:	HACETTEPE-NET<br />descr:	Hacettepe UniversityAnkaraULAKNETHacettepe University<br />ns1:	ns04.hacettepe.edu.tr<br />ns2:	ns01.hacettepe.edu.tr<br />ns3:	ns02.hacettepe.edu.tr<br />ns4:	ns03.hacettepe.edu.tr<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yunus.hacettepe.edu.tr/~suayip06/BTO418_Final/ovk.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8481198</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.73]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8481198</guid>
			<pubDate>2012-11-23T21:50:02+01:00</pubDate>
			<description><![CDATA[id:	8481198<br />first:	1353703802<br />last:	0<br />md5:	f2b1d2b7adc2b72df5349577f5cb50c2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a95746fee27943ad2896277731195dbd<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.73<br />url:	http://yunus.hacettepe.edu.tr/~suayip06/BTO418_Final/ovk.html<br />recent:	up<br />response:	alive<br />ip:	193.140.216.9<br />as:	AS8517<br />review:	193.140.216.9<br />domain:	hacettepe.edu.tr<br />country:	TR<br />source:	RIPE<br />email:	csirt@ulakbim.gov.tr<br />inetnum:	193.140.216.0 - 193.140.223.255<br />netname:	HACETTEPE-NET<br />descr:	Hacettepe UniversityAnkaraULAKNETHacettepe University<br />ns1:	ns04.hacettepe.edu.tr<br />ns2:	ns01.hacettepe.edu.tr<br />ns3:	ns02.hacettepe.edu.tr<br />ns4:	ns03.hacettepe.edu.tr<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wyx16888.bookonline.com.cn/images/ad/435_62.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8480815</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8480815</guid>
			<pubDate>2012-11-23T21:00:05+01:00</pubDate>
			<description><![CDATA[id:	8480815<br />first:	1353700805<br />last:	0<br />md5:	0dc4c77c7f3593fc7a584c7b10684cd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0dc4c77c7f3593fc7a584c7b10684cd2<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://wyx16888.bookonline.com.cn/images/ad/435_62.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tuentel.de/wp-content/themes/twentyeleven/style.css]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8480751</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/WebShell.A.80]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8480751</guid>
			<pubDate>2012-11-23T20:40:27+01:00</pubDate>
			<description><![CDATA[id:	8480751<br />first:	1353699627<br />last:	0<br />md5:	b34c3c697d2ac328e4fb5103e0cb5d5f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b34c3c697d2ac328e4fb5103e0cb5d5f<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	PHP/WebShell.A.80<br />url:	http://tuentel.de/wp-content/themes/twentyeleven/style.css<br />recent:	up<br />response:	alive<br />ip:	176.28.16.46<br />as:	AS20773<br />review:	176.28.16.46<br />domain:	tuentel.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	176.28.16.0 - 176.28.23.255<br />netname:	DE-HE-LVPS-176-28-16-NET<br />descr:	Hosteurope GmbHnoc@hosteurope.de<br />ns1:	ns1.hans.hosteurope.de<br />ns2:	ns2.hans.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tem97.org/super-old/member/yanik/i_am.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479510</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479510</guid>
			<pubDate>2012-11-23T20:10:27+01:00</pubDate>
			<description><![CDATA[id:	8479510<br />first:	1353697827<br />last:	0<br />md5:	60ddc00b45c5cdebc5c3443691ff87a8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=60ddc00b45c5cdebc5c3443691ff87a8<br />vt_score:	19/44 (43.2%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://tem97.org/super-old/member/yanik/i_am.html<br />recent:	up<br />response:	alive<br />ip:	209.172.44.134<br />as:	AS32613<br />review:	209.172.44.134<br />domain:	tem97.org<br />country:	CA<br />source:	ARIN<br />email:	abuse@noc.privatedns.com<br />inetnum:	209.172.32.0 - 209.172.63.255<br />netname:	IWEB-BLK-01<br />descr:	iWeb Technologies Inc. GIT-20 20, place du Commerce Montreal QC H3E-1Z6<br />ns1:	ns1.yourtal.com<br />ns2:	ns2.yourtal.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://teelanovela.de/alte%20schule/tc/7.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479509</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479509</guid>
			<pubDate>2012-11-23T20:10:27+01:00</pubDate>
			<description><![CDATA[id:	8479509<br />first:	1353697827<br />last:	0<br />md5:	3462cd6dafda25e6d8c29e46d5ef873a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3462cd6dafda25e6d8c29e46d5ef873a<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://teelanovela.de/alte%20schule/tc/7.htm<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	teelanovela.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://teelanovela.de/alte%20schule/tc/4.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479508</guid>
			<pubDate>2012-11-23T20:10:27+01:00</pubDate>
			<description><![CDATA[id:	8479508<br />first:	1353697827<br />last:	0<br />md5:	51b7238e6391c0f153abd421caebb408<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=51b7238e6391c0f153abd421caebb408<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://teelanovela.de/alte%20schule/tc/4.htm<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	teelanovela.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://teelanovela.de/alte%20schule/tc/3.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479507</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479507</guid>
			<pubDate>2012-11-23T20:10:27+01:00</pubDate>
			<description><![CDATA[id:	8479507<br />first:	1353697827<br />last:	0<br />md5:	2e14f05f4b0d8e366898f64906fbcfc6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2e14f05f4b0d8e366898f64906fbcfc6<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://teelanovela.de/alte%20schule/tc/3.htm<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	teelanovela.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://spreekuurpsycholoog.nl/discus/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479504</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Clicker.G.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479504</guid>
			<pubDate>2012-11-23T20:10:26+01:00</pubDate>
			<description><![CDATA[id:	8479504<br />first:	1353697826<br />last:	0<br />md5:	d2cad26735bf9dc8d1640546942c5065<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d2cad26735bf9dc8d1640546942c5065<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	JS/Clicker.G.1<br />url:	http://spreekuurpsycholoog.nl/discus/<br />recent:	up<br />response:	alive<br />ip:	85.17.203.139<br />as:	AS16265<br />review:	85.17.203.139<br />domain:	spreekuurpsycholoog.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	85.17.0.0 - 85.17.255.255<br />netname:	NL-LEASEWEB-20050311<br />descr:	LeaseWeb B.V.LEASEWEB<br />ns1:	ns1.secure-services.nl<br />ns2:	ns2.secure-services.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sgnv.de/impressum.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479290</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479290</guid>
			<pubDate>2012-11-23T19:50:03+01:00</pubDate>
			<description><![CDATA[id:	8479290<br />first:	1353696603<br />last:	0<br />md5:	c64f3deda2c487798125faf0ae1f419f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c64f3deda2c487798125faf0ae1f419f<br />vt_score:	0/36 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/Rce.Gen3<br />url:	http://sgnv.de/impressum.html<br />recent:	up<br />response:	alive<br />ip:	83.220.144.13<br />as:	AS25074<br />review:	83.220.144.13<br />domain:	sgnv.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@inetbone.net<br />inetnum:	83.220.144.0 - 83.220.144.255<br />netname:	DE-SPEICHERHOSTING<br />descr:	SpeicherhostingCustomer PA Space<br />ns1:	ns3.ns1-tech.de<br />ns2:	ns2.ns1-tech.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://priveclub.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479201</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479201</guid>
			<pubDate>2012-11-23T19:30:02+01:00</pubDate>
			<description><![CDATA[id:	8479201<br />first:	1353695402<br />last:	0<br />md5:	bc6e683ef5f31f70bb907378bfa5c2bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bc6e683ef5f31f70bb907378bfa5c2bc<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://priveclub.de/<br />recent:	up<br />response:	alive<br />ip:	85.214.55.54<br />as:	AS6724<br />review:	85.214.55.54<br />domain:	priveclub.de<br />country:	DE<br />source:	RIPE<br />email:	abuse-server@strato.de<br />inetnum:	85.214.16.0 - 85.214.139.255<br />netname:	STRATO-RZG-DED2<br />descr:	Strato Rechenzentrum, Berlin<br />ns1:	ns.stratoserver.net<br />ns2:	ns2.stratoserver.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://planetpeace.ws/index.asp?id=30]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8479199</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.hhd]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8479199</guid>
			<pubDate>2012-11-23T19:30:02+01:00</pubDate>
			<description><![CDATA[id:	8479199<br />first:	1353695402<br />last:	0<br />md5:	d22bcc9e195d6ce08d0e02b0bff25873<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2fc2431f13a801e705caf5c7f14e02c8<br />vt_score:	9/35 (25.7%)<br />scanner:	avira<br />virusname:	JS/Agent.hhd<br />url:	http://planetpeace.ws/index.asp?id=30<br />recent:	up<br />response:	alive<br />ip:	216.119.79.243<br />as:	AS14992<br />review:	216.119.79.243<br />domain:	planetpeace.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@crystaltech.com<br />inetnum:	216.119.64.0 - 216.119.127.255<br />netname:	CRYSTALTECH-BLK-1<br />descr:	CrystalTech Web Hosting Inc. CRTW 1125 W. Pinnacle Peak Road, Suite 103 Phoenix AZ 85027<br />ns1:	ns4.webcontrolcenter.com<br />ns2:	ns3.webcontrolcenter.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://personales.mundivia.es/villoslada/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478794</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.gkb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478794</guid>
			<pubDate>2012-11-23T18:50:31+01:00</pubDate>
			<description><![CDATA[id:	8478794<br />first:	1353693031<br />last:	0<br />md5:	93a172f4f2b8135f6aa6301c278a2c5d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=93a172f4f2b8135f6aa6301c278a2c5d<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Agent.gkb<br />url:	http://personales.mundivia.es/villoslada/<br />recent:	up<br />response:	alive<br />ip:	62.13.225.14<br />as:	AS24856<br />review:	62.13.225.14<br />domain:	mundivia.es<br />country:	ES<br />source:	RIPE<br />email:	administracion@mundivia.net<br />inetnum:	62.13.224.0 - 62.13.232.255<br />netname:	MUNDIVIA<br />descr:	Mundivia S.A.PROVIDER LIRMundivia<br />ns1:	ns1.mundivia.es<br />ns2:	ns2.mundivia.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/components/com_jomcomment/script.js?]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478793</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478793</guid>
			<pubDate>2012-11-23T18:50:31+01:00</pubDate>
			<description><![CDATA[id:	8478793<br />first:	1353693031<br />last:	0<br />md5:	d46a5558ba8655d2806a2bb1af0ae5bd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d46a5558ba8655d2806a2bb1af0ae5bd<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/components/com_jomcomment/script.js?<br />recent:	up<br />response:	alive<br />ip:	62.149.128.74<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pacc.info/news-more.asp?newsid=40]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478791</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Redirector.CA.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478791</guid>
			<pubDate>2012-11-23T18:50:03+01:00</pubDate>
			<description><![CDATA[id:	8478791<br />first:	1353693003<br />last:	0<br />md5:	030bf7cb26a34ca5870d41e6b2fc36f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d0e8f3cddec296894d5a6f53d7ba6c6<br />vt_score:	15/43 (34.9%)<br />scanner:	undef<br />virusname:	HTML/Redirector.CA.1<br />url:	http://pacc.info/news-more.asp?newsid=40<br />recent:	up<br />response:	alive<br />ip:	64.64.214.138<br />as:	AS1616<br />review:	64.64.214.138<br />domain:	pacc.info<br />country:	US<br />source:	ARIN<br />email:	ipadmin@corelink.com<br />inetnum:	64.64.214.128 - 64.64.214.159<br />netname:	LAS01-SUBSTREAM-001<br />descr:	5858 S. Pecos Rd. Suite 400a Las Vegas NV 89120<br />ns1:	ns2.substorm.com<br />ns2:	ns1.substorm.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ozbb.info/1/malware/remove-spyware-spyfalcon/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478790</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.ooo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478790</guid>
			<pubDate>2012-11-23T18:50:03+01:00</pubDate>
			<description><![CDATA[id:	8478790<br />first:	1353693003<br />last:	0<br />md5:	4889d743c830e98705633ce0792d9aa5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4889d743c830e98705633ce0792d9aa5<br />vt_score:	32/44 (72.7%)<br />scanner:	avira<br />virusname:	HTML/IFrame.ooo<br />url:	http://ozbb.info/1/malware/remove-spyware-spyfalcon/index.html<br />recent:	up<br />response:	alive<br />ip:	64.90.56.55<br />as:	AS26347<br />review:	64.90.56.55<br />domain:	ozbb.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	64.90.32.0 - 64.90.63.255<br />netname:	DREAMHOST-BLK10<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mussi.com.br/pt/consultoriac.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478559</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478559</guid>
			<pubDate>2012-11-23T18:20:04+01:00</pubDate>
			<description><![CDATA[id:	8478559<br />first:	1353691204<br />last:	0<br />md5:	47c9036f3d6c79cd7cddadb5fd0b3fd7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=47c9036f3d6c79cd7cddadb5fd0b3fd7<br />vt_score:	28/44 (63.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://mussi.com.br/pt/consultoriac.htm<br />recent:	up<br />response:	alive<br />ip:	189.38.80.92<br />as:	AS28299<br />review:	189.38.80.92<br />domain:	mussi.com.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@kinghost.com.br<br />inetnum:	189.38.80.0 - 189.38.95.255<br />netname:	005.305.671/0001-84<br />descr:	Cyberweb Networks Ltda<br />ns1:	dns2.kinghost.com.br<br />ns2:	dns5.kinghost.com.br<br />ns3:	dns3.kinghost.com.br<br />ns4:	dns1.kinghost.com.br<br />ns5:	dns4.kinghost.com.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mercede.info/italiano/laici/cavalieri/cavalieri.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478558</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478558</guid>
			<pubDate>2012-11-23T18:20:04+01:00</pubDate>
			<description><![CDATA[id:	8478558<br />first:	1353691204<br />last:	0<br />md5:	7be266c72ffba332b5ba3ad706ec93c8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7be266c72ffba332b5ba3ad706ec93c8<br />vt_score:	23/42 (54.8%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://mercede.info/italiano/laici/cavalieri/cavalieri.htm<br />recent:	up<br />response:	alive<br />ip:	98.131.160.1<br />as:	AS32392<br />review:	98.131.160.1<br />domain:	mercede.info<br />country:	US<br />source:	ARIN<br />email:	ipadmin@ecommerce.com<br />inetnum:	98.130.0.0 - 98.131.255.255<br />netname:	ECOMMERCE-HOSTING<br />descr:	Ecommerce Corporation ECOMM-5 1774 Dividend Dr Columbus OH 43228<br />ns1:	dns1.videobank.it<br />ns2:	dns2.videobank.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://members.liwest.at/bock/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478557</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.uer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478557</guid>
			<pubDate>2012-11-23T18:20:04+01:00</pubDate>
			<description><![CDATA[id:	8478557<br />first:	1353691204<br />last:	0<br />md5:	31ef2a288ee14bb4684f2e3d7794aa63<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=31ef2a288ee14bb4684f2e3d7794aa63<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	HTML/IFrame.uer<br />url:	http://members.liwest.at/bock/<br />recent:	up<br />response:	alive<br />ip:	212.33.32.142<br />as:	AS12605<br />review:	212.33.32.142<br />domain:	liwest.at<br />country:	AT<br />source:	RIPE<br />email:	abuse@liwest.at<br />inetnum:	212.33.32.0 - 212.33.36.255<br />netname:	AT-LIWEST-INTERN<br />descr:	Internal<br />ns1:	ns2.liwest.at<br />ns2:	ns1.liwest.at<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://light048.com.ne.kr/art-2-03.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478354</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Changeset.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478354</guid>
			<pubDate>2012-11-23T17:41:06+01:00</pubDate>
			<description><![CDATA[id:	8478354<br />first:	1353688866<br />last:	0<br />md5:	9725e4db08cb636306e3e40343173c81<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9725e4db08cb636306e3e40343173c81<br />vt_score:	34/36 (94.4%)<br />scanner:	avira<br />virusname:	VBS/Changeset.A<br />url:	http://light048.com.ne.kr/art-2-03.htm<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ipepe.org/artigos_5s_na_pratica.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478180</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Dldr.Psyme.mq]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478180</guid>
			<pubDate>2012-11-23T17:30:05+01:00</pubDate>
			<description><![CDATA[id:	8478180<br />first:	1353688205<br />last:	0<br />md5:	3aa41ac6cc4e43a5fd711ae8a3896c4a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3aa41ac6cc4e43a5fd711ae8a3896c4a<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/Dldr.Psyme.mq<br />url:	http://ipepe.org/artigos_5s_na_pratica.htm<br />recent:	up<br />response:	alive<br />ip:	189.38.90.61<br />as:	AS28299<br />review:	189.38.90.61<br />domain:	ipepe.org<br />country:	BR<br />source:	LACNIC<br />email:	abuse@kinghost.com.br<br />inetnum:	189.38.80.0 - 189.38.95.255<br />netname:	005.305.671/0001-84<br />descr:	Cyberweb Networks Ltda<br />ns1:	dns1.powempresas.com.br<br />ns2:	dns2.powempresas.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://heart-transplant.org/objectives/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478085</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478085</guid>
			<pubDate>2012-11-23T17:00:09+01:00</pubDate>
			<description><![CDATA[id:	8478085<br />first:	1353686409<br />last:	0<br />md5:	ecef6424cbee23023f2e8f1abe94d79f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ecef6424cbee23023f2e8f1abe94d79f<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://heart-transplant.org/objectives/<br />recent:	up<br />response:	alive<br />ip:	69.73.140.107<br />as:	AS3595<br />review:	69.73.168.216<br />domain:	heart-transplant.org<br />country:	US<br />source:	ARIN<br />email:	abuse@jaguarpc.com<br />inetnum:	69.73.128.0 - 69.73.191.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns.nocdirect.com<br />ns2:	ns2.nocdirect.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://granitko.hu/index-5.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478082</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478082</guid>
			<pubDate>2012-11-23T17:00:08+01:00</pubDate>
			<description><![CDATA[id:	8478082<br />first:	1353686408<br />last:	0<br />md5:	3d7da96e50e0d8ddcb9cd5ef7025b0d5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3d7da96e50e0d8ddcb9cd5ef7025b0d5<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://granitko.hu/index-5.html<br />recent:	up<br />response:	alive<br />ip:	87.229.26.125<br />as:	AS29278<br />review:	87.229.26.125<br />domain:	granitko.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@deninet.hu<br />inetnum:	87.229.26.0 - 87.229.26.255<br />netname:	Deninet-HU<br />descr:	Deninet serverhostingDeninet Ltd.<br />ns1:	ns2.dataglobe.hu<br />ns2:	ns0.dataglobe.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fuss-und-pedalreisen.de/typo3conf/_img/closen.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478079</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478079</guid>
			<pubDate>2012-11-23T17:00:08+01:00</pubDate>
			<description><![CDATA[id:	8478079<br />first:	1353686408<br />last:	0<br />md5:	895827fe044874edf6498eb06268b144<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=895827fe044874edf6498eb06268b144<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://fuss-und-pedalreisen.de/typo3conf/_img/closen.html<br />recent:	up<br />response:	alive<br />ip:	212.162.52.27<br />as:	AS9829<br />review:	212.162.52.27<br />domain:	fuss-und-pedalreisen.de<br />country:	de<br />source:	RIPE<br />email:	abuse@level3.com<br />inetnum:	212.162.52.0 - 212.162.53.255<br />netname:	SECURENETZ-DE<br />descr:	Secure-Netz<br />ns1:	ns02.nethosting4you.de<br />ns2:	ns01.nethosting4you.de<br />ns3:	ns03.nethosting4you.de<br />ns4:	ns04.nethosting4you.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enduropage.de/zettisch/DSCF1236.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478075</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478075</guid>
			<pubDate>2012-11-23T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	8478075<br />first:	1353686407<br />last:	0<br />md5:	1f1194cafb9b2ab316c408e198ca61ca<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1f1194cafb9b2ab316c408e198ca61ca<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://enduropage.de/zettisch/DSCF1236.html<br />recent:	up<br />response:	alive<br />ip:	212.12.119.22<br />as:	AS12595<br />review:	212.12.119.22<br />domain:	enduropage.de<br />country:	DE<br />source:	RIPE<br />email:	s.willing@mops.net<br />inetnum:	212.12.119.0 - 212.12.119.127<br />netname:	DE-APACHEHOST-NET2<br />descr:	APACHEHOST Tim Hinterlandhttpmops.net<br />ns1:	dns.dns1.de<br />ns2:	dns.dns2.de<br />ns3:	dns.dns3.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://endorphin-junkies.at/Fotogalerie_x-mas_tree/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478074</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HEUR/HTML.Malware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478074</guid>
			<pubDate>2012-11-23T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	8478074<br />first:	1353686407<br />last:	0<br />md5:	284e43dc7f97f7dcbaa18c8abe216857<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=284e43dc7f97f7dcbaa18c8abe216857<br />vt_score:	16/35 (45.7%)<br />scanner:	AntiVir<br />virusname:	HEUR/HTML.Malware<br />url:	http://endorphin-junkies.at/Fotogalerie_x-mas_tree/index.htm<br />recent:	up<br />response:	alive<br />ip:	195.206.98.50<br />as:	AS8339<br />review:	195.206.98.50<br />domain:	endorphin-junkies.at<br />country:	AT<br />source:	RIPE<br />email:	chris@streams.at<br />inetnum:	195.206.96.0 - 195.206.103.255<br />netname:	STREAMS<br />descr:	Streams Telecommunicationsservices GmbHUniversitaetsstrasse 10/7A-1090 WienAustriaStreams via Kabelsignal AGStreams via Kabelsignal AG<br />ns1:	motor.endorphin-junkies.at<br />ns2:	rotor.endorphin-junkies.at<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://emmasphere.co.uk/home.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478073</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.DB.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478073</guid>
			<pubDate>2012-11-23T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	8478073<br />first:	1353686407<br />last:	0<br />md5:	821fb73327c52dfa7b94bf6581703837<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=821fb73327c52dfa7b94bf6581703837<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Redirector.DB.5<br />url:	http://emmasphere.co.uk/home.asp<br />recent:	up<br />response:	alive<br />ip:	212.227.26.20<br />as:	AS8560<br />review:	212.227.26.20<br />domain:	emmasphere.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.20.0 - 212.227.29.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AG<br />ns1:	ns45.1and1.co.uk<br />ns2:	ns46.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dynpos.co.uk/js/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8478072</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8478072</guid>
			<pubDate>2012-11-23T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	8478072<br />first:	1353686407<br />last:	0<br />md5:	308fd0efefdae78675ca77cb0f63f40d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=308fd0efefdae78675ca77cb0f63f40d<br />vt_score:	25/42 (59.5%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://dynpos.co.uk/js/jquery.js<br />recent:	up<br />response:	alive<br />ip:	217.154.103.34<br />as:	AS8897<br />review:	217.154.103.34<br />domain:	dynpos.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@mistral.net<br />inetnum:	217.154.0.0 - 217.154.255.255<br />netname:	UK-MISTRAL-20010219<br />descr:	Mistral Internet<br />ns1:	bison.kingston-internet.co.uk<br />ns2:	ibex.kingston-internet.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://clients.wm.co.za/20030292/contact.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8477427</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML_IFRAME.DDI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8477427</guid>
			<pubDate>2012-11-23T15:30:15+01:00</pubDate>
			<description><![CDATA[id:	8477427<br />first:	1353681015<br />last:	0<br />md5:	226115b63f42096265147b2d2fbadcf7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=226115b63f42096265147b2d2fbadcf7<br />vt_score:	31/44 (70.5%)<br />scanner:	trendmicro<br />virusname:	HTML_IFRAME.DDI<br />url:	http://clients.wm.co.za/20030292/contact.htm<br />recent:	up<br />response:	alive<br />ip:	196.41.214.135<br />as:	AS11845<br />review:	196.41.214.135<br />domain:	wm.co.za<br />country:	ZA<br />source:	AFRINIC<br />email:	abuse@datapro.co.za<br />inetnum:	196.41.192.0 - 196.41.223.255<br />netname:	GIA-BLK6<br />descr:	Global Internet AccessBlock B Rutherford Estate1 Scott StreetWaverlyGauteng2090<br />ns1:	ns2.mailbox.co.za<br />ns2:	ns1.mailbox.co.za<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://chinawood.org/news_e/news/02117.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8477426</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.CF.82256]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8477426</guid>
			<pubDate>2012-11-23T15:30:15+01:00</pubDate>
			<description><![CDATA[id:	8477426<br />first:	1353681015<br />last:	0<br />md5:	fb72634cd73908879f3624606cffe11e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fb72634cd73908879f3624606cffe11e<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	JS/Agent.CF.82256<br />url:	http://chinawood.org/news_e/news/02117.html<br />recent:	up<br />response:	alive<br />ip:	118.192.19.216<br />as:	AS18245<br />review:	118.192.19.216<br />domain:	chinawood.org<br />country:	CN<br />source:	APNIC<br />email:	antepc@sina.com<br />inetnum:	118.192.0.0 - 118.192.49.255<br />netname:	SANXIN<br />descr:	Beijing Sanxin Shidai Co.Ltd1513 Xinjishu building Beijing link west road,Haidian District, Beijing, PRC<br />ns1:	dns2.sinonets.cn<br />ns2:	dns1.sinonets.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://autohuisbolide.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8476800</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.aof]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8476800</guid>
			<pubDate>2012-11-23T14:50:03+01:00</pubDate>
			<description><![CDATA[id:	8476800<br />first:	1353678603<br />last:	0<br />md5:	2488ad709e54e2b12f5b61ec5ab39a90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30eedf98b70b6b78f040562532dcbfcd<br />vt_score:	11/41 (26.8%)<br />scanner:	avira<br />virusname:	HTML/IFrame.aof<br />url:	http://autohuisbolide.nl/<br />recent:	up<br />response:	alive<br />ip:	46.235.43.143<br />as:	AS34233<br />review:	46.235.43.143<br />domain:	autohuisbolide.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@webreus.nl<br />inetnum:	46.235.43.0 - 46.235.47.255<br />netname:	WEBREUS<br />descr:	WebReus WebhostingWebReus @ Superior<br />ns1:	ns1.webreus.nl<br />ns2:	ns3.webreus.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ajaxhirek.nl/additional/ajax_zsido.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8476352</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8476352</guid>
			<pubDate>2012-11-23T14:20:03+01:00</pubDate>
			<description><![CDATA[id:	8476352<br />first:	1353676803<br />last:	0<br />md5:	2f232c48b0eeecc01756adc2bae752cb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f232c48b0eeecc01756adc2bae752cb<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://ajaxhirek.nl/additional/ajax_zsido.htm<br />recent:	up<br />response:	alive<br />ip:	209.59.137.2<br />as:	AS32244<br />review:	209.59.137.2<br />domain:	ajaxhirek.nl<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	209.59.128.0 - 209.59.191.255<br />netname:	LIQUIDWEB-2<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	ns2.webbed.nl<br />ns2:	ns1.webbed.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://accordiacalcio.org/recapiti--societa-.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8476082</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8476082</guid>
			<pubDate>2012-11-23T13:50:48+01:00</pubDate>
			<description><![CDATA[id:	8476082<br />first:	1353675048<br />last:	0<br />md5:	efc7ebdc400e6c6e0d38e520a8344abd<br />virustotal:	<br />vt_score:	1/46 (2.2%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://accordiacalcio.org/recapiti--societa-.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.74<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	accordiacalcio.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://accordiacalcio.org/belli-commenta-la-3-.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8476081</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8476081</guid>
			<pubDate>2012-11-23T13:50:48+01:00</pubDate>
			<description><![CDATA[id:	8476081<br />first:	1353675048<br />last:	0<br />md5:	c9284ec4a5cfd8885f736ebc5f36be37<br />virustotal:	<br />vt_score:	1/46 (2.2%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://accordiacalcio.org/belli-commenta-la-3-.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.163<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	accordiacalcio.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://2.duote.com.cn/fantizizhh.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8476075</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8476075</guid>
			<pubDate>2012-11-23T13:50:48+01:00</pubDate>
			<description><![CDATA[id:	8476075<br />first:	1353675048<br />last:	0<br />md5:	0fc292796f84eedfbc2ce641e1200e95<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://2.duote.com.cn/fantizizhh.zip<br />recent:	up<br />response:	alive<br />ip:	122.228.248.4<br />as:	AS4809<br />review:	122.228.248.4<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	122.224.0.0 - 122.239.255.255<br />netname:	CHINANET-ZJ<br />descr:	CHINANET Zhejiang province networkChina TelecomNo.31,jingrong streetBeijing 100032China Telecom Zhejiang Province<br />ns1:	dns3.50bang.org<br />ns2:	dns2.kabasiji.com<br />ns3:	dns1.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKaezicon5.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8475447</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8475447</guid>
			<pubDate>2012-11-23T12:11:19+01:00</pubDate>
			<description><![CDATA[id:	8475447<br />first:	1353669079<br />last:	0<br />md5:	e9531349f178602ec24ba2577e5a4a2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e9531349f178602ec24ba2577e5a4a2a<br />vt_score:	16/43 (37.2%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKaezicon5.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://apitsd.org/_mysql/dump/news-1308.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8472939</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8472939</guid>
			<pubDate>2012-11-23T09:40:03+01:00</pubDate>
			<description><![CDATA[id:	8472939<br />first:	1353660003<br />last:	0<br />md5:	c6914bdb80bf890894f9c9b44082a525<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c6914bdb80bf890894f9c9b44082a525<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://apitsd.org/_mysql/dump/news-1308.html<br />recent:	up<br />response:	alive<br />ip:	94.155.15.10<br />as:	AS49226<br />review:	94.155.15.10<br />domain:	apitsd.org<br />country:	BG<br />source:	RIPE<br />email:	abuse@itdnet.net<br />inetnum:	94.155.15.0 - 94.155.15.255<br />netname:	IRISVISIA<br />descr:	Iris Visia Ltd.<br />ns1:	ns11.irisvisia.com<br />ns2:	ns10.irisvisia.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://videoalpha.jp/css/jquery-latest.pack.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8470509</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Script.Packed-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8470509</guid>
			<pubDate>2012-11-22T22:13:02+01:00</pubDate>
			<description><![CDATA[id:	8470509<br />first:	1353618782<br />last:	0<br />md5:	8e6ae645896c83c6ccf88a974bb427b6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8e6ae645896c83c6ccf88a974bb427b6<br />vt_score:	8/35 (22.9%)<br />scanner:	clamav<br />virusname:	PUA.Script.Packed-2<br />url:	http://videoalpha.jp/css/jquery-latest.pack.js<br />recent:	up<br />response:	alive<br />ip:	118.82.122.208<br />as:	AS9597<br />review:	118.82.122.208<br />domain:	videoalpha.jp<br />country:	JP<br />source:	APNIC<br />email:	tech@cpi.ad.jp<br />inetnum:	118.82.120.0 - 118.82.127.255<br />netname:	CPI-NET<br />descr:	KDDI Web Communications Inc.<br />ns1:	ns6.cpi.ad.jp<br />ns2:	ns7.cpi.ad.jp<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://users.htcnet.org/~bhefner]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8470508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8470508</guid>
			<pubDate>2012-11-22T22:13:01+01:00</pubDate>
			<description><![CDATA[id:	8470508<br />first:	1353618781<br />last:	0<br />md5:	3e67dfb494938fc7f8d0df923679d777<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3e67dfb494938fc7f8d0df923679d777<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://users.htcnet.org/~bhefner<br />recent:	up<br />response:	alive<br />ip:	137.118.10.5<br />as:	AS6250<br />review:	137.118.10.5<br />domain:	htcnet.org<br />country:	US<br />source:	ARIN<br />email:	ipadmin@neonova.net<br />inetnum:	137.118.0.0 - 137.118.255.255<br />netname:	NNS-137-118-0-0<br />descr:	Neonova Network Services NNS-32 1000 Perimeter Park Drive Suite K Morrisville NC 27560<br />ns1:	ns2.neonova.net<br />ns2:	ns1.neonova.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://the-test-area.co.uk/skip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8470441</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.JI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8470441</guid>
			<pubDate>2012-11-22T21:50:20+01:00</pubDate>
			<description><![CDATA[id:	8470441<br />first:	1353617420<br />last:	0<br />md5:	5f48d27a45f6a5ae7003c0a26a93633e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5f48d27a45f6a5ae7003c0a26a93633e<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.JI<br />url:	http://the-test-area.co.uk/skip<br />recent:	up<br />response:	alive<br />ip:	195.26.90.15<br />as:	AS31727<br />review:	195.26.90.15<br />domain:	the-test-area.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@node4.co.uk<br />inetnum:	195.26.88.0 - 195.26.91.255<br />netname:	HOSTVUE-UK<br />descr:	Daily Internet Ltd Infrastructure<br />ns1:	ns2.daily.co.uk<br />ns2:	ns1.daily.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://target-office.it/postal_receipt.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8470439</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Strictor.15604]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8470439</guid>
			<pubDate>2012-11-22T21:50:20+01:00</pubDate>
			<description><![CDATA[id:	8470439<br />first:	1353617420<br />last:	0<br />md5:	fd48d5f2194888661c89a4fa64f6e394<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fd48d5f2194888661c89a4fa64f6e394<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	TR/Strictor.15604<br />url:	http://target-office.it/postal_receipt.zip<br />recent:	up<br />response:	alive<br />ip:	62.149.128.74<br />as:	AS31034<br />review:	62.149.128.163<br />domain:	target-office.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soprano-club.ch/mobile/js/cufon-replace.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8470362</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Trojan.Script.KX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8470362</guid>
			<pubDate>2012-11-22T21:30:04+01:00</pubDate>
			<description><![CDATA[id:	8470362<br />first:	1353616204<br />last:	0<br />md5:	15d871a3c38f981075554e3712a8ac1a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=15d871a3c38f981075554e3712a8ac1a<br />vt_score:	11/35 (31.4%)<br />scanner:	BitDefender<br />virusname:	JS:Trojan.Script.KX<br />url:	http://soprano-club.ch/mobile/js/cufon-replace.js<br />recent:	up<br />response:	alive<br />ip:	213.239.216.98<br />as:	AS24940<br />review:	213.239.216.98<br />domain:	soprano-club.ch<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	213.239.216.0 - 213.239.219.255<br />netname:	HETZNER-RZ-NBG-NET<br />descr:	Hetzner Online AGDatacenter NuernbergHETZNER-RZ-NBG-BLK2<br />ns1:	ns202.hoststar.ch<br />ns2:	ns201.hoststar.ch<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mdxh.com.cn/NewsClass.asp?BigClass=????????????????????]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.avu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468813</guid>
			<pubDate>2012-11-22T18:45:51+01:00</pubDate>
			<description><![CDATA[id:	8468813<br />first:	1353606351<br />last:	0<br />md5:	2f0985fa859f06175e4df307d241408a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f0985fa859f06175e4df307d241408a<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.avu<br />url:	http://mdxh.com.cn/NewsClass.asp?BigClass=????????????????????<br />recent:	up<br />response:	alive<br />ip:	125.77.197.11<br />as:	AS4134<br />review:	125.77.197.11<br />domain:	mdxh.com.cn<br />country:	CN<br />source:	APNIC<br />email:	fjnic@fjdcb.fz.fj.cn<br />inetnum:	125.77.0.0 - 125.77.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET Fujian province networkChina Telecom7,East Street ,Fuzhou ,Fujian ,PRC<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://labtarni.rissani.org/etablis/belle_image/images/48.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468708</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Chir.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468708</guid>
			<pubDate>2012-11-22T18:30:03+01:00</pubDate>
			<description><![CDATA[id:	8468708<br />first:	1353605403<br />last:	0<br />md5:	c223e4825d00312ac42687d8e4dfebc1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c223e4825d00312ac42687d8e4dfebc1<br />vt_score:	32/35 (91.4%)<br />scanner:	avira<br />virusname:	W32/Chir.B<br />url:	http://labtarni.rissani.org/etablis/belle_image/images/48.htm<br />recent:	up<br />response:	alive<br />ip:	72.29.83.201<br />as:	AS33182<br />review:	72.29.83.201<br />domain:	rissani.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns965.dizinc.com<br />ns2:	ns966.dizinc.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://heart-transplant.org/research/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468347</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468347</guid>
			<pubDate>2012-11-22T17:20:07+01:00</pubDate>
			<description><![CDATA[id:	8468347<br />first:	1353601207<br />last:	0<br />md5:	9f2b86cebfa5c59ba6be191cf29dab16<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9f2b86cebfa5c59ba6be191cf29dab16<br />vt_score:	25/35 (71.4%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://heart-transplant.org/research/<br />recent:	up<br />response:	alive<br />ip:	69.73.140.107<br />as:	AS3595<br />review:	69.73.168.216<br />domain:	heart-transplant.org<br />country:	US<br />source:	ARIN<br />email:	abuse@jaguarpc.com<br />inetnum:	69.73.128.0 - 69.73.191.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns.nocdirect.com<br />ns2:	ns2.nocdirect.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fluvannaswimming.info/promotions.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468274</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.TX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468274</guid>
			<pubDate>2012-11-22T16:52:05+01:00</pubDate>
			<description><![CDATA[id:	8468274<br />first:	1353599525<br />last:	0<br />md5:	62c19cb6ce727d01c82eb2f94254275c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=62c19cb6ce727d01c82eb2f94254275c<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/Redirect.TX<br />url:	http://fluvannaswimming.info/promotions.html<br />recent:	up<br />response:	alive<br />ip:	68.178.254.205<br />as:	AS26496<br />review:	68.178.254.205<br />domain:	fluvannaswimming.info<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	68.178.128.0 - 68.178.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns53.domaincontrol.com<br />ns2:	ns54.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/dolls-bears/bear-making-supplies.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468043</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/FunDF.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468043</guid>
			<pubDate>2012-11-22T16:10:04+01:00</pubDate>
			<description><![CDATA[id:	8468043<br />first:	1353597004<br />last:	0<br />md5:	bbf2c66773b351879af205aa9940d83e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bbf2c66773b351879af205aa9940d83e<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	JS/FunDF.B<br />url:	http://dollarauctions.ws/dolls-bears/bear-making-supplies.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cleaning4.co.uk/officecleaners.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468002</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML_TACCESS.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468002</guid>
			<pubDate>2012-11-22T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8468002<br />first:	1353595802<br />last:	0<br />md5:	49de0796a843ffb698daf35480144683<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=49de0796a843ffb698daf35480144683<br />vt_score:	14/44 (31.8%)<br />scanner:	trendmicro<br />virusname:	HTML_TACCESS.A<br />url:	http://cleaning4.co.uk/officecleaners.htm<br />recent:	up<br />response:	alive<br />ip:	216.130.165.31<br />as:	AS27257<br />review:	216.130.165.31<br />domain:	cleaning4.co.uk<br />country:	US<br />source:	ARIN<br />email:	abuse@webair.com<br />inetnum:	216.130.160.0 - 216.130.191.255<br />netname:	WEBAIRINTERNET<br />descr:	Webair Internet Development Company Inc. WAIR 1025 Old Country Road Suite 320 Westbury NY 11590-5645<br />ns1:	ns.webair.net<br />ns2:	ns2.webair.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cigv.de/Astrolabe/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8468001</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Script-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8468001</guid>
			<pubDate>2012-11-22T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8468001<br />first:	1353595802<br />last:	0<br />md5:	1e44ab497268eb2680c2bc8f71151bf0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1e44ab497268eb2680c2bc8f71151bf0<br />vt_score:	12/34 (35.3%)<br />scanner:	Avast<br />virusname:	HTML:Script-inf<br />url:	http://cigv.de/Astrolabe/index.html<br />recent:	up<br />response:	alive<br />ip:	82.165.98.202<br />as:	AS8560<br />review:	82.165.98.202<br />domain:	cigv.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns10.schlund.de<br />ns2:	ns9.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bfk-consulting.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8467901</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.chw]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8467901</guid>
			<pubDate>2012-11-22T14:50:12+01:00</pubDate>
			<description><![CDATA[id:	8467901<br />first:	1353592212<br />last:	0<br />md5:	298b402305f7dd5ff36d963f8e9032c2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=298b402305f7dd5ff36d963f8e9032c2<br />vt_score:	10/35 (28.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.chw<br />url:	http://bfk-consulting.de/<br />recent:	up<br />response:	alive<br />ip:	83.243.58.156<br />as:	AS25504<br />review:	83.243.58.156<br />domain:	bfk-consulting.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@cronon-ag.de<br />inetnum:	83.243.56.0 - 83.243.63.255<br />netname:	CRONON-RE2<br />descr:	-----------------------------------Cronon AG, Niederlassung RegensburgServerhousing, Domainregistrierung,Internet-Services fuerGewerbetreibendeWWWBei Missbrauch, bitte Mail anabuse@cronon-ag.de-----------------------------------CRONON-NET<br />ns1:	ns1.netbeat.de<br />ns2:	ns2.netbeat.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ariplex.com.tr/jquery.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8467753</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZK Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8467753</guid>
			<pubDate>2012-11-22T14:30:01+01:00</pubDate>
			<description><![CDATA[id:	8467753<br />first:	1353591001<br />last:	0<br />md5:	bb381e2d19d8eace86b34d20759491a5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4be8e3c667127c06d94a432f17c3a54f<br />vt_score:	17/36 (47.2%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZK Trj<br />url:	http://ariplex.com.tr/jquery.min.js<br />recent:	up<br />response:	alive<br />ip:	89.252.146.102<br />as:	AS34388<br />review:	94.73.151.40<br />domain:	ariplex.com.tr<br />country:	TR<br />source:	RIPE<br />email:	huseyin.caymaz@cizgibilgisayar.com<br />inetnum:	89.252.144.0 - 89.252.147.254<br />netname:	TR-CIZGI-20080710<br />descr:	Cizgi Bilgisayar Sistemleri San. Tic. Ltd. Sti.Cizgi Telekom Block #10.0Cizgi Telekom Colocation Block<br />ns1:	dns2.maya.net.tr<br />ns2:	dns1.maya.net.tr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://661.com.cn/images/index0_02.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8466952</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8466952</guid>
			<pubDate>2012-11-22T13:50:03+01:00</pubDate>
			<description><![CDATA[id:	8466952<br />first:	1353588603<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://661.com.cn/images/index0_02.gif<br />recent:	up<br />response:	alive<br />ip:	219.140.195.178<br />as:	AS4134<br />review:	219.140.195.178<br />domain:	661.com.cn<br />country:	CN<br />source:	APNIC<br />email:	wxi@dc.wh.hb.cn<br />inetnum:	219.140.0.0 - 219.140.255.255<br />netname:	CHINANET-HB-WH<br />descr:	Chinanet network in Wuhan city Hubei province<br />ns1:	ns14.xincache.com<br />ns2:	ns13.xincache.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://americanstandard.hk/index-th.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8465857</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8465857</guid>
			<pubDate>2012-11-22T11:00:04+01:00</pubDate>
			<description><![CDATA[id:	8465857<br />first:	1353578404<br />last:	0<br />md5:	27545193e4875cfa758533a23dcdc67e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=27545193e4875cfa758533a23dcdc67e<br />vt_score:	12/35 (34.3%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://americanstandard.hk/index-th.htm<br />recent:	up<br />response:	alive<br />ip:	203.174.48.88<br />as:	AS9381<br />review:	203.174.48.88<br />domain:	americanstandard.hk<br />country:	HK<br />source:	APNIC<br />email:	abuse@wharftt.com<br />inetnum:	203.174.32.0 - 203.174.63.255<br />netname:	IPC-NEWTT<br />descr:	Wharf T&T LimitedFixed Telecommunication Network Service (FTNS)Harbour City, Hong Kong SAR<br />ns1:	ns2.abchk.net<br />ns2:	ns1.abchk.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://piscine-sicilia.it/galleria_piscine5/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8464008</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.AY.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8464008</guid>
			<pubDate>2012-11-21T21:20:04+01:00</pubDate>
			<description><![CDATA[id:	8464008<br />first:	1353529204<br />last:	0<br />md5:	8ce8cb42d8b4dfa4de99e883e5e697bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8ce8cb42d8b4dfa4de99e883e5e697bf<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	JS/Redirector.AY.2<br />url:	http://piscine-sicilia.it/galleria_piscine5/index.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	piscine-sicilia.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns3.arubadns.net<br />ns3:	dns.technorail.com<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pilisszentivan.hu/_pgtres/stm31.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8464006</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.AJ.40]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8464006</guid>
			<pubDate>2012-11-21T21:20:04+01:00</pubDate>
			<description><![CDATA[id:	8464006<br />first:	1353529204<br />last:	0<br />md5:	3f7157c0f2167e1e1467868a8b83b6d8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3f7157c0f2167e1e1467868a8b83b6d8<br />vt_score:	28/43 (65.1%)<br />scanner:	avira<br />virusname:	JS/Redirector.AJ.40<br />url:	http://pilisszentivan.hu/_pgtres/stm31.js<br />recent:	up<br />response:	alive<br />ip:	178.238.210.107<br />as:	ASError:<br />review:	178.238.210.107<br />domain:	pilisszentivan.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@deninet.hu<br />inetnum:	<br />netname:	MAXER-NET<br />descr:	MAXER Hosting Kft.HU 9024 Gyor Repce u. 24.<br />ns1:	ns1.maxer.hu<br />ns2:	ns2.maxer.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://novoplay.nl/jstools.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462869</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.BS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462869</guid>
			<pubDate>2012-11-21T20:50:03+01:00</pubDate>
			<description><![CDATA[id:	8462869<br />first:	1353527403<br />last:	0<br />md5:	e267bfccabfbeb3540cd9d58367c2b94<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e267bfccabfbeb3540cd9d58367c2b94<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.BS<br />url:	http://novoplay.nl/jstools.js<br />recent:	up<br />response:	alive<br />ip:	94.75.226.130<br />as:	AS16265<br />review:	94.75.226.130<br />domain:	novoplay.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	94.75.226.0 - 94.75.226.255<br />netname:	LEASEWEB<br />descr:	LeaseWebP.O. Box 930541090BB AMSTERDAMNetherlandswww.leaseweb.com<br />ns1:	ns3.securitydatabase.net<br />ns2:	ns4.securitydatabase.org<br />ns3:	ns1.securitydatabase.nl<br />ns4:	ns2.securitydatabase.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mostwatched.ws/sporting-goods/surfing-wind-surfing.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462831</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462831</guid>
			<pubDate>2012-11-21T20:20:10+01:00</pubDate>
			<description><![CDATA[id:	8462831<br />first:	1353525610<br />last:	0<br />md5:	ad7fb85e27f196e3a9b00c20e401e09c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ad7fb85e27f196e3a9b00c20e401e09c<br />vt_score:	7/25 (28%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://mostwatched.ws/sporting-goods/surfing-wind-surfing.html<br />recent:	up<br />response:	alive<br />ip:	208.109.46.211<br />as:	AS26496<br />review:	208.109.46.211<br />domain:	mostwatched.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns43.domaincontrol.com<br />ns2:	ns44.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3ditools&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462765</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADWARE/Adware.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462765</guid>
			<pubDate>2012-11-21T19:30:03+01:00</pubDate>
			<description><![CDATA[id:	8462765<br />first:	1353522603<br />last:	0<br />md5:	7b4d425dc6cfca5e827fd29b6cf4e1a7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7b4d425dc6cfca5e827fd29b6cf4e1a7<br />vt_score:	13/22 (59.1%)<br />scanner:	avira<br />virusname:	ADWARE/Adware.Gen<br />url:	http://ld.download-guru.com?s=3ditools&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jpkc.nefu.edu.cn/zwx/Get/lwujiake/2126356.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462692</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AGZ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462692</guid>
			<pubDate>2012-11-21T18:41:08+01:00</pubDate>
			<description><![CDATA[id:	8462692<br />first:	1353519668<br />last:	0<br />md5:	102f7c92f6879e640e4d736914eab3f6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=102f7c92f6879e640e4d736914eab3f6<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.AGZ<br />url:	http://jpkc.nefu.edu.cn/zwx/Get/lwujiake/2126356.htm<br />recent:	up<br />response:	alive<br />ip:	202.118.223.22<br />as:	AS24564<br />review:	202.118.223.22<br />domain:	nefu.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	helpdesk@apnic.net<br />inetnum:	202.0.0.0 - 203.255.255.255<br />netname:	APNIC-AP<br />descr:	Asia Pacific Network Information CentreRegional Internet Registry for the Asia-Pacific Region6 Cordelia StreetPO Box 3646South Brisbane, QLD 4101Australia<br />ns1:	ns2.nefu.edu.cn<br />ns2:	ns3.nefu.edu.cn<br />ns3:	ns4.nefu.edu.cn<br />ns4:	ns1.nefu.edu.cn<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gjjd.sh.cn/articles.asp?id=45]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462638</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ScrInj.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462638</guid>
			<pubDate>2012-11-21T18:00:07+01:00</pubDate>
			<description><![CDATA[id:	8462638<br />first:	1353517207<br />last:	0<br />md5:	f55f0c3496e2d888a8bf22cfc1fdec78<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/ScrInj.C<br />url:	http://gjjd.sh.cn/articles.asp?id=45<br />recent:	up<br />response:	alive<br />ip:	222.191.251.21<br />as:	AS4134<br />review:	222.191.251.21<br />domain:	sh.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.184.0.0 - 222.191.255.255<br />netname:	CHINANET-JS<br />descr:	CHINANET jiangsu province networkChina TelecomA12,Xin-Jie-Kou-Wai StreetBeijing 100088<br />ns1:	e.dns.cn<br />ns2:	cns.cernet.net<br />ns3:	a.dns.cn<br />ns4:	b.dns.cn<br />ns5:	c.dns.cn<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fotomoto.lt/Copy_of_UPS_Label.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462538</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Jorik]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462538</guid>
			<pubDate>2012-11-21T17:30:03+01:00</pubDate>
			<description><![CDATA[id:	8462538<br />first:	1353515403<br />last:	0<br />md5:	58eb300a6be00deef61e112dc1084862<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=58eb300a6be00deef61e112dc1084862<br />vt_score:	19/44 (43.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Jorik<br />url:	http://fotomoto.lt/Copy_of_UPS_Label.zip<br />recent:	up<br />response:	alive<br />ip:	79.142.113.57<br />as:	AS8486<br />review:	79.142.113.57<br />domain:	fotomoto.lt<br />country:	LT<br />source:	RIPE<br />email:	abuse@balt.net<br />inetnum:	79.142.112.0 - 79.142.127.255<br />netname:	LT-BALTNET-20071106<br />descr:	UAB "Baltnetos komunikacijos"<br />ns1:	ns4.webas.lt<br />ns2:	ns3.webas.lt<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eyezine.co.uk/js/prototype.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462534</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462534</guid>
			<pubDate>2012-11-21T17:20:03+01:00</pubDate>
			<description><![CDATA[id:	8462534<br />first:	1353514803<br />last:	0<br />md5:	12cfa87a1c8af60d3b1373431d34ae8a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=12cfa87a1c8af60d3b1373431d34ae8a<br />vt_score:	23/33 (69.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://eyezine.co.uk/js/prototype.js<br />recent:	up<br />response:	alive<br />ip:	204.93.197.145<br />as:	AS23352<br />review:	204.93.197.145<br />domain:	eyezine.co.uk<br />country:	US<br />source:	ARIN<br />email:	support@servercentral.net<br />inetnum:	204.93.197.0 - 204.93.197.255<br />netname:	SCNET-204-93-197-0-24<br />descr:	2880 Zanker Rd. # 203 San Jose CA 95134<br />ns1:	ns.mainnameserver.com<br />ns2:	ns2.mainnameserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eventi.it/js/lib/swfobject.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462533</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462533</guid>
			<pubDate>2012-11-21T17:20:02+01:00</pubDate>
			<description><![CDATA[id:	8462533<br />first:	1353514802<br />last:	0<br />md5:	ab619f9ce3f04cb5ccd98bda8b42fa51<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ab619f9ce3f04cb5ccd98bda8b42fa51<br />vt_score:	14/43 (32.6%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA [Trj]<br />url:	http://eventi.it/js/lib/swfobject.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	eventi.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns3.arubadns.net<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eventi.it/js/lib/jquery.tooltip.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462532</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462532</guid>
			<pubDate>2012-11-21T17:20:02+01:00</pubDate>
			<description><![CDATA[id:	8462532<br />first:	1353514802<br />last:	0<br />md5:	18e768b7b765fbe372ea0ecd421e35c4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=18e768b7b765fbe372ea0ecd421e35c4<br />vt_score:	14/43 (32.6%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA [Trj]<br />url:	http://eventi.it/js/lib/jquery.tooltip.min.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.166<br />domain:	eventi.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns4.arubadns.cz<br />ns3:	dns3.arubadns.net<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eaae-france.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462470</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/IFrame.PE.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462470</guid>
			<pubDate>2012-11-21T16:50:40+01:00</pubDate>
			<description><![CDATA[id:	8462470<br />first:	1353513040<br />last:	0<br />md5:	63a8937542391035d887952d5606b64d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=63a8937542391035d887952d5606b64d<br />vt_score:	17/43 (39.5%)<br />scanner:	avira<br />virusname:	TR/IFrame.PE.2<br />url:	http://eaae-france.org/<br />recent:	up<br />response:	alive<br />ip:	193.252.114.157<br />as:	AS3215<br />review:	193.252.114.157<br />domain:	eaae-france.org<br />country:	FR<br />source:	RIPE<br />email:	abuse@orange-business.com<br />inetnum:	193.252.114.0 - 193.252.114.255<br />netname:	FT-TPC-DO-DIH<br />descr:	FT TPC DO DIH<br />ns1:	ns3.domicile.fr<br />ns2:	ns2.domicile.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://designemlata.com.br/wp-includes/js/jquery/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462428</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Iframe-DK Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462428</guid>
			<pubDate>2012-11-21T16:25:26+01:00</pubDate>
			<description><![CDATA[id:	8462428<br />first:	1353511526<br />last:	0<br />md5:	b15cdc68c220c5327ba26c8ba28bf2fe<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	Avast<br />virusname:	JS:Iframe-DK Trj<br />url:	http://designemlata.com.br/wp-includes/js/jquery/jquery.js<br />recent:	up<br />response:	alive<br />ip:	189.38.80.92<br />as:	AS28299<br />review:	189.38.80.92<br />domain:	designemlata.com.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@kinghost.com.br<br />inetnum:	189.38.80.0 - 189.38.95.255<br />netname:	005.305.671/0001-84<br />descr:	Cyberweb Networks Ltda<br />ns1:	dns4.kinghost.com.br<br />ns2:	dns3.kinghost.com.br<br />ns3:	dns6.kinghost.com.br<br />ns4:	dns2.kinghost.com.br<br />ns5:	dns5.kinghost.com.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://clinicaoftalmed.com.br/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462269</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462269</guid>
			<pubDate>2012-11-21T16:00:04+01:00</pubDate>
			<description><![CDATA[id:	8462269<br />first:	1353510004<br />last:	0<br />md5:	0d7c151580f09c74ad29215d1b5f5c46<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0d7c151580f09c74ad29215d1b5f5c46<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://clinicaoftalmed.com.br/<br />recent:	up<br />response:	alive<br />ip:	74.55.72.234<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	74.55.72.234<br />domain:	clinicaoftalmed.com.br<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	74.52.0.0 - 74.55.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns.clinicaoftalmed.com.br<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bluemozaiek.nl/photogallery/photo00013648/sldshow.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8462248</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.OV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8462248</guid>
			<pubDate>2012-11-21T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	8462248<br />first:	1353509402<br />last:	0<br />md5:	1a74800dfb82f9b480b7ae3c987d67c6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1a74800dfb82f9b480b7ae3c987d67c6<br />vt_score:	11/35 (31.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.OV<br />url:	http://bluemozaiek.nl/photogallery/photo00013648/sldshow.js<br />recent:	up<br />response:	alive<br />ip:	85.17.131.62<br />as:	AS16265<br />review:	185.10.98.4<br />domain:	bluemozaiek.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	85.17.0.0 - 85.17.255.255<br />netname:	NL-LEASEWEB-20050311<br />descr:	LeaseWeb B.V.LEASEWEB<br />ns1:	ns2.ermis.nl<br />ns2:	ns1.ermis.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://antwarp.jp/malibu_cafe/shop_info]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8461601</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.GA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8461601</guid>
			<pubDate>2012-11-21T14:46:20+01:00</pubDate>
			<description><![CDATA[id:	8461601<br />first:	1353505580<br />last:	0<br />md5:	99f08bd32720201528d00fe689c58dab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=99f08bd32720201528d00fe689c58dab<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	JS/Redirector.GA<br />url:	http://antwarp.jp/malibu_cafe/shop_info<br />recent:	up<br />response:	alive<br />ip:	202.133.122.21<br />as:	AS9597<br />review:	202.133.122.21<br />domain:	antwarp.jp<br />country:	JP<br />source:	APNIC<br />email:	tech@cpi.ad.jp<br />inetnum:	202.133.120.0 - 202.133.127.255<br />netname:	CPI-NET<br />descr:	KDDI Web Communications Inc.<br />ns1:	ns4.cpi.ad.jp<br />ns2:	ns5.cpi.ad.jp<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://220.112.31.66/1433.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454924</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.NSPM.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454924</guid>
			<pubDate>2012-11-20T19:00:03+01:00</pubDate>
			<description><![CDATA[id:	8454924<br />first:	1353434403<br />last:	0<br />md5:	29b728aa40535d3452a151607814e114<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.NSPM.Gen<br />url:	http://220.112.31.66/1433.exe<br />recent:	up<br />response:	alive<br />ip:	220.112.31.66<br />as:	AS17623<br />review:	220.112.31.66<br />domain:	220.112.31.66<br />country:	CN<br />source:	APNIC<br />email:	speed0822@sina.com<br />inetnum:	220.112.0.0 - 220.112.63.255<br />netname:	GWBN-SHENZHEN<br />descr:	FOR GREAT WALL BROADBAND NETWORK SERVICE ACCESS IN SHENZHEN<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yaprakpen.com.tr/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454922</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.hht.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454922</guid>
			<pubDate>2012-11-20T19:00:03+01:00</pubDate>
			<description><![CDATA[id:	8454922<br />first:	1353434403<br />last:	0<br />md5:	c27c57ccc6a56d56f156cf659640eccf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c27c57ccc6a56d56f156cf659640eccf<br />vt_score:	15/43 (34.9%)<br />scanner:	avira<br />virusname:	JS/Agent.hht.1<br />url:	http://yaprakpen.com.tr/<br />recent:	up<br />response:	alive<br />ip:	95.173.189.21<br />as:	AS51559<br />review:	159.253.43.34<br />domain:	yaprakpen.com.tr<br />country:	TR<br />source:	RIPE<br />email:	abuse@ni.net.tr<br />inetnum:	95.173.160.0 - 95.173.191.255<br />netname:	TR-NETINTERNET-201100921<br />descr:	Netinternet Bilgisayar ve Telekomunikasyon San. ve Tic. Ltd. Sti.<br />ns1:	ns2.ni.net.tr<br />ns2:	ns1.ni.net.tr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://viva.by/js/dnn.dom.positioning.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454916</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454916</guid>
			<pubDate>2012-11-20T19:00:03+01:00</pubDate>
			<description><![CDATA[id:	8454916<br />first:	1353434403<br />last:	0<br />md5:	f8818322e67985cb19a2e21f382c0e22<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f8818322e67985cb19a2e21f382c0e22<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://viva.by/js/dnn.dom.positioning.js<br />recent:	up<br />response:	alive<br />ip:	86.57.246.168<br />as:	AS6697<br />review:	86.57.246.168<br />domain:	viva.by<br />country:	BY<br />source:	RIPE<br />email:	dimon@mck.beltelecom.by<br />inetnum:	86.57.246.0 - 86.57.246.255<br />netname:	BELTELECOM-DATACENTER<br />descr:	Minsk, BelarusDELEGATED FROM BELPAK<br />ns1:	ns3.activeby.net<br />ns2:	ns2.activeby.net<br />ns3:	ns1.activeby.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://theatremuseum.gr/highslide/highslide-with-html.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454885</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454885</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454885<br />first:	1353432602<br />last:	0<br />md5:	329abc89fabd463fd171ff247fcfa459<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=329abc89fabd463fd171ff247fcfa459<br />vt_score:	25/35 (71.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://theatremuseum.gr/highslide/highslide-with-html.js<br />recent:	up<br />response:	alive<br />ip:	75.125.39.194<br />as:	AS36420, AS30315, AS13749, AS21844, AS13884<br />review:	75.125.39.194<br />domain:	theatremuseum.gr<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	75.125.0.0 - 75.125.255.255<br />netname:	NETBLK-THEPLANET-BLK-EV1-17<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns2.theatremuseum.gr<br />ns2:	ns1.theatremuseum.gr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/nrplc4tpl.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454883</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454883</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454883<br />first:	1353432602<br />last:	0<br />md5:	02ffc4bb78819cc5439f152a59a0ecf2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02ffc4bb78819cc5439f152a59a0ecf2<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/nrplc4tpl.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns3.datapro.co.za<br />ns2:	ns1.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://team-interaktion.de/css/cont01.css]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454882</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454882</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454882<br />first:	1353432602<br />last:	0<br />md5:	2883ca44b1f05556c100c49b1ff1cd28<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2883ca44b1f05556c100c49b1ff1cd28<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	JS/Redirector.A<br />url:	http://team-interaktion.de/css/cont01.css<br />recent:	up<br />response:	alive<br />ip:	89.110.129.53<br />as:	AS24989<br />review:	89.110.129.53<br />domain:	team-interaktion.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@netclusive.com<br />inetnum:	89.110.129.0 - 89.110.129.255<br />netname:	NCL-NET<br />descr:	netclusive GmbHHosting Services<br />ns1:	ns5.netclusive.de<br />ns2:	ns6.netclusive.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tanadellistrice.it/de/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454881</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.czo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454881</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454881<br />first:	1353432602<br />last:	0<br />md5:	51004022341c23e5c62d21d922bad6a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=51004022341c23e5c62d21d922bad6a3<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.czo<br />url:	http://tanadellistrice.it/de/index.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.166<br />domain:	tanadellistrice.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns4.arubadns.cz<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://stary.pzbs.pl/_stara/kadra/2008/open/zd3/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454877</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454877</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454877<br />first:	1353432602<br />last:	0<br />md5:	dae73699e88c4732a03f12f859dfacaf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dae73699e88c4732a03f12f859dfacaf<br />vt_score:	13/35 (37.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://stary.pzbs.pl/_stara/kadra/2008/open/zd3/index.html<br />recent:	up<br />response:	alive<br />ip:	89.161.183.211<br />as:	AS12824<br />review:	89.161.183.211<br />domain:	pzbs.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://skyoflebanon.org/tajawoz/magazine/may2006/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454874</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454874</guid>
			<pubDate>2012-11-20T18:30:02+01:00</pubDate>
			<description><![CDATA[id:	8454874<br />first:	1353432602<br />last:	0<br />md5:	16c405338c21c2678b01c7e274541bd0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=16c405338c21c2678b01c7e274541bd0<br />vt_score:	28/35 (80%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://skyoflebanon.org/tajawoz/magazine/may2006/index.html<br />recent:	up<br />response:	alive<br />ip:	65.110.48.60<br />as:	AS21840<br />review:	65.110.48.60<br />domain:	skyoflebanon.org<br />country:	US<br />source:	ARIN<br />email:	abuse@sagonet.com<br />inetnum:	65.110.32.0 - 65.110.63.255<br />netname:	SAGO-20030401<br />descr:	Sago Networks SAGO 4465 W. Gandy Blvd STE 800 Tampa FL 33611<br />ns1:	ns.netdesignplus.net<br />ns2:	ns2.netdesignplus.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://planetbuilding.co.il/section/3.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454677</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.EC.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454677</guid>
			<pubDate>2012-11-20T17:27:51+01:00</pubDate>
			<description><![CDATA[id:	8454677<br />first:	1353428871<br />last:	0<br />md5:	f45d8d1baaa140f131a9c9d05a40a235<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=98ab1660f8d97d691069f7d5416c2acb<br />vt_score:	12/42 (28.6%)<br />scanner:	avira<br />virusname:	JS/Agent.EC.2<br />url:	http://planetbuilding.co.il/section/3.html<br />recent:	up<br />response:	alive<br />ip:	62.90.102.3<br />as:	AS1680<br />review:	62.90.102.3<br />domain:	planetbuilding.co.il<br />country:	IL<br />source:	RIPE<br />email:	abuse@013netvision.co.il<br />inetnum:	62.90.102.0 - 62.90.102.63<br />netname:	ran<br />descr:	ran@adcd.co.il<br />ns1:	ns3.adcd.co.il<br />ns2:	ns5.powdns.com<br />ns3:	ns7.powdns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/templates/rt_hyperion_j15/js/rokmoomenu.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454659</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454659</guid>
			<pubDate>2012-11-20T17:10:04+01:00</pubDate>
			<description><![CDATA[id:	8454659<br />first:	1353427804<br />last:	0<br />md5:	e9421d131a1296cfdd7532d72f86f91f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e9421d131a1296cfdd7532d72f86f91f<br />vt_score:	18/36 (50%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/templates/rt_hyperion_j15/js/rokmoomenu.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/plugins/system/pc_includes/ajax.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454658</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454658</guid>
			<pubDate>2012-11-20T17:10:04+01:00</pubDate>
			<description><![CDATA[id:	8454658<br />first:	1353427804<br />last:	0<br />md5:	518dc2f7a7d9ab40612eaf61b007519e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=518dc2f7a7d9ab40612eaf61b007519e<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/plugins/system/pc_includes/ajax.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.163<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454657</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454657</guid>
			<pubDate>2012-11-20T17:10:04+01:00</pubDate>
			<description><![CDATA[id:	8454657<br />first:	1353427804<br />last:	0<br />md5:	3416374c25ed4cbc0690f10b900fde24<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3416374c25ed4cbc0690f10b900fde24<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pdroma2.it/components/com_jomcomment/script.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454656</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454656</guid>
			<pubDate>2012-11-20T17:10:04+01:00</pubDate>
			<description><![CDATA[id:	8454656<br />first:	1353427804<br />last:	0<br />md5:	d46a5558ba8655d2806a2bb1af0ae5bd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d46a5558ba8655d2806a2bb1af0ae5bd<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://pdroma2.it/components/com_jomcomment/script.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	pdroma2.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://otis-konin.pl/templates/klima2/swfobject.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454655</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.aql]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454655</guid>
			<pubDate>2012-11-20T17:10:04+01:00</pubDate>
			<description><![CDATA[id:	8454655<br />first:	1353427804<br />last:	0<br />md5:	62ed6816c1c2f02dadf894a646dc6d35<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=17f31ba1ee8f6ec81ec7036032218950<br />vt_score:	16/43 (37.2%)<br />scanner:	avira<br />virusname:	JS/Agent.aql<br />url:	http://otis-konin.pl/templates/klima2/swfobject.js<br />recent:	up<br />response:	alive<br />ip:	93.159.16.132<br />as:	AS12968<br />review:	193.218.152.20<br />domain:	otis-konin.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@superhost.pl<br />inetnum:	93.159.16.128 - 93.159.16.159<br />netname:	SUPERHOST-PL<br />descr:	SuperHost.pl Sp. z o.o.<br />ns1:	dns1.mserwis.pl<br />ns2:	dns2.mserwis.pl<br />ns3:	dns3.mserwis.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mudlord.info/democrap/ml_quicktro.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454515</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HEUR/Crypted]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454515</guid>
			<pubDate>2012-11-20T16:41:06+01:00</pubDate>
			<description><![CDATA[id:	8454515<br />first:	1353426066<br />last:	0<br />md5:	4b2ba77ee5eb6780909628d0c17abf9a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4b2ba77ee5eb6780909628d0c17abf9a<br />vt_score:	14/34 (41.2%)<br />scanner:	AntiVir<br />virusname:	HEUR/Crypted<br />url:	http://mudlord.info/democrap/ml_quicktro.zip<br />recent:	up<br />response:	alive<br />ip:	173.236.169.189<br />as:	AS26347<br />review:	208.97.150.177<br />domain:	mudlord.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	173.236.128.0 - 173.236.255.255<br />netname:	DREAMHOST-BLK5<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mudlord.info/democrap/ml_nethermind.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454514</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HEUR/Crypted]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454514</guid>
			<pubDate>2012-11-20T16:41:06+01:00</pubDate>
			<description><![CDATA[id:	8454514<br />first:	1353426066<br />last:	0<br />md5:	c53d29ceddc711bc63a87facb3b34f9a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c53d29ceddc711bc63a87facb3b34f9a<br />vt_score:	12/34 (35.3%)<br />scanner:	AntiVir<br />virusname:	HEUR/Crypted<br />url:	http://mudlord.info/democrap/ml_nethermind.zip<br />recent:	up<br />response:	alive<br />ip:	173.236.169.189<br />as:	AS26347<br />review:	208.97.150.177<br />domain:	mudlord.info<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	173.236.128.0 - 173.236.255.255<br />netname:	DREAMHOST-BLK5<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns1.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mini.b-52.com.pl/otwarty_disp/js_blank.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8454508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[EXP/JS.Blacole.CQ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8454508</guid>
			<pubDate>2012-11-20T16:41:06+01:00</pubDate>
			<description><![CDATA[id:	8454508<br />first:	1353426066<br />last:	0<br />md5:	68d79519c0f49801e5aac09e85dc037f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=68d79519c0f49801e5aac09e85dc037f<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	EXP/JS.Blacole.CQ<br />url:	http://mini.b-52.com.pl/otwarty_disp/js_blank.js<br />recent:	up<br />response:	alive<br />ip:	62.129.196.58<br />as:	AS12824<br />review:	62.129.196.58<br />domain:	b-52.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=tengo+ganas+de+ti+(3msc+2)]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8432110</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8432110</guid>
			<pubDate>2012-11-20T16:13:56+01:00</pubDate>
			<description><![CDATA[id:	8432110<br />first:	1353424436<br />last:	0<br />md5:	0b468be4019e97a2c6cf85fd84ac57b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0b468be4019e97a2c6cf85fd84ac57b3<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=tengo+ganas+de+ti+(3msc+2)<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=(500)]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8432109</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8432109</guid>
			<pubDate>2012-11-20T16:13:56+01:00</pubDate>
			<description><![CDATA[id:	8432109<br />first:	1353424436<br />last:	0<br />md5:	ac0f052c7a3d99bf74dc3993a8377109<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ac0f052c7a3d99bf74dc3993a8377109<br />vt_score:	25/34 (73.5%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=(500)<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lanuevaconciencia.com.ar/chequeo_biosalud.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8432107</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.vk.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8432107</guid>
			<pubDate>2012-11-20T16:13:56+01:00</pubDate>
			<description><![CDATA[id:	8432107<br />first:	1353424436<br />last:	0<br />md5:	a9ab0025fd9284d44415b339338d6054<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a9ab0025fd9284d44415b339338d6054<br />vt_score:	23/35 (65.7%)<br />scanner:	avira<br />virusname:	TR/Spy.Banker.vk.1<br />url:	http://lanuevaconciencia.com.ar/chequeo_biosalud.html<br />recent:	up<br />response:	alive<br />ip:	66.7.198.76<br />as:	AS33182<br />review:	66.7.198.76<br />domain:	lanuevaconciencia.com.ar<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	66.7.192.0 - 66.7.223.255<br />netname:	DIMECNET<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns4.dns-principal-3.com<br />ns2:	ns3.dns-principal-3.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kim.ymodels.nl/images/simpleviewer5/swfobject.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8432101</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.U.36]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8432101</guid>
			<pubDate>2012-11-20T16:13:56+01:00</pubDate>
			<description><![CDATA[id:	8432101<br />first:	1353424436<br />last:	0<br />md5:	c06178b01fdb5006bbc3a62aea5e54a9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	JS/Redirector.U.36<br />url:	http://kim.ymodels.nl/images/simpleviewer5/swfobject.js<br />recent:	up<br />response:	alive<br />ip:	213.247.51.237<br />as:	AS25525<br />review:	213.247.51.237<br />domain:	ymodels.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@reasonnet.com<br />inetnum:	213.247.51.0 - 213.247.51.255<br />netname:	ROKSCOM-INTERNET-BV<br />descr:	DELL Dedi Servers<br />ns1:	ns2.pghosting.nl<br />ns2:	ns1.pghosting.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kbtrans.sk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8432100</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Dldr.IFrame.BM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8432100</guid>
			<pubDate>2012-11-20T16:13:56+01:00</pubDate>
			<description><![CDATA[id:	8432100<br />first:	1353424436<br />last:	0<br />md5:	3cf36a6bc82aac4734aeea8753ac824e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3cf36a6bc82aac4734aeea8753ac824e<br />vt_score:	24/35 (68.6%)<br />scanner:	avira<br />virusname:	JS/Dldr.IFrame.BM<br />url:	http://kbtrans.sk/<br />recent:	up<br />response:	alive<br />ip:	217.67.30.14<br />as:	AS29208<br />review:	217.67.30.14<br />domain:	kbtrans.sk<br />country:	SK<br />source:	RIPE<br />email:	abuse@dial.sk<br />inetnum:	217.67.30.0 - 217.67.31.255<br />netname:	YEGON-SK<br />descr:	Yegon, s.r.oSlovakia<br />ns1:	ns1.nameserver.sk<br />ns2:	ns1.dnsbackup.net<br />ns3:	ns2.nameserver.sk<br />ns4:	ns2.dnsbackup.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p453p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8409756</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8409756</guid>
			<pubDate>2012-11-20T16:00:03+01:00</pubDate>
			<description><![CDATA[id:	8409756<br />first:	1353423603<br />last:	0<br />md5:	775fcfc8f52a18bd28922940f1d1c72b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=775fcfc8f52a18bd28922940f1d1c72b<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p453p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p40p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8409755</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8409755</guid>
			<pubDate>2012-11-20T16:00:03+01:00</pubDate>
			<description><![CDATA[id:	8409755<br />first:	1353423603<br />last:	0<br />md5:	5bf7c0237596bdfb5581735380b4d071<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5bf7c0237596bdfb5581735380b4d071<br />vt_score:	26/35 (74.3%)<br />scanner:	AhnLab_V3<br />virusname:	HTML/Agent<br />url:	http://jong1025.com.ne.kr/html/sbr32/p40p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://healingteddies.org.il/hemlah/_hemlah.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8387813</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8387813</guid>
			<pubDate>2012-11-20T15:40:02+01:00</pubDate>
			<description><![CDATA[id:	8387813<br />first:	1353422402<br />last:	0<br />md5:	27e8fb0ec9b9c7ce6bb8ae44a5beb5f7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=27e8fb0ec9b9c7ce6bb8ae44a5beb5f7<br />vt_score:	19/35 (54.3%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://healingteddies.org.il/hemlah/_hemlah.html<br />recent:	up<br />response:	alive<br />ip:	208.109.14.20<br />as:	AS26496<br />review:	208.109.14.20<br />domain:	healingteddies.org.il<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	208.109.0.0 - 208.109.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns3.secureserver.net<br />ns2:	ns4.secureserver.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fullertonhigh.org/ourpages/gp/mrp_files/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8366343</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Dldr.IFrame.bjo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8366343</guid>
			<pubDate>2012-11-20T15:20:04+01:00</pubDate>
			<description><![CDATA[id:	8366343<br />first:	1353421204<br />last:	0<br />md5:	86be2e83dc96de8629c9105c5e4de1ba<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=86be2e83dc96de8629c9105c5e4de1ba<br />vt_score:	23/34 (67.6%)<br />scanner:	avira<br />virusname:	JS/Dldr.IFrame.bjo<br />url:	http://fullertonhigh.org/ourpages/gp/mrp_files/index.html<br />recent:	up<br />response:	alive<br />ip:	4.59.62.4<br />as:	AS3356<br />review:	4.59.62.4<br />domain:	fullertonhigh.org<br />country:	US<br />source:	ARIN<br />email:	security@level3.com<br />inetnum:	4.0.0.0 - 4.255.255.255<br />netname:	LVLT-ORG-4-8<br />descr:	Level 3 Communications, Inc. LVLT 1025 Eldorado Blvd. Broomfield CO 80021<br />ns1:	ns2.edlio.com<br />ns2:	ns1.edlio.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://eroglu-it.de/javascript/main.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8366335</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8366335</guid>
			<pubDate>2012-11-20T15:20:03+01:00</pubDate>
			<description><![CDATA[id:	8366335<br />first:	1353421203<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://eroglu-it.de/javascript/main.js<br />recent:	up<br />response:	alive<br />ip:	62.116.164.44<br />as:	AS15456<br />review:	62.116.164.44<br />domain:	eroglu-it.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@internetx.de<br />inetnum:	62.116.128.0 - 62.116.191.255<br />netname:	INTERNETX_RESOURCES_2005-2007<br />descr:	InterNetX GmbHProvider<br />ns1:	ns1.moyomedia.de<br />ns2:	ns2.moyomedia.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://donplandscapedesign.ca/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8366329</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.26]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8366329</guid>
			<pubDate>2012-11-20T15:20:03+01:00</pubDate>
			<description><![CDATA[id:	8366329<br />first:	1353421203<br />last:	0<br />md5:	45ae0a4c13541d44d25159219943ceae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=45ae0a4c13541d44d25159219943ceae<br />vt_score:	14/35 (40%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.26<br />url:	http://donplandscapedesign.ca/<br />recent:	up<br />response:	alive<br />ip:	67.213.88.100<br />as:	AS41864<br />review:	67.213.88.100<br />domain:	donplandscapedesign.ca<br />country:	CA<br />source:	ARIN<br />email:	SUPPORT@spdnetwork.net<br />inetnum:	67.213.64.0 - 67.213.95.255<br />netname:	SPDNETWORK-03<br />descr:	SPD NETWORK SPDNE 8-40 METROPOLITAN RD TORONTO ON M1R-2T6 AS40028 151 FRONT ST WEST TORONTO ON M5J-2N1 AS40028<br />ns1:	ns2.levelhosting.ca<br />ns2:	ns1.levelhosting.ca<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://candlesatwholesale.com.au/skin1/common.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8315210</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Script.Packed-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8315210</guid>
			<pubDate>2012-11-20T14:20:03+01:00</pubDate>
			<description><![CDATA[id:	8315210<br />first:	1353417603<br />last:	0<br />md5:	9ca75ed82081bd9bd14804d27f3c0a45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9ca75ed82081bd9bd14804d27f3c0a45<br />vt_score:	9/44 (20.5%)<br />scanner:	clamav<br />virusname:	PUA.Script.Packed-2<br />url:	http://candlesatwholesale.com.au/skin1/common.js<br />recent:	up<br />response:	alive<br />ip:	203.89.208.122<br />as:	AS9328<br />review:	203.89.208.122<br />domain:	candlesatwholesale.com.au<br />country:	AU<br />source:	APNIC<br />email:	ben.holko@globalcenter.net.au<br />inetnum:	203.89.192.0 - 203.89.223.255<br />netname:	GLOBALCENTER-AU-NET2<br />descr:	GlobalCenter - A Division of Datacom SystemsInternet Data CenterSouth Melbourne<br />ns1:	NS2.KAS.NET.au<br />ns2:	NS1.KAS.NET.au<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aurelia-moden.de/nathus/include/java_script.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8315200</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8315200</guid>
			<pubDate>2012-11-20T14:20:03+01:00</pubDate>
			<description><![CDATA[id:	8315200<br />first:	1353417603<br />last:	0<br />md5:	b1618915c833ad3aa6150ca030a93df7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b1618915c833ad3aa6150ca030a93df7<br />vt_score:	0/36 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.BO.1<br />url:	http://aurelia-moden.de/nathus/include/java_script.js<br />recent:	up<br />response:	alive<br />ip:	62.116.168.45<br />as:	AS15456<br />review:	62.116.168.45<br />domain:	aurelia-moden.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@internetx.de<br />inetnum:	62.116.168.0 - 62.116.168.255<br />netname:	INTERNETX_RESOURCES_2005-2007<br />descr:	InterNetX GmbHProvider<br />ns1:	a.ns14.net<br />ns2:	d.ns14.net<br />ns3:	b.ns14.net<br />ns4:	c.ns14.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://accordiacalcio.org/-mister-tony-commento.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8248358</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[EXP/JS.Expack.FC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8248358</guid>
			<pubDate>2012-11-20T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8248358<br />first:	1353414602<br />last:	0<br />md5:	7491016ce9bebf6d6629ecfc381f15b2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7491016ce9bebf6d6629ecfc381f15b2<br />vt_score:	17/36 (47.2%)<br />scanner:	AntiVir<br />virusname:	EXP/JS.Expack.FC<br />url:	http://accordiacalcio.org/-mister-tony-commento.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.163<br />as:	AS31034<br />review:	62.149.128.166<br />domain:	accordiacalcio.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://accordiacalcio.org/commenti-sulle-partite.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8248357</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[EXP/JS.Expack.FC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8248357</guid>
			<pubDate>2012-11-20T13:30:02+01:00</pubDate>
			<description><![CDATA[id:	8248357<br />first:	1353414602<br />last:	0<br />md5:	2bfa8e19e90f6c6a6d81b15e0d19e5b8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2bfa8e19e90f6c6a6d81b15e0d19e5b8<br />vt_score:	17/36 (47.2%)<br />scanner:	AntiVir<br />virusname:	EXP/JS.Expack.FC<br />url:	http://accordiacalcio.org/commenti-sulle-partite.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.163<br />as:	AS31034<br />review:	62.149.128.151<br />domain:	accordiacalcio.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns2.technorail.com<br />ns2:	dns.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bvzxhgdsf.blogspot.co.nz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=7513551</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Script.VI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=7513551</guid>
			<pubDate>2012-11-19T13:40:17+01:00</pubDate>
			<description><![CDATA[id:	7513551<br />first:	1353328817<br />last:	0<br />md5:	abe3a0b55e831dc34648f17f78380f5a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=abe3a0b55e831dc34648f17f78380f5a<br />vt_score:	12/46 (26.1%)<br />scanner:	BitDefender<br />virusname:	Trojan.Script.VI<br />url:	http://bvzxhgdsf.blogspot.co.nz<br />recent:	up<br />response:	alive<br />ip:	173.194.67.132<br />as:	AS15169<br />review:	173.194.70.132<br />domain:	blogspot.co.nz<br />country:	US<br />source:	ARIN<br />email:	arin-contact@google.com<br />inetnum:	173.194.0.0 - 173.194.255.255<br />netname:	GOOGLE<br />descr:	Google Inc. GOGL 1600 Amphitheatre Parkway Mountain View CA 94043<br />ns1:	ns2.google.com<br />ns2:	ns4.google.com<br />ns3:	ns1.google.com<br />ns4:	ns3.google.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wytwym.bookonline.com.cn/freepage/pubimg/download.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6931487</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6931487</guid>
			<pubDate>2012-11-18T14:20:02+01:00</pubDate>
			<description><![CDATA[id:	6931487<br />first:	1353244802<br />last:	0<br />md5:	50015d6f3961316776af3a2f3dd41c0f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50015d6f3961316776af3a2f3dd41c0f<br />vt_score:	20/40 (50%)<br />scanner:	AntiVir<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://wytwym.bookonline.com.cn/freepage/pubimg/download.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns1.dnspod.net<br />ns2:	f1g1ns2.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://resalh.ws/js/jquery-1.3.2.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6922448</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.W.76]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6922448</guid>
			<pubDate>2012-11-18T14:00:03+01:00</pubDate>
			<description><![CDATA[id:	6922448<br />first:	1353243603<br />last:	0<br />md5:	5f417a24ae8a65da537e26a086f39f5c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a1024f830c143d43190246446c9306a2<br />vt_score:	21/35 (60%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.W.76<br />url:	http://resalh.ws/js/jquery-1.3.2.min.js<br />recent:	up<br />response:	alive<br />ip:	209.59.164.170<br />as:	AS32244<br />review:	209.59.186.52<br />domain:	resalh.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	209.59.128.0 - 209.59.191.255<br />netname:	LIQUIDWEB-2<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	ns1.arabsgate10.com<br />ns2:	ns2.arabsgate10.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fenjiu.com.cn/docc/news/news_open.asp?auto_id=1633]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6922405</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.BG.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6922405</guid>
			<pubDate>2012-11-18T14:00:02+01:00</pubDate>
			<description><![CDATA[id:	6922405<br />first:	1353243602<br />last:	0<br />md5:	a3902e1b808b75cb959544ac6ff1411e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a3902e1b808b75cb959544ac6ff1411e<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	JS/Agent.BG.1<br />url:	http://fenjiu.com.cn/docc/news/news_open.asp?auto_id=1633<br />recent:	up<br />response:	alive<br />ip:	124.165.231.201<br />as:	AS4837<br />review:	124.165.231.201<br />domain:	fenjiu.com.cn<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	124.164.0.0 - 124.167.255.255<br />netname:	UNICOM-SX<br />descr:	China Unicom Shan1xi province networkChina UnicomCNC Group CHINA169 Shan1xi Province Network<br />ns1:	ns1.fenjiu.com.cn<br />ns2:	ns2.fenjiu.com.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://72.167.111.216]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6900537</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirect.AC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6900537</guid>
			<pubDate>2012-11-18T13:10:15+01:00</pubDate>
			<description><![CDATA[id:	6900537<br />first:	1353240615<br />last:	0<br />md5:	bc7ed354ff9842df6a1ace92a6da020a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bc7ed354ff9842df6a1ace92a6da020a<br />vt_score:	21/35 (60%)<br />scanner:	avira<br />virusname:	JS/Redirect.AC<br />url:	http://72.167.111.216<br />recent:	up<br />response:	alive<br />ip:	72.167.111.216<br />as:	AS26496<br />review:	72.167.111.216<br />domain:	72.167.111.216<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	72.167.0.0 - 72.167.127.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://203.146.215.106/~2c/files/gimgs/nyet.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6900535</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/IRCBOT.21970]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6900535</guid>
			<pubDate>2012-11-18T13:10:14+01:00</pubDate>
			<description><![CDATA[id:	6900535<br />first:	1353240614<br />last:	0<br />md5:	6ea9d1fa83e6fdc6a6a6ac10f7b84dd0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6ea9d1fa83e6fdc6a6a6ac10f7b84dd0<br />vt_score:	27/40 (67.5%)<br />scanner:	avira<br />virusname:	PHP/IRCBOT.21970<br />url:	http://203.146.215.106/~2c/files/gimgs/nyet.jpg<br />recent:	up<br />response:	alive<br />ip:	203.146.215.106<br />as:	AS9891<br />review:	203.146.215.106<br />domain:	203.146.215.106<br />country:	TH<br />source:	APNIC<br />email:	ip_admin@csloxinfo.net<br />inetnum:	203.146.215.0 - 203.146.215.255<br />netname:	idc-csloxinfo<br />descr:	reassign to "IDC-CBW- IDC customer"contact "dc@csloxinfo.net"<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gr-catering.de/gasthaus/wirtschaft.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6836823</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.brb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6836823</guid>
			<pubDate>2012-11-18T10:20:03+01:00</pubDate>
			<description><![CDATA[id:	6836823<br />first:	1353230403<br />last:	0<br />md5:	363f35926c786a12dd662d8325a2c3d9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=363f35926c786a12dd662d8325a2c3d9<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.brb<br />url:	http://gr-catering.de/gasthaus/wirtschaft.html<br />recent:	up<br />response:	alive<br />ip:	195.200.192.207<br />as:	AS47670<br />review:	195.200.192.207<br />domain:	gr-catering.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@goldlabs.net<br />inetnum:	195.200.192.0 - 195.200.192.255<br />netname:	EU-GOLDLABS-NETWORK<br />descr:	GoldLabs - Get it in Goldwww.GoldLabs.netOrganisation Handle - GoldLabs<br />ns1:	ns27.ns27.de<br />ns2:	ns25.ns25.de<br />ns3:	ns28.ns28.de<br />ns4:	ns26.ns26.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wildmetselwerk.nl/applething/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6319785</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.chw]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6319785</guid>
			<pubDate>2012-11-17T15:50:02+01:00</pubDate>
			<description><![CDATA[id:	6319785<br />first:	1353163802<br />last:	0<br />md5:	7f5733331a93c3866ea181c6104869be<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d79129c5aba02c58b71f2f7d2659e85<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.chw<br />url:	http://wildmetselwerk.nl/applething/<br />recent:	up<br />response:	alive<br />ip:	194.165.34.121<br />as:	AS8315<br />review:	194.165.34.121<br />domain:	wildmetselwerk.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@argeweb.nl<br />inetnum:	194.165.34.0 - 194.165.34.255<br />netname:	ARGEWEB<br />descr:	Argeweb B.V.<br />ns1:	ns.argewebhosting.nl<br />ns2:	ns0.argewebhosting.nl<br />ns3:	ns3.argewebhosting.nl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=windows+8+xtreme+ultimate+final+]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282964</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282964</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282964<br />first:	1353160202<br />last:	0<br />md5:	2668f9552f98c5583bc0ff4c72ca1dc5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2668f9552f98c5583bc0ff4c72ca1dc5<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=windows+8+xtreme+ultimate+final+<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=ver+poder+sin+limites+(2012)]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282963</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ADWARE/Adware.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282963</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282963<br />first:	1353160202<br />last:	0<br />md5:	6e6f12704783e183379f6050ad572a5b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6e6f12704783e183379f6050ad572a5b<br />vt_score:	19/30 (63.3%)<br />scanner:	avira<br />virusname:	ADWARE/Adware.Gen<br />url:	http://ld.download-guru.com?s=ver+poder+sin+limites+(2012)<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3d3d?????&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282962</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282962</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282962<br />first:	1353160202<br />last:	0<br />md5:	4ab118af5071580db5564118aea332f8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4ab118af5071580db5564118aea332f8<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3d3d?????&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3d3d3d&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282961</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282961</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282961<br />first:	1353160202<br />last:	0<br />md5:	7b1156967acbad333dc2001a81aa36ab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7b1156967acbad333dc2001a81aa36ab<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3d3d3d&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kijowski.plnkijowski.plnmail.kijowski.pl/ojciec.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282959</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282959</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282959<br />first:	1353160202<br />last:	0<br />md5:	f178eae080569f399c17ef8409fb05da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8161ab425c7fbbdae0d723cf1034aac9<br />vt_score:	18/40 (45%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://kijowski.plnkijowski.plnmail.kijowski.pl/ojciec.html<br />recent:	up<br />response:	alive<br />ip:	77.79.246.200<br />as:	AS15694<br />review:	77.79.247.160<br />domain:	kijowski.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@atman.pl<br />inetnum:	77.79.244.0 - 77.79.247.255<br />netname:	PROGRESO-PL<br />descr:	Progreso #1ul. 1 Maja 744-330 Jastrzebie Zdroj<br />ns1:	d.ns2.pl<br />ns2:	d.ns1.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://insan.co.kr/images/main_html_smartbutton1.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6282953</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.aaq]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6282953</guid>
			<pubDate>2012-11-17T14:50:02+01:00</pubDate>
			<description><![CDATA[id:	6282953<br />first:	1353160202<br />last:	0<br />md5:	265e401b4fa2a93e0cf1a092350ddc66<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=265e401b4fa2a93e0cf1a092350ddc66<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	HTML/IFrame.aaq<br />url:	http://insan.co.kr/images/main_html_smartbutton1.gif<br />recent:	up<br />response:	alive<br />ip:	211.196.153.54<br />as:	AS4766<br />review:	211.196.153.54<br />domain:	insan.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@kornet.net<br />inetnum:	211.196.0.0 - 211.199.255.255<br />netname:	KORNET-KR<br />descr:	Korea Telecom<br />ns1:	ns2.insan.co.kr<br />ns2:	ns3.insan.co.kr<br />ns3:	ns1.insan.co.kr<br />ns4:	ns.insan.co.kr<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ijkt.it/moodle/mod/forum/rate_ajax.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6270881</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bye]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6270881</guid>
			<pubDate>2012-11-17T14:30:03+01:00</pubDate>
			<description><![CDATA[id:	6270881<br />first:	1353159003<br />last:	0<br />md5:	6d381bb56a2bc615858e794c10730d2c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6d381bb56a2bc615858e794c10730d2c<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.bye<br />url:	http://ijkt.it/moodle/mod/forum/rate_ajax.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	ijkt.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns.technorail.com<br />ns3:	dns3.arubadns.net<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ihlamurevleri.org/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6270878</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.NA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6270878</guid>
			<pubDate>2012-11-17T14:30:02+01:00</pubDate>
			<description><![CDATA[id:	6270878<br />first:	1353159002<br />last:	0<br />md5:	9c7325670d756af2331097e2a49e2edd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9c7325670d756af2331097e2a49e2edd<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.NA<br />url:	http://ihlamurevleri.org/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	94.199.200.153<br />as:	AS42807<br />review:	94.199.200.153<br />domain:	ihlamurevleri.org<br />country:	TR<br />source:	RIPE<br />email:	abuse@aerotek.com.tr<br />inetnum:	94.199.200.0 - 94.199.204.255<br />netname:	TURHOST-NET<br />descr:	Aerotek Bilisim Taahhut Sanayi ve Ticaret Limited Sirketi<br />ns1:	ns2.turdns.com<br />ns2:	ns1.turdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://expat-coaching.de/coaching-finanzen.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6270872</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.GH]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6270872</guid>
			<pubDate>2012-11-17T14:30:02+01:00</pubDate>
			<description><![CDATA[id:	6270872<br />first:	1353159002<br />last:	0<br />md5:	53ed38e02cae0f2e1391eaed2d98ad5f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=53ed38e02cae0f2e1391eaed2d98ad5f<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.GH<br />url:	http://expat-coaching.de/coaching-finanzen.html<br />recent:	up<br />response:	alive<br />ip:	31.47.251.18<br />as:	AS45012<br />review:	31.47.251.18<br />domain:	expat-coaching.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@mediawebline.de<br />inetnum:	31.47.240.0 - 31.47.255.255<br />netname:	DE-MEDIAWEBLINE-20110322<br />descr:	mediamedia<br />ns1:	ns2-tec.de<br />ns2:	ns1-tec.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cleaning4.co.uk/acatalog/directories.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6247693</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6247693</guid>
			<pubDate>2012-11-17T14:00:02+01:00</pubDate>
			<description><![CDATA[id:	6247693<br />first:	1353157202<br />last:	0<br />md5:	090ac525556345524126c5f83ec52fda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=090ac525556345524126c5f83ec52fda<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://cleaning4.co.uk/acatalog/directories.htm<br />recent:	up<br />response:	alive<br />ip:	216.130.165.31<br />as:	AS27257<br />review:	216.130.165.31<br />domain:	cleaning4.co.uk<br />country:	US<br />source:	ARIN<br />email:	abuse@webair.com<br />inetnum:	216.130.160.0 - 216.130.191.255<br />netname:	WEBAIRINTERNET<br />descr:	Webair Internet Development Company Inc. WAIR 1025 Old Country Road Suite 320 Westbury NY 11590-5645<br />ns1:	ns.webair.net<br />ns2:	ns2.webair.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://66.71.139.126/wp-includes/js/comment-reply.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=6247678</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PH.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=6247678</guid>
			<pubDate>2012-11-17T14:00:01+01:00</pubDate>
			<description><![CDATA[id:	6247678<br />first:	1353157201<br />last:	0<br />md5:	20ef5771571f1be483869066b2830c2f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a1f3d43851f20e26c4d76c4e725814b7<br />vt_score:	13/35 (37.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.PH.3<br />url:	http://66.71.139.126/wp-includes/js/comment-reply.js<br />recent:	up<br />response:	alive<br />ip:	66.71.139.126<br />as:	AS31034<br />review:	66.71.139.126<br />domain:	66.71.139.126<br />country:	US<br />source:	ARIN<br />email:	noc@9net.it<br />inetnum:	66.71.128.0 - 66.71.191.255<br />netname:	NETAPPSERV-1BLK<br />descr:	Network Application Services, Inc. NAS 1719 State Rt 10 Parsippany NJ 07054<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zeus.gau.hu/pipermail/lib-l.mbox/lib-l.mbox]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5768130</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PE_BUGBEAR.B-O]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5768130</guid>
			<pubDate>2012-11-16T18:50:42+01:00</pubDate>
			<description><![CDATA[id:	5768130<br />first:	1353088242<br />last:	0<br />md5:	d197b84e8a67e1eccee9af6855692c66<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d197b84e8a67e1eccee9af6855692c66<br />vt_score:	15/36 (41.7%)<br />scanner:	trendmicro<br />virusname:	PE_BUGBEAR.B-O<br />url:	http://zeus.gau.hu/pipermail/lib-l.mbox/lib-l.mbox<br />recent:	up<br />response:	alive<br />ip:	192.188.242.66<br />as:	ASError:<br />review:	192.188.242.66<br />domain:	gau.hu<br />country:	HU<br />source:	RIPE<br />email:	<br />inetnum:	<br />netname:	<br />descr:	<br />ns1:	gate.gau.hu<br />ns2:	linserv.abc.hu<br />ns3:	ns2.iif.hu<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tvparadise.info/download.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5755199</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5755199</guid>
			<pubDate>2012-11-16T18:20:02+01:00</pubDate>
			<description><![CDATA[id:	5755199<br />first:	1353086402<br />last:	0<br />md5:	4a7e91130c1ddcf667ab6504bbb1088c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://tvparadise.info/download.zip<br />recent:	up<br />response:	alive<br />ip:	184.172.165.16<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	184.172.165.16<br />domain:	tvparadise.info<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	184.172.0.0 - 184.173.255.255<br />netname:	NETBLK-THEPLANET-BLK-17<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns578.hostgator.com<br />ns2:	ns577.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sultoner.com.br/buscadores]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5742409</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5742409</guid>
			<pubDate>2012-11-16T18:00:05+01:00</pubDate>
			<description><![CDATA[id:	5742409<br />first:	1353085205<br />last:	0<br />md5:	482ca762b86393a6df5d57b0a9c790f8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=482ca762b86393a6df5d57b0a9c790f8<br />vt_score:	10/36 (27.8%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://sultoner.com.br/buscadores<br />recent:	up<br />response:	alive<br />ip:	189.38.80.77<br />as:	AS28299<br />review:	189.38.80.77<br />domain:	sultoner.com.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@kinghost.com.br<br />inetnum:	189.38.80.0 - 189.38.95.255<br />netname:	005.305.671/0001-84<br />descr:	Cyberweb Networks Ltda<br />ns1:	dns4.kinghost.com.br<br />ns2:	dns1.kinghost.com.br<br />ns3:	dns3.kinghost.com.br<br />ns4:	dns5.kinghost.com.br<br />ns5:	dns6.kinghost.com.br<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://stereoplace.it/highslide/highslide-full.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5742408</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Trojan.Iframe.S]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5742408</guid>
			<pubDate>2012-11-16T18:00:05+01:00</pubDate>
			<description><![CDATA[id:	5742408<br />first:	1353085205<br />last:	0<br />md5:	7e3c2dbd84cb22c461703b747fabb2a8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7e3c2dbd84cb22c461703b747fabb2a8<br />vt_score:	0/36 (0.0%)<br />scanner:	BitDefender<br />virusname:	JS:Trojan.Iframe.S<br />url:	http://stereoplace.it/highslide/highslide-full.js<br />recent:	up<br />response:	alive<br />ip:	151.1.162.8<br />as:	AS3242<br />review:	151.1.162.8<br />domain:	stereoplace.it<br />country:	IT<br />source:	RIPE<br />email:	registry@it.net<br />inetnum:	151.1.0.0 - 151.1.255.255<br />netname:	ITNET-WAN<br />descr:	ITnet S.p.A. - Genova - Italia<br />ns1:	ns2.omnibus.net<br />ns2:	ns1.omnibus.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://snison.de/js/dyn.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5742402</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.JY.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5742402</guid>
			<pubDate>2012-11-16T18:00:04+01:00</pubDate>
			<description><![CDATA[id:	5742402<br />first:	1353085204<br />last:	0<br />md5:	6bdad9080148fae8e909d9c727948c6d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6bdad9080148fae8e909d9c727948c6d<br />vt_score:	22/42 (52.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.JY.2<br />url:	http://snison.de/js/dyn.js<br />recent:	up<br />response:	alive<br />ip:	81.169.145.67<br />as:	AS6724<br />review:	81.169.145.67<br />domain:	snison.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	docks18.rzone.de<br />ns2:	shades03.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pennerstorfer.co.at/js/milkbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5692481</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-CI Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5692481</guid>
			<pubDate>2012-11-16T16:50:08+01:00</pubDate>
			<description><![CDATA[id:	5692481<br />first:	1353081008<br />last:	0<br />md5:	fc9ec8eae64f4e5c1f4ba6f9e1f794f0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fc9ec8eae64f4e5c1f4ba6f9e1f794f0<br />vt_score:	12/44 (27.3%)<br />scanner:	Avast<br />virusname:	JS:Illredir-CI Trj<br />url:	http://pennerstorfer.co.at/js/milkbox.js<br />recent:	up<br />response:	alive<br />ip:	193.19.92.209<br />as:	AS47692<br />review:	193.19.92.209<br />domain:	pennerstorfer.co.at<br />country:	AT<br />source:	RIPE<br />email:	hostmaster@hanival.com<br />inetnum:	193.19.92.0 - 193.19.93.255<br />netname:	HANIVAL-NET<br />descr:	Hanival Internet Services GmbHhanival.com Infrastructure ViennaHanival Internet Services GmbHHanival Internet Services GmbH<br />ns1:	ns2.hanival.com<br />ns2:	ns1.hanival.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://matrimonialemira.it/portale/vedibook]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5578296</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-JD [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5578296</guid>
			<pubDate>2012-11-16T16:05:12+01:00</pubDate>
			<description><![CDATA[id:	5578296<br />first:	1353078312<br />last:	0<br />md5:	219ffa7b1b1cdf90796c0b779b7f426f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=219ffa7b1b1cdf90796c0b779b7f426f<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-JD [Trj]<br />url:	http://matrimonialemira.it/portale/vedibook<br />recent:	up<br />response:	alive<br />ip:	62.149.128.151<br />as:	AS31034<br />review:	62.149.128.151<br />domain:	matrimonialemira.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=private]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5578210</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5578210</guid>
			<pubDate>2012-11-16T16:05:10+01:00</pubDate>
			<description><![CDATA[id:	5578210<br />first:	1353078310<br />last:	0<br />md5:	167a56ee56e216cd24ce5fc8099055a6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=167a56ee56e216cd24ce5fc8099055a6<br />vt_score:	23/32 (71.9%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=private<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=mandidee-pixandvideo&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5578209</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5578209</guid>
			<pubDate>2012-11-16T16:05:10+01:00</pubDate>
			<description><![CDATA[id:	5578209<br />first:	1353078310<br />last:	0<br />md5:	aa131e607d465e227d15d84519018252<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aa131e607d465e227d15d84519018252<br />vt_score:	22/33 (66.7%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=mandidee-pixandvideo&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kijowski.pl/ojciec.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5578129</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5578129</guid>
			<pubDate>2012-11-16T16:05:08+01:00</pubDate>
			<description><![CDATA[id:	5578129<br />first:	1353078308<br />last:	0<br />md5:	f178eae080569f399c17ef8409fb05da<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8161ab425c7fbbdae0d723cf1034aac9<br />vt_score:	18/40 (45%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://kijowski.pl/ojciec.html<br />recent:	up<br />response:	alive<br />ip:	77.79.246.200<br />as:	AS15694<br />review:	77.79.247.160<br />domain:	kijowski.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@atman.pl<br />inetnum:	77.79.244.0 - 77.79.247.255<br />netname:	PROGRESO-PL<br />descr:	Progreso #1ul. 1 Maja 744-330 Jastrzebie Zdroj<br />ns1:	d.ns1.pl<br />ns2:	d.ns2.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jachtingchorwacja.eu/panel/jachtingjava.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5578047</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_ONLOAD.SMD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5578047</guid>
			<pubDate>2012-11-16T16:05:05+01:00</pubDate>
			<description><![CDATA[id:	5578047<br />first:	1353078305<br />last:	0<br />md5:	63e254b0a4e286aefec6afcde874589f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=63e254b0a4e286aefec6afcde874589f<br />vt_score:	13/36 (36.1%)<br />scanner:	trendmicro<br />virusname:	JS_ONLOAD.SMD<br />url:	http://jachtingchorwacja.eu/panel/jachtingjava.js<br />recent:	up<br />response:	alive<br />ip:	79.96.159.236<br />as:	AS12824<br />review:	79.96.159.236<br />domain:	jachtingchorwacja.eu<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://halat.com.tr/intranet]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5577970</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5577970</guid>
			<pubDate>2012-11-16T16:05:03+01:00</pubDate>
			<description><![CDATA[id:	5577970<br />first:	1353078303<br />last:	0<br />md5:	9cd8281202b0fbba988c6611adf60193<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9cd8281202b0fbba988c6611adf60193<br />vt_score:	20/34 (58.8%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://halat.com.tr/intranet<br />recent:	up<br />response:	alive<br />ip:	213.144.112.11<br />as:	AS25145<br />review:	213.144.112.11<br />domain:	halat.com.tr<br />country:	TR<br />source:	RIPE<br />email:	alper.selcuk@teknotel.com<br />inetnum:	213.144.96.0 - 213.144.127.255<br />netname:	TR-TEKNOTEL-20020729<br />descr:	TEKNOTEL TELEKOMUNIKASYON SANAYI VE TICARET A.S.Teknotel A.STEKNOTEL<br />ns1:	ns1.teknotel.net<br />ns2:	ns2.teknotel.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://graphic-design.ca:16080/~tpaul/content_new.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5577964</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5577964</guid>
			<pubDate>2012-11-16T16:05:03+01:00</pubDate>
			<description><![CDATA[id:	5577964<br />first:	1353078303<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://graphic-design.ca:16080/~tpaul/content_new.htm<br />recent:	up<br />response:	alive<br />ip:	205.211.140.114<br />as:	ASError:<br />review:	205.211.140.114<br />domain:	graphic-design.ca<br />country:	CA<br />source:	ARIN<br />email:	noc@largnet.ca<br />inetnum:	<br />netname:	<br />descr:	<br />ns1:	dns1.largnet.on.ca<br />ns2:	ns1.fanshawec.ca<br />ns3:	ns2.fanshawec.ca<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fiatcoupepassion.it/clientscript/vbulletin_lightbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5577827</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5577827</guid>
			<pubDate>2012-11-16T16:05:00+01:00</pubDate>
			<description><![CDATA[id:	5577827<br />first:	1353078300<br />last:	0<br />md5:	90713234f0790976e86669670827c147<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4124bcc9fb534f92691381bd3dab7c24<br />vt_score:	12/36 (33.3%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA Trj<br />url:	http://fiatcoupepassion.it/clientscript/vbulletin_lightbox.js<br />recent:	up<br />response:	alive<br />ip:	195.110.124.133<br />as:	AS12363<br />review:	195.110.124.133<br />domain:	fiatcoupepassion.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@dada.net<br />inetnum:	195.110.124.128 - 195.110.124.191<br />netname:	register-it<br />descr:	Register.it S.p.A.DADANETInternet Service ProviderDADANETInternet Service Provider<br />ns1:	ns1.register.it<br />ns2:	ns2.register.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bremen-onfire.de/klopf.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5577604</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent.opd]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5577604</guid>
			<pubDate>2012-11-16T16:04:53+01:00</pubDate>
			<description><![CDATA[id:	5577604<br />first:	1353078293<br />last:	0<br />md5:	d42690c8801b045d817a6123e15e0188<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d42690c8801b045d817a6123e15e0188<br />vt_score:	19/27 (70.4%)<br />scanner:	avira<br />virusname:	HTML/Agent.opd<br />url:	http://bremen-onfire.de/klopf.htm<br />recent:	up<br />response:	alive<br />ip:	82.165.96.117<br />as:	AS8560<br />review:	82.165.96.117<br />domain:	bremen-onfire.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns35.1und1.de<br />ns2:	ns36.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ateliertre.ch/swfaddress/swfaddress.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5577599</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.S]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5577599</guid>
			<pubDate>2012-11-16T16:04:53+01:00</pubDate>
			<description><![CDATA[id:	5577599<br />first:	1353078293<br />last:	0<br />md5:	be4d4a4b00ed0b1656e96d7d8a991f7e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be4d4a4b00ed0b1656e96d7d8a991f7e<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/Blacole.S<br />url:	http://ateliertre.ch/swfaddress/swfaddress.js<br />recent:	up<br />response:	alive<br />ip:	77.109.132.143<br />as:	ASNA.77.0.0.0 - 95.255.255.255<br />review:	77.109.132.143<br />domain:	ateliertre.ch<br />country:	CH<br />source:	RIPE<br />email:	abuse@ripe.net<br />inetnum:	77.0.0.0 - 95.255.255.255<br />netname:	EU-ZZ-80-93<br />descr:	RIPE NCCEuropean Regional Registry<br />ns1:	ns1.idea-net.ch<br />ns2:	ns2.idea-net.ch<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://saar-residenz.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5262844</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Prontexi.dza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5262844</guid>
			<pubDate>2012-11-15T19:01:23+01:00</pubDate>
			<description><![CDATA[id:	5262844<br />first:	1353002483<br />last:	0<br />md5:	05c229c9966f4bf1140362773114d406<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cccfa8921663a3e5fac6c487f67c804b<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	JS/Prontexi.dza<br />url:	http://saar-residenz.de/<br />recent:	up<br />response:	alive<br />ip:	212.88.134.59<br />as:	AS9063<br />review:	212.88.134.59<br />domain:	saar-residenz.de<br />country:	DE<br />source:	RIPE<br />email:	registration@saargate.de<br />inetnum:	212.88.134.0 - 212.88.134.63<br />netname:	TERESTO-HOUSING-NET2<br />descr:	TERESTO Kunden-Router/Firewalls (Housing 2)VSENET / Teresto / artelisNell-Breunig-Allee 6D-66115 Saarbruecken<br />ns1:	ns4.teresto.net<br />ns2:	ns1.teresto.net<br />ns3:	ns2.teresto.net<br />ns4:	ns3.teresto.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fiatcoupepassion.it/clientscript/vbulletin_global.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5262822</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-AOA Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5262822</guid>
			<pubDate>2012-11-15T19:01:23+01:00</pubDate>
			<description><![CDATA[id:	5262822<br />first:	1353002483<br />last:	0<br />md5:	ba37d386a40f490f947043a0a8debe41<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=add160695e2b3071632a4d3ef3741a37<br />vt_score:	11/36 (30.6%)<br />scanner:	Avast<br />virusname:	JS:Agent-AOA Trj<br />url:	http://fiatcoupepassion.it/clientscript/vbulletin_global.js<br />recent:	up<br />response:	alive<br />ip:	195.110.124.133<br />as:	AS12363<br />review:	195.110.124.133<br />domain:	fiatcoupepassion.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@dada.net<br />inetnum:	195.110.124.128 - 195.110.124.191<br />netname:	register-it<br />descr:	Register.it S.p.A.DADANETInternet Service ProviderDADANETInternet Service Provider<br />ns1:	ns1.register.it<br />ns2:	ns2.register.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://festeaziendali.it/js/scriptaculous.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5262821</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PH.3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5262821</guid>
			<pubDate>2012-11-15T19:01:23+01:00</pubDate>
			<description><![CDATA[id:	5262821<br />first:	1353002483<br />last:	0<br />md5:	dc567e96e869edd2e41d43da0c659a72<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dc567e96e869edd2e41d43da0c659a72<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.PH.3<br />url:	http://festeaziendali.it/js/scriptaculous.js<br />recent:	up<br />response:	alive<br />ip:	93.95.217.99<br />as:	AS3313<br />review:	93.95.217.99<br />domain:	festeaziendali.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@inet.it<br />inetnum:	93.95.216.0 - 93.95.219.255<br />netname:	SERVERPLAN<br />descr:	Serverplan network1Serverplan S.r.l.<br />ns1:	ns1.activenight.it<br />ns2:	ns2.activenight.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://arbeitsrecht-infoline.de/bag-gleichbehandlung.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5262786</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5262786</guid>
			<pubDate>2012-11-15T19:01:23+01:00</pubDate>
			<description><![CDATA[id:	5262786<br />first:	1353002483<br />last:	0<br />md5:	ace45bc26208149d7269643a13907d39<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ace45bc26208149d7269643a13907d39<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://arbeitsrecht-infoline.de/bag-gleichbehandlung.htm<br />recent:	up<br />response:	alive<br />ip:	94.102.218.245<br />as:	AS41078<br />review:	94.102.218.245<br />domain:	arbeitsrecht-infoline.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@antagus.de<br />inetnum:	94.102.216.0 - 94.102.219.255<br />netname:	NETBEAT-HOSTING<br />descr:	NetBeat Domain Hosting FarmAntagus GmbH<br />ns1:	ns1.netbeat.de<br />ns2:	ns2.netbeat.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aquaeipsitanae.it/shipping_label_usps.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5262785</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Buzus.mrbz]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5262785</guid>
			<pubDate>2012-11-15T19:01:23+01:00</pubDate>
			<description><![CDATA[id:	5262785<br />first:	1353002483<br />last:	0<br />md5:	6fbdee5b1fba21d73e29bf3addca0b8f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6fbdee5b1fba21d73e29bf3addca0b8f<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	TR/Buzus.mrbz<br />url:	http://aquaeipsitanae.it/shipping_label_usps.zip<br />recent:	up<br />response:	alive<br />ip:	195.225.168.113<br />as:	AS31034<br />review:	195.225.168.113<br />domain:	aquaeipsitanae.it<br />country:	IT<br />source:	RIPE<br />email:	omero.narducci@widestore.net<br />inetnum:	195.225.168.0 - 195.225.171.255<br />netname:	WIDESTORE-IT-02<br />descr:	Widestore s.r.l.Widestore s.r.l.<br />ns1:	dns.sitesolutions.it<br />ns2:	dns2.sitesolutions.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://acmeinteriors.co.in/acme/AC_RunActiveContent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=5168923</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=5168923</guid>
			<pubDate>2012-11-15T00:09:57+01:00</pubDate>
			<description><![CDATA[id:	5168923<br />first:	1352934597<br />last:	0<br />md5:	ddbe3d60fbf2c4033052fd0400201501<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bd4390bffced3ecf740db2c3e0d752c2<br />vt_score:	22/42 (52.4%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://acmeinteriors.co.in/acme/AC_RunActiveContent.js<br />recent:	up<br />response:	alive<br />ip:	173.201.141.128<br />as:	AS26496<br />review:	173.201.141.128<br />domain:	acmeinteriors.co.in<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	173.201.0.0 - 173.201.255.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ganeshamgroup.venus.orderbox-dns.com<br />ns2:	ganeshamgroup.mercury.orderbox-dns.com<br />ns3:	ganeshamgroup.earth.orderbox-dns.com<br />ns4:	ganeshamgroup.mars.orderbox-dns.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://xfaqmmg.bookonline.com.cn/freepage/pubimg/download.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4593197</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4593197</guid>
			<pubDate>2012-11-14T17:20:05+01:00</pubDate>
			<description><![CDATA[id:	4593197<br />first:	1352910005<br />last:	0<br />md5:	50015d6f3961316776af3a2f3dd41c0f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50015d6f3961316776af3a2f3dd41c0f<br />vt_score:	20/40 (50%)<br />scanner:	AntiVir<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://xfaqmmg.bookonline.com.cn/freepage/pubimg/download.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns1.dnspod.net<br />ns2:	f1g1ns2.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://volvo740rallyteam.nl/Almere/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4593192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4593192</guid>
			<pubDate>2012-11-14T17:20:05+01:00</pubDate>
			<description><![CDATA[id:	4593192<br />first:	1352910005<br />last:	0<br />md5:	e127693f8e8f0c280799c07815659c34<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e127693f8e8f0c280799c07815659c34<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://volvo740rallyteam.nl/Almere/index.html<br />recent:	up<br />response:	alive<br />ip:	194.213.126.120<br />as:	AS51331<br />review:	194.213.126.120<br />domain:	volvo740rallyteam.nl<br />country:	NL<br />source:	RIPE<br />email:	info@yourname.nl<br />inetnum:	194.213.126.0 - 194.213.127.255<br />netname:	YourName<br />descr:	Your Name WebhostingYour Name WebhostingYourname WebhostingYour Name Webhosting<br />ns1:	ns.yournamehosting.com<br />ns2:	ns.yournamewebhosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://std.dkuug.dk/jtc1/sc22/wg15/iso14766/65]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4570040</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Klez.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4570040</guid>
			<pubDate>2012-11-14T17:00:08+01:00</pubDate>
			<description><![CDATA[id:	4570040<br />first:	1352908808<br />last:	0<br />md5:	8c6b9cba0887a3c9c63bfe16796eb7f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8c6b9cba0887a3c9c63bfe16796eb7f2<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	WORM/Klez.E<br />url:	http://std.dkuug.dk/jtc1/sc22/wg15/iso14766/65<br />recent:	up<br />response:	alive<br />ip:	195.215.30.152<br />as:	AS3292<br />review:	195.215.30.152<br />domain:	dkuug.dk<br />country:	DK<br />source:	RIPE<br />email:	nihb@tdc.dk<br />inetnum:	195.215.0.0 - 195.215.255.255<br />netname:	DK-TELEDANMARK-971007<br />descr:	TDC A/STele Danmark<br />ns1:	ns2.dkuug.dk<br />ns2:	ns1.dkuug.dk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sigabrasil.com.br/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4570033</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.ahf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4570033</guid>
			<pubDate>2012-11-14T17:00:08+01:00</pubDate>
			<description><![CDATA[id:	4570033<br />first:	1352908808<br />last:	0<br />md5:	9bc1c1a296dbdec45c8aa8cdbd364297<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9bc1c1a296dbdec45c8aa8cdbd364297<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	JS/Agent.ahf<br />url:	http://sigabrasil.com.br/<br />recent:	up<br />response:	alive<br />ip:	200.219.245.186<br />as:	AS16397<br />review:	200.219.245.186<br />domain:	sigabrasil.com.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@comdominio.com.br<br />inetnum:	200.219.224.0 - 200.219.255.255<br />netname:	003.672.254/0001-44<br />descr:	Alog-02 Soluções de Tecnologia em Informática S.A.<br />ns1:	ns1.bighost.com.br<br />ns2:	ns2.bighost.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rudolfwoelki.gmxhome.de/html/mikroskopfotografie.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4569938</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4569938</guid>
			<pubDate>2012-11-14T16:50:05+01:00</pubDate>
			<description><![CDATA[id:	4569938<br />first:	1352908205<br />last:	0<br />md5:	30f5c110e2ef70d6ee091afb6a4f4754<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30f5c110e2ef70d6ee091afb6a4f4754<br />vt_score:	9/36 (25%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-inf<br />url:	http://rudolfwoelki.gmxhome.de/html/mikroskopfotografie.html<br />recent:	up<br />response:	alive<br />ip:	82.165.127.197<br />as:	AS8560<br />review:	82.165.127.197<br />domain:	gmxhome.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns9.schlund.de<br />ns2:	ns10.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pinolecce.it/classici.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4569935</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-S Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4569935</guid>
			<pubDate>2012-11-14T16:50:05+01:00</pubDate>
			<description><![CDATA[id:	4569935<br />first:	1352908205<br />last:	0<br />md5:	f0eb4b44a7f4780a1deaedabfae9f53b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f0eb4b44a7f4780a1deaedabfae9f53b<br />vt_score:	9/36 (25%)<br />scanner:	Avast<br />virusname:	JS:Illredir-S Trj<br />url:	http://pinolecce.it/classici.htm<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	pinolecce.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns3.arubadns.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mole2k.co.uk/photocomp/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4569929</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.PT.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4569929</guid>
			<pubDate>2012-11-14T16:50:04+01:00</pubDate>
			<description><![CDATA[id:	4569929<br />first:	1352908204<br />last:	0<br />md5:	30af29171a9c062cf1551c0319572a3e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=30af29171a9c062cf1551c0319572a3e<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	HTML/IFrame.PT.1<br />url:	http://mole2k.co.uk/photocomp/<br />recent:	up<br />response:	alive<br />ip:	209.217.225.181<br />as:	AS3595<br />review:	209.217.225.181<br />domain:	mole2k.co.uk<br />country:	US<br />source:	ARIN<br />email:	greg@jaguarpc.com<br />inetnum:	209.217.224.0 - 209.217.239.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns2-collin.nswebhost.com<br />ns2:	ns1-collin.nswebhost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jg-gornau.de/Inhalt/Alt/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4525096</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-AX [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4525096</guid>
			<pubDate>2012-11-14T16:20:04+01:00</pubDate>
			<description><![CDATA[id:	4525096<br />first:	1352906404<br />last:	0<br />md5:	9657636d5714c5dc61df49314ed71d37<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9657636d5714c5dc61df49314ed71d37<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	JS:Illredir-AX [Trj]<br />url:	http://jg-gornau.de/Inhalt/Alt/index.html<br />recent:	up<br />response:	alive<br />ip:	85.13.129.57<br />as:	AS34788<br />review:	85.13.129.57<br />domain:	jg-gornau.de<br />country:	DE<br />source:	RIPE<br />email:	ip@all-inkl.com<br />inetnum:	85.13.128.0 - 85.13.191.255<br />netname:	DE-ALL-INKL-20050405<br />descr:	Neue Medien Muennich<br />ns1:	ns3.kasserver.com<br />ns2:	ns4.kasserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://grbaonline.org/scripts/ac_runactivecontent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4503392</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Infected.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4503392</guid>
			<pubDate>2012-11-14T16:00:06+01:00</pubDate>
			<description><![CDATA[id:	4503392<br />first:	1352905206<br />last:	0<br />md5:	ff5b9fb1ba12dc11201228f6857a5f7a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ff5b9fb1ba12dc11201228f6857a5f7a<br />vt_score:	28/36 (77.8%)<br />scanner:	avira<br />virusname:	JS/Infected.C<br />url:	http://grbaonline.org/scripts/ac_runactivecontent.js<br />recent:	up<br />response:	alive<br />ip:	74.208.141.241<br />as:	AS8560<br />review:	74.208.141.241<br />domain:	grbaonline.org<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns27.1and1.com<br />ns2:	ns28.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fuss-und-pedalreisen.de/typo3conf/_img/_class.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4503298</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4503298</guid>
			<pubDate>2012-11-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	4503298<br />first:	1352904604<br />last:	0<br />md5:	ffd33857aa2609bd10e76de851660f90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ffd33857aa2609bd10e76de851660f90<br />vt_score:	15/23 (65.2%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://fuss-und-pedalreisen.de/typo3conf/_img/_class.html<br />recent:	up<br />response:	alive<br />ip:	212.162.52.27<br />as:	AS9829<br />review:	212.162.52.27<br />domain:	fuss-und-pedalreisen.de<br />country:	de<br />source:	RIPE<br />email:	abuse@level3.com<br />inetnum:	212.162.52.0 - 212.162.53.255<br />netname:	SECURENETZ-DE<br />descr:	Secure-Netz<br />ns1:	ns03.nethosting4you.de<br />ns2:	ns02.nethosting4you.de<br />ns3:	ns04.nethosting4you.de<br />ns4:	ns01.nethosting4you.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fotoszym.pl/koncert/album/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4503296</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/SrcInject.N]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4503296</guid>
			<pubDate>2012-11-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	4503296<br />first:	1352904604<br />last:	0<br />md5:	08307c5ef9d8909a0a81fc383523b524<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=08307c5ef9d8909a0a81fc383523b524<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	JS/SrcInject.N<br />url:	http://fotoszym.pl/koncert/album/index.html<br />recent:	up<br />response:	alive<br />ip:	62.129.237.252<br />as:	AS12824<br />review:	62.129.237.252<br />domain:	fotoszym.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.224.0 - 62.129.239.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://erp.onsec.net.cn/test/ie.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4503292</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.bhm.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4503292</guid>
			<pubDate>2012-11-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	4503292<br />first:	1352904604<br />last:	0<br />md5:	cd5cde54a7af1eae614d717e32b22521<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cd5cde54a7af1eae614d717e32b22521<br />vt_score:	15/40 (37.5%)<br />scanner:	avira<br />virusname:	TR/Agent.bhm.1<br />url:	http://erp.onsec.net.cn/test/ie.html<br />recent:	up<br />response:	alive<br />ip:	125.171.1.12<br />as:	AS4134<br />review:	125.171.1.12<br />domain:	onsec.net.cn<br />country:	CN<br />source:	APNIC<br />email:	ken.zeng@etrunk.cn<br />inetnum:	125.171.0.0 - 125.171.255.255<br />netname:	eTrunk<br />descr:	eTrunk Network Telecomunication Ltd.Guangzhou,7/F WangYuan Building,No 62 Meibinbei Road,MeiHuaYuan, Guangzhou, China<br />ns1:	ns1.95820.net<br />ns2:	ns2.95820.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://d8788780.u128.hoststore.info/Juhhud_IUA.ASp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4441091</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML_IFRAME.DEF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4441091</guid>
			<pubDate>2012-11-14T15:00:19+01:00</pubDate>
			<description><![CDATA[id:	4441091<br />first:	1352901619<br />last:	0<br />md5:	5117f8c30f17793277dcc4e6716b2b3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5117f8c30f17793277dcc4e6716b2b3b<br />vt_score:	14/36 (38.9%)<br />scanner:	trendmicro<br />virusname:	HTML_IFRAME.DEF<br />url:	http://d8788780.u128.hoststore.info/Juhhud_IUA.ASp<br />recent:	up<br />response:	alive<br />ip:	173.0.143.204<br />as:	AS53628<br />review:	173.0.143.204<br />domain:	hoststore.info<br />country:	US<br />source:	ARIN<br />email:	abuse@jdnextgen.com<br />inetnum:	173.0.128.0 - 173.0.143.255<br />netname:	APYLI-AS<br />descr:	Apyl Inc APYLI-1 1517 E Hillcrest Street Orlando FL 32803<br />ns1:	ns2.hoststore.info<br />ns2:	ns.hoststore.info<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cleaning4.co.uk/acatalog//directories.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4441014</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4441014</guid>
			<pubDate>2012-11-14T15:00:08+01:00</pubDate>
			<description><![CDATA[id:	4441014<br />first:	1352901608<br />last:	0<br />md5:	090ac525556345524126c5f83ec52fda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=090ac525556345524126c5f83ec52fda<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://cleaning4.co.uk/acatalog//directories.htm<br />recent:	up<br />response:	alive<br />ip:	216.130.165.31<br />as:	AS27257<br />review:	216.130.165.31<br />domain:	cleaning4.co.uk<br />country:	US<br />source:	ARIN<br />email:	abuse@webair.com<br />inetnum:	216.130.160.0 - 216.130.191.255<br />netname:	WEBAIRINTERNET<br />descr:	Webair Internet Development Company Inc. WAIR 1025 Old Country Road Suite 320 Westbury NY 11590-5645<br />ns1:	ns.webair.net<br />ns2:	ns2.webair.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://6.duote.com.cn/qqkjhc.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4383132</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4383132</guid>
			<pubDate>2012-11-14T13:50:12+01:00</pubDate>
			<description><![CDATA[id:	4383132<br />first:	1352897412<br />last:	0<br />md5:	7afbf06c6d944a7a1d78623c90ef8f39<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7afbf06c6d944a7a1d78623c90ef8f39<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://6.duote.com.cn/qqkjhc.zip<br />recent:	up<br />response:	alive<br />ip:	218.75.155.216<br />as:	AS4134<br />review:	218.75.155.240<br />domain:	duote.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	218.75.128.0 - 218.75.159.255<br />netname:	CHINANET-HN-CD<br />descr:	CHINANET-HN changde node networkhunan Telecom<br />ns1:	dns3.50bang.org<br />ns2:	dns1.kabasiji.com<br />ns3:	dns2.kabasiji.com<br />ns4:	dns4.50bang.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://2007jointmeeting.org/schedule/user/login/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4383053</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4383053</guid>
			<pubDate>2012-11-14T13:50:03+01:00</pubDate>
			<description><![CDATA[id:	4383053<br />first:	1352897403<br />last:	0<br />md5:	fe57211fa2f3d3d99c343d7323310082<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fe57211fa2f3d3d99c343d7323310082<br />vt_score:	9/36 (25%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://2007jointmeeting.org/schedule/user/login/<br />recent:	up<br />response:	alive<br />ip:	69.41.230.10<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	69.41.230.10<br />domain:	2007jointmeeting.org<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	69.41.224.0 - 69.41.255.255<br />netname:	NETBLK-THEPLANET-BLK-6<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	sns18.websitewelcome.com<br />ns2:	sns17.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sada.org.ar/Catan/Tp_2007/tp_1/polinizacion.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4364861</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4364861</guid>
			<pubDate>2012-11-14T13:40:04+01:00</pubDate>
			<description><![CDATA[id:	4364861<br />first:	1352896804<br />last:	0<br />md5:	2e73814be70a6be904a9ec5e308ad0c6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2e73814be70a6be904a9ec5e308ad0c6<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-inf<br />url:	http://sada.org.ar/Catan/Tp_2007/tp_1/polinizacion.htm<br />recent:	up<br />response:	alive<br />ip:	200.69.195.15<br />as:	AS16814<br />review:	200.69.195.15<br />domain:	sada.org.ar<br />country:	AR<br />source:	LACNIC<br />email:	abuse@iplan.com.ar<br />inetnum:	200.69.192.0 - 200.69.255.255<br />netname:	AR-NSSA-LACNIC<br />descr:	NSS S.A.Reconquista, 865, 2C1003ABQ - Buenos Aires - CFReconquista, 865,1003 - Buenos Aires -<br />ns1:	ns.sada.org.ar<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hebammenseite.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4097223</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4097223</guid>
			<pubDate>2012-11-14T07:20:03+01:00</pubDate>
			<description><![CDATA[id:	4097223<br />first:	1352874003<br />last:	0<br />md5:	b3b3e75de7ad8d3252e617192fe948ad<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b3b3e75de7ad8d3252e617192fe948ad<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://hebammenseite.de/<br />recent:	up<br />response:	alive<br />ip:	91.223.141.107<br />as:	AS25504<br />review:	91.223.141.107<br />domain:	hebammenseite.de<br />country:	DE<br />source:	RIPE<br />email:	patrick@argonius.de<br />inetnum:	91.223.141.0 - 91.223.141.255<br />netname:	FLUSHMEDIA-NET<br />descr:	Patrick Kaiser--------------------------------------------------Flush Media--------------------------------------------------FLUSHMEDIA-NET<br />ns1:	srvdns01.yopeho-server.de<br />ns2:	srvdns02.yopeho-server.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tipografiagonzalez.com.ar/villaurquiza/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3835137</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS_GUMBLAR.SMNY]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3835137</guid>
			<pubDate>2012-11-13T16:20:06+01:00</pubDate>
			<description><![CDATA[id:	3835137<br />first:	1352820006<br />last:	0<br />md5:	772abdca68a6e97f5e59b420acbb93d6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=772abdca68a6e97f5e59b420acbb93d6<br />vt_score:	16/34 (47.1%)<br />scanner:	trendmicro<br />virusname:	JS_GUMBLAR.SMNY<br />url:	http://tipografiagonzalez.com.ar/villaurquiza/index.htm<br />recent:	up<br />response:	alive<br />ip:	216.147.2.225<br />as:	AS11022<br />review:	216.147.2.225<br />domain:	tipografiagonzalez.com.ar<br />country:	US<br />source:	ARIN<br />email:	donglee@alabanza.com<br />inetnum:	216.147.0.0 - 216.147.127.255<br />netname:	ALABANZA-BALT-2<br />descr:	Alabanza, Inc. ALAB 10 East Baltimore St., 10th floor Baltimore MD 21202<br />ns1:	ns2.pageimpact.com<br />ns2:	ns.pageimpact.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://telgisz.hu/osztalyok/12B/index_2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3826994</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.FX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3826994</guid>
			<pubDate>2012-11-13T15:50:23+01:00</pubDate>
			<description><![CDATA[id:	3826994<br />first:	1352818223<br />last:	0<br />md5:	c960f2d9854479a1a62803dcdf7e6313<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c960f2d9854479a1a62803dcdf7e6313<br />vt_score:	15/36 (41.7%)<br />scanner:	avira<br />virusname:	JS/Redirector.FX<br />url:	http://telgisz.hu/osztalyok/12B/index_2.html<br />recent:	up<br />response:	alive<br />ip:	92.61.120.4<br />as:	AS44302<br />review:	92.61.120.4<br />domain:	telgisz.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@iec.hu<br />inetnum:	92.61.112.0 - 92.61.127.255<br />netname:	HU-IEC-20071219<br />descr:	InterEuro Computer Ltd.abuse@iec.hu<br />ns1:	ns2.telgisz.hu<br />ns2:	ns1.telgisz.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sv80.de/Material/bilder/Schuetzenfest+2007/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3826990</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3826990</guid>
			<pubDate>2012-11-13T15:50:22+01:00</pubDate>
			<description><![CDATA[id:	3826990<br />first:	1352818222<br />last:	0<br />md5:	b1b4c029fbcd06272a51cdcdec8db96f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b1b4c029fbcd06272a51cdcdec8db96f<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://sv80.de/Material/bilder/Schuetzenfest+2007/index.html<br />recent:	up<br />response:	alive<br />ip:	82.165.84.98<br />as:	AS8560<br />review:	82.165.84.98<br />domain:	sv80.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns38.1und1.de<br />ns2:	ns37.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://plaza-stegeman.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3819886</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.OR]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3819886</guid>
			<pubDate>2012-11-13T15:30:07+01:00</pubDate>
			<description><![CDATA[id:	3819886<br />first:	1352817007<br />last:	0<br />md5:	f08d14bb6cd5bad3149d2296ee826685<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f08d14bb6cd5bad3149d2296ee826685<br />vt_score:	0/36 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.OR<br />url:	http://plaza-stegeman.nl/<br />recent:	up<br />response:	alive<br />ip:	46.249.34.173<br />as:	AS50673<br />review:	46.249.34.173<br />domain:	plaza-stegeman.nl<br />country:	NL<br />source:	RIPE<br />email:	gijs@serverius.nl<br />inetnum:	46.249.34.128 - 46.249.34.191<br />netname:	CUST-Hosting-On-Demand<br />descr:	Hosting on DemandServerius Route Object<br />ns1:	ns2.hostingondemand.nl<br />ns2:	ns1.hostingondemand.org<br />ns3:	ns3.ibmhosting.eu<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pioneer.netserv.chula.ac.th/%7Eiapinun/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3819885</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3819885</guid>
			<pubDate>2012-11-13T15:30:07+01:00</pubDate>
			<description><![CDATA[id:	3819885<br />first:	1352817007<br />last:	0<br />md5:	8d1c26755a458aae5375b0b8ac6d44a1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8d1c26755a458aae5375b0b8ac6d44a1<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://pioneer.netserv.chula.ac.th/%7Eiapinun/<br />recent:	up<br />response:	alive<br />ip:	161.200.192.25<br />as:	AS3839<br />review:	161.200.192.25<br />domain:	chula.ac.th<br />country:	TH<br />source:	APNIC<br />email:	chaya.l@chula.ac.th<br />inetnum:	161.200.0.0 - 161.200.255.255<br />netname:	CHULANET<br />descr:	imported inetnum object for CHULAL<br />ns1:	ns.netserv.chula.ac.th<br />ns2:	explorer.netserv.chula.ac.th<br />ns3:	ns.thnic.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://matrimonialemira.it/portale/vedibook/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3813043</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-JD [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3813043</guid>
			<pubDate>2012-11-13T15:10:23+01:00</pubDate>
			<description><![CDATA[id:	3813043<br />first:	1352815823<br />last:	0<br />md5:	219ffa7b1b1cdf90796c0b779b7f426f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=219ffa7b1b1cdf90796c0b779b7f426f<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-JD [Trj]<br />url:	http://matrimonialemira.it/portale/vedibook/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.160<br />domain:	matrimonialemira.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns2.technorail.com<br />ns3:	dns3.arubadns.net<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://logos.or.kr/logos/skin/nzeo_ver3/line.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3813039</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Giframe.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3813039</guid>
			<pubDate>2012-11-13T15:10:23+01:00</pubDate>
			<description><![CDATA[id:	3813039<br />first:	1352815823<br />last:	0<br />md5:	8458ad7031a5275d386802396de99672<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	TR/Giframe.A<br />url:	http://logos.or.kr/logos/skin/nzeo_ver3/line.gif<br />recent:	up<br />response:	alive<br />ip:	220.95.231.73<br />as:	AS4766<br />review:	115.68.15.190<br />domain:	logos.or.kr<br />country:	KR<br />source:	APNIC<br />email:	network@smileserv.com<br />inetnum:	220.92.0.0 - 220.95.255.255<br />netname:	SMILESERV-KR<br />descr:	SMILESERV<br />ns1:	ns.logos.or.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKaezraver.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3813038</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3813038</guid>
			<pubDate>2012-11-13T15:10:23+01:00</pubDate>
			<description><![CDATA[id:	3813038<br />first:	1352815823<br />last:	0<br />md5:	36de603f1e72e0d154276a2a40b4f434<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36de603f1e72e0d154276a2a40b4f434<br />vt_score:	12/33 (36.4%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKaezraver.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fullmotion.hu/js/prototype.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3802422</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Infected.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3802422</guid>
			<pubDate>2012-11-13T14:31:59+01:00</pubDate>
			<description><![CDATA[id:	3802422<br />first:	1352813519<br />last:	0<br />md5:	dfc0d9592ad7c05106dda52a1c5306dc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dfc0d9592ad7c05106dda52a1c5306dc<br />vt_score:	23/37 (62.2%)<br />scanner:	avira<br />virusname:	JS/Infected.C<br />url:	http://fullmotion.hu/js/prototype.js<br />recent:	up<br />response:	alive<br />ip:	84.2.35.129<br />as:	AS5483<br />review:	84.2.35.169<br />domain:	fullmotion.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@t-online.hu<br />inetnum:	84.2.34.128 - 84.2.35.255<br />netname:	DATAPLEX-UGYFEL<br />descr:	Magyar Telekomsplit block ,  Hosting84.2.34.0/25 abuse@netvertise.us TP1087-RIPE<br />ns1:	ns1.web-server.hu<br />ns2:	ns2.web-server.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://exacta.pl/krelbud/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3802417</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3802417</guid>
			<pubDate>2012-11-13T14:31:59+01:00</pubDate>
			<description><![CDATA[id:	3802417<br />first:	1352813519<br />last:	0<br />md5:	faaf0f6c5f8d99b49c07b3363e73510a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=faaf0f6c5f8d99b49c07b3363e73510a<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://exacta.pl/krelbud/<br />recent:	up<br />response:	alive<br />ip:	193.218.152.132<br />as:	AS41079<br />review:	193.218.152.132<br />domain:	exacta.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@superhost.pl<br />inetnum:	193.218.152.0 - 193.218.155.255<br />netname:	SUPERHOST-PL<br />descr:	SuperHost.pl Sp. z o.o.<br />ns1:	ns2.aidahosting.com<br />ns2:	ns1.aidahosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://catour.com.vn/images/Baocaotaichinh%20tom%20tat.xls]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3782253</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[XF/Sic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3782253</guid>
			<pubDate>2012-11-13T14:13:19+01:00</pubDate>
			<description><![CDATA[id:	3782253<br />first:	1352812399<br />last:	0<br />md5:	3cfa0f77d7e6602c67417c7791af3ba2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3cfa0f77d7e6602c67417c7791af3ba2<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	XF/Sic<br />url:	http://catour.com.vn/images/Baocaotaichinh%20tom%20tat.xls<br />recent:	up<br />response:	alive<br />ip:	221.132.37.11<br />as:	AS7643<br />review:	221.132.37.11<br />domain:	catour.com.vn<br />country:	vn<br />source:	APNIC<br />email:	giangdo@hcmpt.com.vn<br />inetnum:	221.132.16.0 - 221.132.39.255<br />netname:	HCMPT-NET<br />descr:	Ho Chi Minh City Post and Telecom CompanyVietNam Post and Telecom Corporation (VNPT)VNPT-AS-AP<br />ns1:	ns2.cadao.net<br />ns2:	ns1.cadao.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aiz.by/partners/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3778763</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-CU Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3778763</guid>
			<pubDate>2012-11-13T13:50:04+01:00</pubDate>
			<description><![CDATA[id:	3778763<br />first:	1352811004<br />last:	0<br />md5:	cadfab4980ac0c84f8955b518552707a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cadfab4980ac0c84f8955b518552707a<br />vt_score:	21/36 (58.3%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-CU Trj<br />url:	http://aiz.by/partners/<br />recent:	up<br />response:	alive<br />ip:	93.84.116.213<br />as:	AS6697<br />review:	93.84.116.213<br />domain:	aiz.by<br />country:	BY<br />source:	RIPE<br />email:	dimon@mck.beltelecom.by<br />inetnum:	93.84.112.0 - 93.84.119.255<br />netname:	BELTELECOM-DATACENTER<br />descr:	MCC & REGIONAL DCsDELEGATED FROM BELPAK<br />ns1:	ns1.medialine.by<br />ns2:	ns2.medialine.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://afa15.com.ne.kr/Shipping_Label_USPS.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3778760</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Dropper-gen Drp]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3778760</guid>
			<pubDate>2012-11-13T13:50:04+01:00</pubDate>
			<description><![CDATA[id:	3778760<br />first:	1352811004<br />last:	0<br />md5:	d5d2911e8229bd03a45aa70cbb7dce3f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d5d2911e8229bd03a45aa70cbb7dce3f<br />vt_score:	16/36 (44.4%)<br />scanner:	Avast<br />virusname:	Win32:Dropper-gen Drp<br />url:	http://afa15.com.ne.kr/Shipping_Label_USPS.zip<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://accordiacalcio.org/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3778759</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.20]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3778759</guid>
			<pubDate>2012-11-13T13:50:04+01:00</pubDate>
			<description><![CDATA[id:	3778759<br />first:	1352811004<br />last:	0<br />md5:	4c6aeb5e29de9fa194d14cf70c125db2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1804610ea98e345b0efc4cd91158cd0d<br />vt_score:	11/36 (30.6%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.BS.20<br />url:	http://accordiacalcio.org/<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.74<br />domain:	accordiacalcio.org<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://60.8.194.163:6680/tools/YS-RouteSim.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3778757</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3778757</guid>
			<pubDate>2012-11-13T13:50:04+01:00</pubDate>
			<description><![CDATA[id:	3778757<br />first:	1352811004<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://60.8.194.163:6680/tools/YS-RouteSim.rar<br />recent:	up<br />response:	alive<br />ip:	60.8.194.163<br />as:	AS4837<br />review:	60.8.194.163<br />domain:	60.8.194.163<br />country:	CN<br />source:	APNIC<br />email:	abuse@cnc-noc.net<br />inetnum:	60.0.0.0 - 60.10.255.255<br />netname:	UNICOM-HE<br />descr:	China Unicom Hebei Province NetworkChina UnicomCNC Group CHINA169 Hebei Province Network<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rightclick.co.kr/down/RaclSetup_son010.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3623445</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Strictor.6097.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3623445</guid>
			<pubDate>2012-11-13T04:30:09+01:00</pubDate>
			<description><![CDATA[id:	3623445<br />first:	1352777409<br />last:	0<br />md5:	bf9bacffb3b176ed94cdc7a5c3f22fd3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=68de4dee3c6266919d640b888eb2d660<br />vt_score:	18/36 (50%)<br />scanner:	avira<br />virusname:	TR/Strictor.6097.2<br />url:	http://rightclick.co.kr/down/RaclSetup_son010.exe<br />recent:	up<br />response:	alive<br />ip:	210.112.10.154<br />as:	AS9848<br />review:	210.112.10.154<br />domain:	rightclick.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@sejongtelecom.net<br />inetnum:	210.112.0.0 - 210.112.127.255<br />netname:	SEJONGNET-KR<br />descr:	SEJONG TELECOM<br />ns1:	ns2.rcdns.com<br />ns2:	ns3.rcdns.com<br />ns3:	ns1.rcdns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://germantezanos.es/sol_villa/jquery-1.4.2.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3623429</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.K.43]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3623429</guid>
			<pubDate>2012-11-13T04:30:08+01:00</pubDate>
			<description><![CDATA[id:	3623429<br />first:	1352777408<br />last:	0<br />md5:	5c278a7d9bc45540b3d3203201d32377<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5c278a7d9bc45540b3d3203201d32377<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/Agent.K.43<br />url:	http://germantezanos.es/sol_villa/jquery-1.4.2.min.js<br />recent:	up<br />response:	alive<br />ip:	82.98.149.197<br />as:	AS42612<br />review:	82.98.149.197<br />domain:	germantezanos.es<br />country:	ES<br />source:	RIPE<br />email:	ripe@dinahosting.com<br />inetnum:	82.98.149.0 - 82.98.149.255<br />netname:	DH-J2-NET6<br />descr:	Dinahosting Subred 3J2Dinahosting S.L. prefix<br />ns1:	ns2.dinahosting.com<br />ns2:	ns.dinahosting.com<br />ns3:	ns3.dinahosting.com<br />ns4:	ns4.dinahosting.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://newdata.box.sk/neworder/may09/paradise99.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3518093</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3518093</guid>
			<pubDate>2012-11-12T14:30:07+01:00</pubDate>
			<description><![CDATA[id:	3518093<br />first:	1352727007<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://newdata.box.sk/neworder/may09/paradise99.zip<br />recent:	up<br />response:	alive<br />ip:	88.212.3.8<br />as:	AS42841<br />review:	88.212.3.8<br />domain:	box.sk<br />country:	SK<br />source:	RIPE<br />email:	abuse@antik.sk<br />inetnum:	88.212.0.0 - 88.212.63.255<br />netname:	SK-ANTIK-20051208<br />descr:	Antik Computers and Communications s.r.o.<br />ns1:	elf2.box.sk<br />ns2:	elf.box.sk.sk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://madpowah.org/projets/iphonestealer/iphonestealer.py]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3516207</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PY/IphoneSteal.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3516207</guid>
			<pubDate>2012-11-12T14:20:06+01:00</pubDate>
			<description><![CDATA[id:	3516207<br />first:	1352726406<br />last:	0<br />md5:	c0b6efe81dc3dc594b4b6192f7645459<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c0b6efe81dc3dc594b4b6192f7645459<br />vt_score:	0/36 (0.0%)<br />scanner:	F_Prot<br />virusname:	PY/IphoneSteal.A<br />url:	http://madpowah.org/projets/iphonestealer/iphonestealer.py<br />recent:	up<br />response:	alive<br />ip:	91.121.93.163<br />as:	AS16276<br />review:	91.121.82.222<br />domain:	madpowah.org<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	91.121.64.0 - 91.121.127.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	dns.ovh.net<br />ns2:	ns.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://113.160.178.140/MO/Editor/editor/fckeditor.html?]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3511313</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3511313</guid>
			<pubDate>2012-11-12T13:30:04+01:00</pubDate>
			<description><![CDATA[id:	3511313<br />first:	1352723404<br />last:	0<br />md5:	809a7b76a29fc12041420bb62e9519ff<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=809a7b76a29fc12041420bb62e9519ff<br />vt_score:	19/38 (50%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen<br />url:	http://113.160.178.140/MO/Editor/editor/fckeditor.html?<br />recent:	up<br />response:	alive<br />ip:	113.160.178.140<br />as:	AS45899<br />review:	113.160.178.140<br />domain:	113.160.178.140<br />country:	vn<br />source:	APNIC<br />email:	hathm@vdc.com.vn<br />inetnum:	113.160.0.0 - 113.160.255.255<br />netname:	VNPT-NET<br />descr:	Dai IP dong su dung cho ket noi ADSL tai Ha NoiIP range use for ADSL Service of VNPT in Ha NOiVietNam Post and Telecom Corporation (VNPT)VNPT-AS-AP<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zpchr.pl/katalog]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3306760</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ahl.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3306760</guid>
			<pubDate>2012-11-11T16:50:04+01:00</pubDate>
			<description><![CDATA[id:	3306760<br />first:	1352649004<br />last:	0<br />md5:	8adbaf4d880556a12dcc70b31250db5a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8adbaf4d880556a12dcc70b31250db5a<br />vt_score:	14/29 (48.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.ahl.1<br />url:	http://zpchr.pl/katalog<br />recent:	up<br />response:	alive<br />ip:	62.181.1.76<br />as:	AS21244<br />review:	62.181.1.76<br />domain:	zpchr.pl<br />country:	PL<br />source:	RIPE<br />email:	gregory-ripe@wdc.pl<br />inetnum:	62.181.0.0 - 62.181.5.255<br />netname:	WDC<br />descr:	Warsaw Data CenterWDC<br />ns1:	ns1.obpon.pl<br />ns2:	ns2.obpon.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://repli.es/js/jquery.cookie.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3298553</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.TO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3298553</guid>
			<pubDate>2012-11-11T16:02:43+01:00</pubDate>
			<description><![CDATA[id:	3298553<br />first:	1352646163<br />last:	0<br />md5:	eae4c6da39a4b506444ba13b3181ba43<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eae4c6da39a4b506444ba13b3181ba43<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.TO<br />url:	http://repli.es/js/jquery.cookie.js<br />recent:	up<br />response:	alive<br />ip:	94.23.80.126<br />as:	AS16276<br />review:	94.23.80.126<br />domain:	repli.es<br />country:	ES<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	94.23.80.0 - 94.23.87.255<br />netname:	ES-OVH<br />descr:	OVH Hispano<br />ns1:	ns.repli.es<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://physiotherapie-mueller-magdeburg.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3291056</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bnz]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3291056</guid>
			<pubDate>2012-11-11T16:00:07+01:00</pubDate>
			<description><![CDATA[id:	3291056<br />first:	1352646007<br />last:	0<br />md5:	3fcd53d7b45685afdb249e16e136840b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3fcd53d7b45685afdb249e16e136840b<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.bnz<br />url:	http://physiotherapie-mueller-magdeburg.de/<br />recent:	up<br />response:	alive<br />ip:	194.116.187.130<br />as:	AS34496<br />review:	194.116.187.130<br />domain:	physiotherapie-mueller-magdeburg.de<br />country:	DE<br />source:	RIPE<br />email:	support@ps-webhosting.de<br />inetnum:	194.116.186.0 - 194.116.187.255<br />netname:	DE-PS-WEBHOSTING<br />descr:	planet school webhosting IP NetworkPlanet School Webhosting e.K.PS-WEBHOSTING-NETPlanet School Webhosting e.K.<br />ns1:	a.ps-dns.de<br />ns2:	b.ps-dns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mindpark.com.tr/collezione.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3290897</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3290897</guid>
			<pubDate>2012-11-11T15:50:05+01:00</pubDate>
			<description><![CDATA[id:	3290897<br />first:	1352645405<br />last:	0<br />md5:	2aa7cc3fd43c5a4dd2191370e2c36f47<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2aa7cc3fd43c5a4dd2191370e2c36f47<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://mindpark.com.tr/collezione.htm<br />recent:	up<br />response:	alive<br />ip:	72.29.75.207<br />as:	AS33182<br />review:	72.29.75.207<br />domain:	mindpark.com.tr<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns100.dizinc.com<br />ns2:	ns101.dizinc.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mindpark.com.tr/camper.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3290896</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3290896</guid>
			<pubDate>2012-11-11T15:50:05+01:00</pubDate>
			<description><![CDATA[id:	3290896<br />first:	1352645405<br />last:	0<br />md5:	bb1e0c4f8d8e7beec7d3ef7aade3902f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb1e0c4f8d8e7beec7d3ef7aade3902f<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://mindpark.com.tr/camper.htm<br />recent:	up<br />response:	alive<br />ip:	72.29.75.207<br />as:	AS33182<br />review:	72.29.75.207<br />domain:	mindpark.com.tr<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns100.dizinc.com<br />ns2:	ns101.dizinc.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kickerclub.eu/Galerien/Weihnachtsfeier/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3283727</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3283727</guid>
			<pubDate>2012-11-11T15:20:05+01:00</pubDate>
			<description><![CDATA[id:	3283727<br />first:	1352643605<br />last:	0<br />md5:	0d1c461c23d4800b5ffc4d012c420f9d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0d1c461c23d4800b5ffc4d012c420f9d<br />vt_score:	16/36 (44.4%)<br />scanner:	AntiVir<br />virusname:	HTML/Rce.Gen3<br />url:	http://kickerclub.eu/Galerien/Weihnachtsfeier/index.html<br />recent:	up<br />response:	alive<br />ip:	134.0.26.175<br />as:	ASError:<br />review:	134.0.26.175<br />domain:	kickerclub.eu<br />country:	DE<br />source:	RIPE<br />email:	abuse@twooit.de<br />inetnum:	<br />netname:	<br />descr:	<br />ns1:	ns3.silver-dns.de<br />ns2:	ns1.silver-dns.de<br />ns3:	ns2.silver-dns.de<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://intecon.com.ng/sites/default/files/forwarding.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3281790</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/BlacoleRef.CP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3281790</guid>
			<pubDate>2012-11-11T15:00:31+01:00</pubDate>
			<description><![CDATA[id:	3281790<br />first:	1352642431<br />last:	0<br />md5:	b5b6595cee0061966c53fb8823096a5b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	avira<br />virusname:	JS/BlacoleRef.CP<br />url:	http://intecon.com.ng/sites/default/files/forwarding.htm<br />recent:	up<br />response:	alive<br />ip:	208.77.97.225<br />as:	AS17183<br />review:	208.77.97.225<br />domain:	intecon.com.ng<br />country:	US<br />source:	ARIN<br />email:	sean@rapidvps.com<br />inetnum:	208.77.96.0 - 208.77.103.255<br />netname:	INFINITUM-TECH<br />descr:	Infinitum Technologies Inc. INFIN-27 873 Grand Regency Pte. Suite 201 Altamonte Springs FL 32714<br />ns1:	ns.skannet.com<br />ns2:	fallback.skannet.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://imcumm.in/my-upload/u/me.php.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3281786</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/Shell.epq]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3281786</guid>
			<pubDate>2012-11-11T15:00:31+01:00</pubDate>
			<description><![CDATA[id:	3281786<br />first:	1352642431<br />last:	0<br />md5:	75abe2d13356601aaebc8c49736cff47<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=75abe2d13356601aaebc8c49736cff47<br />vt_score:	9/36 (25%)<br />scanner:	avira<br />virusname:	PHP/Shell.epq<br />url:	http://imcumm.in/my-upload/u/me.php.jpg<br />recent:	up<br />response:	alive<br />ip:	198.100.147.97<br />as:	AS16276<br />review:	198.27.64.26<br />domain:	imcumm.in<br />country:	CA<br />source:	ARIN<br />email:	noc@ovh.net<br />inetnum:	198.100.144.0 - 198.100.159.255<br />netname:	OVH-ARIN-4<br />descr:	OVH Hosting, Inc. HO-2 625, avenue du President Kennedy Bureau 310 Montreal QC H3A 1K2<br />ns1:	ns2.he.net<br />ns2:	ns3.he.net<br />ns3:	ns5.he.net<br />ns4:	ns1.he.net<br />ns5:	ns4.he.net<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/collectibles/lamps-lighting.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3278154</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3278154</guid>
			<pubDate>2012-11-11T14:40:03+01:00</pubDate>
			<description><![CDATA[id:	3278154<br />first:	1352641203<br />last:	0<br />md5:	5b68d8dca70a3506bfd0cac395377cd0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5b68d8dca70a3506bfd0cac395377cd0<br />vt_score:	10/36 (27.8%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://dollarauctions.ws/collectibles/lamps-lighting.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns1.stabletransit.com<br />ns2:	dns2.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://coniv.it/Scripts/AC_RunActiveContent.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3275171</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3275171</guid>
			<pubDate>2012-11-11T14:30:06+01:00</pubDate>
			<description><![CDATA[id:	3275171<br />first:	1352640606<br />last:	0<br />md5:	ddbe3d60fbf2c4033052fd0400201501<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bd4390bffced3ecf740db2c3e0d752c2<br />vt_score:	22/42 (52.4%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://coniv.it/Scripts/AC_RunActiveContent.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.74<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	coniv.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns4.arubadns.cz<br />ns2:	dns3.arubadns.net<br />ns3:	dns.technorail.com<br />ns4:	dns2.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://physiotherapie-mueller-magdeburg.de]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3244488</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bnz]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3244488</guid>
			<pubDate>2012-11-11T11:20:04+01:00</pubDate>
			<description><![CDATA[id:	3244488<br />first:	1352629204<br />last:	0<br />md5:	3fcd53d7b45685afdb249e16e136840b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3fcd53d7b45685afdb249e16e136840b<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.bnz<br />url:	http://physiotherapie-mueller-magdeburg.de<br />recent:	up<br />response:	alive<br />ip:	194.116.187.130<br />as:	AS34496<br />review:	194.116.187.130<br />domain:	physiotherapie-mueller-magdeburg.de<br />country:	DE<br />source:	RIPE<br />email:	support@ps-webhosting.de<br />inetnum:	194.116.186.0 - 194.116.187.255<br />netname:	DE-PS-WEBHOSTING<br />descr:	planet school webhosting IP NetworkPlanet School Webhosting e.K.PS-WEBHOSTING-NETPlanet School Webhosting e.K.<br />ns1:	a.ps-dns.de<br />ns2:	b.ps-dns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://file.myfiles.com.cn/Net/fujianjl_v20.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3143816</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/FraudPack.oty]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3143816</guid>
			<pubDate>2012-11-10T21:50:03+01:00</pubDate>
			<description><![CDATA[id:	3143816<br />first:	1352580603<br />last:	0<br />md5:	1712ad2fa5b3aba4a27bd3c09b1ac837<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1712ad2fa5b3aba4a27bd3c09b1ac837<br />vt_score:	31/36 (86.1%)<br />scanner:	avira<br />virusname:	TR/FraudPack.oty<br />url:	http://file.myfiles.com.cn/Net/fujianjl_v20.zip<br />recent:	up<br />response:	alive<br />ip:	113.5.250.159<br />as:	AS4837<br />review:	70.39.191.55<br />domain:	myfiles.com.cn<br />country:	US<br />source:	ARIN<br />email:	danc@inmotionhosting.com<br />inetnum:	113.0.0.0 - 113.7.255.255<br />netname:	NETBLK-MZIMA-11<br />descr:	Mzima Networks, Inc. MZIMAN-1 707 Wilshire Blvd. Suite 4737 Los Angeles CA 90017 AS25973InMotion Hosting, Inc. INMOT-1 4553 Glencoe Ave Suite 325 Marina Del Rey CA 90292 AS25973<br />ns1:	dns8.hichina.com<br />ns2:	dns7.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wielkopolskie.gimny.com.pl/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3063585</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3063585</guid>
			<pubDate>2012-11-10T19:00:06+01:00</pubDate>
			<description><![CDATA[id:	3063585<br />first:	1352570406<br />last:	0<br />md5:	338b1c5cdc231fb20b752b3432b81047<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=338b1c5cdc231fb20b752b3432b81047<br />vt_score:	22/43 (51.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://wielkopolskie.gimny.com.pl/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	212.91.6.51<br />as:	AS15694<br />review:	212.91.6.51<br />domain:	gimny.com.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@atman.pl<br />inetnum:	212.91.6.0 - 212.91.7.255<br />netname:	GREENER-NET-2<br />descr:	Greenerul.Malej Laki 9/702-793 Warszawa<br />ns1:	ns1.47.pl<br />ns2:	ns2.47.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tobet.pl/swfobject.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3046657</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.PP.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3046657</guid>
			<pubDate>2012-11-10T18:00:29+01:00</pubDate>
			<description><![CDATA[id:	3046657<br />first:	1352566829<br />last:	0<br />md5:	9efee3bfe19a8f6fd9b0e15e95b3e904<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c3276858507f8382077cd24185c84f08<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.PP.2<br />url:	http://tobet.pl/swfobject.js<br />recent:	up<br />response:	alive<br />ip:	212.180.247.52<br />as:	AS9085<br />review:	212.180.247.52<br />domain:	tobet.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@supermedia.pl<br />inetnum:	212.180.128.0 - 212.180.255.255<br />netname:	PL-SUPERMEDIA-20000831<br />descr:	SUPERMEDIA Sp.z.o.o.<br />ns1:	mt.nordicgaming.com<br />ns2:	se.nordicgaming.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://shong820909.bookonline.com.cn/images/ad/435_62.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3039905</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3039905</guid>
			<pubDate>2012-11-10T17:50:04+01:00</pubDate>
			<description><![CDATA[id:	3039905<br />first:	1352566204<br />last:	0<br />md5:	0dc4c77c7f3593fc7a584c7b10684cd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0dc4c77c7f3593fc7a584c7b10684cd2<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://shong820909.bookonline.com.cn/images/ad/435_62.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://otis-konin.pl/templates/klima2/script.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3026387</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZL Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3026387</guid>
			<pubDate>2012-11-10T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	3026387<br />first:	1352563207<br />last:	0<br />md5:	b1db5a7a18e2ba46306290c3725b63ac<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=34c023c9af465b85b33c05709eff3102<br />vt_score:	12/36 (33.3%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZL Trj<br />url:	http://otis-konin.pl/templates/klima2/script.js<br />recent:	up<br />response:	alive<br />ip:	93.159.16.132<br />as:	AS12968<br />review:	193.218.152.20<br />domain:	otis-konin.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@superhost.pl<br />inetnum:	93.159.16.128 - 93.159.16.159<br />netname:	SUPERHOST-PL<br />descr:	SuperHost.pl Sp. z o.o.<br />ns1:	dns2.mserwis.pl<br />ns2:	dns3.mserwis.pl<br />ns3:	dns1.mserwis.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nlcupc.org/pages/youth.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3026369</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3026369</guid>
			<pubDate>2012-11-10T17:00:06+01:00</pubDate>
			<description><![CDATA[id:	3026369<br />first:	1352563206<br />last:	0<br />md5:	c7817d3a31fe0626f580837f63ed9bf3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c7817d3a31fe0626f580837f63ed9bf3<br />vt_score:	6/35 (17.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://nlcupc.org/pages/youth.html<br />recent:	up<br />response:	alive<br />ip:	174.122.175.194<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.122.175.194<br />domain:	nlcupc.org<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-16<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1.wfdns.com<br />ns2:	ns2.wfdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://imagemuniversal.com.br/pdf/Servizio.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3000151</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3000151</guid>
			<pubDate>2012-11-10T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	3000151<br />first:	1352559004<br />last:	0<br />md5:	f20e3814c2443b2d90beddbe224b0487<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f20e3814c2443b2d90beddbe224b0487<br />vt_score:	19/37 (51.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://imagemuniversal.com.br/pdf/Servizio.zip<br />recent:	up<br />response:	alive<br />ip:	187.61.61.169<br />as:	AS15201<br />review:	187.61.61.169<br />domain:	imagemuniversal.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.61.0.0 - 187.61.63.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns2.imagemuniversal.com.br<br />ns2:	ns1.imagemuniversal.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ibmsn.org.br/dettagli/Team.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3000150</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3000150</guid>
			<pubDate>2012-11-10T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	3000150<br />first:	1352559004<br />last:	0<br />md5:	4d7e6a899aea1d16448885dc7c283abe<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d7e6a899aea1d16448885dc7c283abe<br />vt_score:	12/37 (32.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen5<br />url:	http://ibmsn.org.br/dettagli/Team.zip<br />recent:	up<br />response:	alive<br />ip:	74.55.94.58<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	74.55.94.58<br />domain:	ibmsn.org.br<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	74.52.0.0 - 74.55.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns1.host358.com<br />ns2:	ns2.host358.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://futuresystems.com.sa/kunsa11/ycarv.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2984012</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Kryptik.L]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2984012</guid>
			<pubDate>2012-11-10T15:10:20+01:00</pubDate>
			<description><![CDATA[id:	2984012<br />first:	1352556620<br />last:	0<br />md5:	2fa6e592cacf166e54c3535154f8bc09<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2fa6e592cacf166e54c3535154f8bc09<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/Kryptik.L<br />url:	http://futuresystems.com.sa/kunsa11/ycarv.js<br />recent:	up<br />response:	alive<br />ip:	74.52.152.210<br />as:	AS21844<br />review:	74.52.152.210<br />domain:	futuresystems.com.sa<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	74.52.0.0 - 74.53.255.255<br />netname:	NETBLK-THEPLANET-BLK-14<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 1333 North Stemmons Freeway Suite 110 Dallas TX 75207<br />ns1:	ns1185.hostgator.com<br />ns2:	ns1186.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://frauensingkreis-hasselbach.de/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2984011</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.cgx]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2984011</guid>
			<pubDate>2012-11-10T15:10:20+01:00</pubDate>
			<description><![CDATA[id:	2984011<br />first:	1352556620<br />last:	0<br />md5:	e1bbd5d87ff1b57387a5c81c67c6929f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b4a7850fa2e46633e5559c198cf4122d<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.cgx<br />url:	http://frauensingkreis-hasselbach.de/index.html<br />recent:	up<br />response:	alive<br />ip:	62.216.172.54<br />as:	AS25560<br />review:	62.216.172.54<br />domain:	frauensingkreis-hasselbach.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@rh-tec.de<br />inetnum:	62.216.172.0 - 62.216.172.63<br />netname:	DE-FRA-PSWGROUP-NET<br />descr:	psw group IP-Network<br />ns1:	ns2.ns-serve.net<br />ns2:	ns1.ns-serve.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://endoscopicsurgery.it/sito/yetii.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2983931</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/IFrame.HP.gen (exact)]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2983931</guid>
			<pubDate>2012-11-10T15:10:12+01:00</pubDate>
			<description><![CDATA[id:	2983931<br />first:	1352556612<br />last:	0<br />md5:	ffe5bbe90f6b315e784179c3b84eeeea<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=28fd24ea0366009d71b6fd397e7feb9b<br />vt_score:	18/42 (42.9%)<br />scanner:	undef<br />virusname:	JS/IFrame.HP.gen (exact)<br />url:	http://endoscopicsurgery.it/sito/yetii.js<br />recent:	up<br />response:	alive<br />ip:	46.28.2.41<br />as:	AS1267<br />review:	46.28.2.41<br />domain:	endoscopicsurgery.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@inwind.it<br />inetnum:	46.28.0.0 - 46.28.3.255<br />netname:	SERVERPLAN<br />descr:	Serverplan network3SERVERPLAN<br />ns1:	dns.consultingweb.it<br />ns2:	dns2.consultingweb.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dmtsystem.pl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2980677</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.T]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2980677</guid>
			<pubDate>2012-11-10T15:00:16+01:00</pubDate>
			<description><![CDATA[id:	2980677<br />first:	1352556016<br />last:	0<br />md5:	3d811c14986aa7395c9ea9052d380dfc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3d811c14986aa7395c9ea9052d380dfc<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Twetti.T<br />url:	http://dmtsystem.pl/<br />recent:	up<br />response:	alive<br />ip:	89.161.144.19<br />as:	AS12824<br />review:	89.161.144.19<br />domain:	dmtsystem.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://189.254.225.18/manual/bot.txt???rrrrrrrr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2941865</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/Pbot.A.9]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2941865</guid>
			<pubDate>2012-11-10T13:20:12+01:00</pubDate>
			<description><![CDATA[id:	2941865<br />first:	1352550012<br />last:	0<br />md5:	e40e3488996b67a6af3849f62b3c813b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e40e3488996b67a6af3849f62b3c813b<br />vt_score:	27/43 (62.8%)<br />scanner:	AntiVir<br />virusname:	PHP/Pbot.A.9<br />url:	http://189.254.225.18/manual/bot.txt???rrrrrrrr<br />recent:	up<br />response:	alive<br />ip:	189.254.225.18<br />as:	AS8151<br />review:	189.254.225.18<br />domain:	189.254.225.18<br />country:	MX<br />source:	LACNIC<br />email:	gccips@reduno.com.mx<br />inetnum:	189.240.0.0 - 189.255.255.255<br />netname:	MX-USCV4-LACNIC<br />descr:	Uninet S.A. de C.V.Periferico Sur, 3190,01900 - Ciudad de México - DFPERIFERICO SUR, 3190, ALVARO OBREG01900 - MEXICO DF - DF<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vr6gogo.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563862</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.JS.IFR.as.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563862</guid>
			<pubDate>2012-11-09T17:11:06+01:00</pubDate>
			<description><![CDATA[id:	2563862<br />first:	1352477466<br />last:	0<br />md5:	df71fa3953b6643adf7401bc98adda3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=df71fa3953b6643adf7401bc98adda3b<br />vt_score:	27/35 (77.1%)<br />scanner:	avira<br />virusname:	TR/Dldr.JS.IFR.as.2<br />url:	http://vr6gogo.de/<br />recent:	up<br />response:	alive<br />ip:	62.26.219.182<br />as:	AS12312<br />review:	62.26.219.182<br />domain:	vr6gogo.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@nacamar.net<br />inetnum:	62.26.219.0 - 62.26.219.255<br />netname:	TIS-D402292-NET<br />descr:	JSis Network Solutionsnacamar GmbH<br />ns1:	vns7.dnsservice.net<br />ns2:	vns8.dnsservice.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tupian.huanju.org/qc]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563861</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563861</guid>
			<pubDate>2012-11-09T17:11:06+01:00</pubDate>
			<description><![CDATA[id:	2563861<br />first:	1352477466<br />last:	0<br />md5:	ab319128e0e568cf19ce3d249d8c5f48<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4cf134e90083554d03ece13209ca40f0<br />vt_score:	30/36 (83.3%)<br />scanner:	AhnLab_V3<br />virusname:	HTML/Agent<br />url:	http://tupian.huanju.org/qc<br />recent:	up<br />response:	alive<br />ip:	115.68.76.55<br />as:	AS38700<br />review:	202.105.176.74<br />domain:	huanju.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	115.68.0.0 - 115.68.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	dns15.hichina.com<br />ns2:	dns16.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tupian.huanju.org/mt]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563860</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563860</guid>
			<pubDate>2012-11-09T17:11:06+01:00</pubDate>
			<description><![CDATA[id:	2563860<br />first:	1352477466<br />last:	0<br />md5:	3917aebe7ab5a2edf2981f885dc15f99<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=43e70efc0aa70464b77960d6e3a550e3<br />vt_score:	30/36 (83.3%)<br />scanner:	AhnLab_V3<br />virusname:	HTML/Agent<br />url:	http://tupian.huanju.org/mt<br />recent:	up<br />response:	alive<br />ip:	115.68.76.55<br />as:	AS38700<br />review:	202.105.176.71<br />domain:	huanju.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	115.68.0.0 - 115.68.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	dns15.hichina.com<br />ns2:	dns16.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tupian.huanju.org/mm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563859</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563859</guid>
			<pubDate>2012-11-09T17:11:06+01:00</pubDate>
			<description><![CDATA[id:	2563859<br />first:	1352477466<br />last:	0<br />md5:	3c43052a8c97d2c9eea61680c2baee90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=057ae42f4c70f80f740fb8671bfc5799<br />vt_score:	30/36 (83.3%)<br />scanner:	AhnLab_V3<br />virusname:	HTML/Agent<br />url:	http://tupian.huanju.org/mm<br />recent:	up<br />response:	alive<br />ip:	115.68.76.55<br />as:	AS38700<br />review:	202.105.176.74<br />domain:	huanju.org<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	115.68.0.0 - 115.68.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkData Communication DivisionChina Telecom<br />ns1:	dns15.hichina.com<br />ns2:	dns16.hichina.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://play8.me/wp-content/plugins/zrgboeqaouu/ugoogle.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563680</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.HTML.Redirector.AW]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563680</guid>
			<pubDate>2012-11-09T16:09:58+01:00</pubDate>
			<description><![CDATA[id:	2563680<br />first:	1352473798<br />last:	0<br />md5:	4fc07f36e658e72ea4dba4878835d88d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4fc07f36e658e72ea4dba4878835d88d<br />vt_score:	8/44 (18.2%)<br />scanner:	BitDefender<br />virusname:	Trojan.HTML.Redirector.AW<br />url:	http://play8.me/wp-content/plugins/zrgboeqaouu/ugoogle.html<br />recent:	up<br />response:	alive<br />ip:	50.23.32.187<br />as:	AS36351<br />review:	142.4.26.112<br />domain:	play8.me<br />country:	US<br />source:	ARIN<br />email:	abuse@bluehost.com<br />inetnum:	50.22.0.0 - 50.23.255.255<br />netname:	BLUEHOST-NETWORK-10<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns111.ulink.com.ph<br />ns2:	ns211.ulink.com.ph<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kwsr.co.uk/label_copy_usps.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563395</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563395</guid>
			<pubDate>2012-11-09T15:30:19+01:00</pubDate>
			<description><![CDATA[id:	2563395<br />first:	1352471419<br />last:	0<br />md5:	902200148a2c030a3772446d465a45c5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=902200148a2c030a3772446d465a45c5<br />vt_score:	21/37 (56.8%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://kwsr.co.uk/label_copy_usps.zip<br />recent:	up<br />response:	alive<br />ip:	62.128.158.13<br />as:	AS8912<br />review:	62.128.158.13<br />domain:	kwsr.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@netbenefit.co.uk<br />inetnum:	62.128.158.0 - 62.128.158.127<br />netname:	GROUPNBT-SHARED<br />descr:	Group NBT plc Shared Hosting<br />ns1:	dns0.easily.co.uk<br />ns2:	dns1.easily.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://excelsiors.com.pk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563296</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563296</guid>
			<pubDate>2012-11-09T14:59:59+01:00</pubDate>
			<description><![CDATA[id:	2563296<br />first:	1352469599<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://excelsiors.com.pk/<br />recent:	up<br />response:	alive<br />ip:	67.228.215.136<br />as:	AS36351<br />review:	undef<br />domain:	excelsiors.com.pk<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	67.228.0.0 - 67.228.255.255<br />netname:	SOFTLAYER-4-5<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns1.vhostdns2.com<br />ns2:	ns2.vhostdns2.com<br />ns3:	nt-220.vhostdns5.com<br />ns4:	nt-221.vhostdns5.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://europho.to/wi-birds/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563295</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/ImgHack.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563295</guid>
			<pubDate>2012-11-09T14:59:58+01:00</pubDate>
			<description><![CDATA[id:	2563295<br />first:	1352469598<br />last:	0<br />md5:	3b4387ae72f280a9d5e1b23c5ba8b442<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b4387ae72f280a9d5e1b23c5ba8b442<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	HTML/ImgHack.C<br />url:	http://europho.to/wi-birds/index.html<br />recent:	up<br />response:	alive<br />ip:	97.74.215.121<br />as:	AS26496<br />review:	97.74.215.121<br />domain:	europho.to<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns43.domaincontrol.com<br />ns2:	ns44.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://athphoto.apparis.org]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2563102</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Afriem.U]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2563102</guid>
			<pubDate>2012-11-09T14:29:59+01:00</pubDate>
			<description><![CDATA[id:	2563102<br />first:	1352467799<br />last:	0<br />md5:	4c5e9e13eae3ceacefb48d5e89f27930<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4c5e9e13eae3ceacefb48d5e89f27930<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	HTML/Afriem.U<br />url:	http://athphoto.apparis.org<br />recent:	up<br />response:	alive<br />ip:	173.236.202.221<br />as:	AS26347<br />review:	208.113.213.5<br />domain:	apparis.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	173.236.128.0 - 173.236.255.255<br />netname:	DREAMHOST-BLK6<br />descr:	New Dream Network, LLC NDN 10 Pointe Drive Suite 235 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns2.dreamhost.com<br />ns3:	ns3.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://voh.com.vn/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2562778</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2562778</guid>
			<pubDate>2012-11-09T13:29:58+01:00</pubDate>
			<description><![CDATA[id:	2562778<br />first:	1352464198<br />last:	0<br />md5:	470c6a06f7ea88055d363ef5b863605b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=046891bf415c4af517e3fa0b7995bf43<br />vt_score:	12/36 (33.3%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://voh.com.vn/<br />recent:	up<br />response:	alive<br />ip:	221.132.39.177<br />as:	AS7643<br />review:	221.132.39.177<br />domain:	voh.com.vn<br />country:	vn<br />source:	APNIC<br />email:	giangdo@hcmpt.com.vn<br />inetnum:	221.132.16.0 - 221.132.39.255<br />netname:	HCMPT-NET<br />descr:	Ho Chi Minh City Post and Telecom CompanyVietNam Post and Telecom Corporation (VNPT)VNPT-AS-AP<br />ns1:	dns1.netsoft.com.vn<br />ns2:	dns2.netsoft.com.vn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yambol.digicom.bg/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2558239</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Agent.opd]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2558239</guid>
			<pubDate>2012-11-08T23:20:25+01:00</pubDate>
			<description><![CDATA[id:	2558239<br />first:	1352413225<br />last:	0<br />md5:	8f9d3ff9b3d8dafb97778050cfc422eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1199c7910988500f7781fbe83a0f9ff<br />vt_score:	3/38 (7.9%)<br />scanner:	AntiVir<br />virusname:	HTML/Agent.opd<br />url:	http://yambol.digicom.bg/<br />recent:	up<br />response:	alive<br />ip:	95.169.200.7<br />as:	AS34524<br />review:	95.169.200.7<br />domain:	digicom.bg<br />country:	BG<br />source:	RIPE<br />email:	pavlin.nedelchev@bulgartel.bg<br />inetnum:	95.169.192.0 - 95.169.207.255<br />netname:	DIGICOM-NET<br />descr:	Digicom,BourgasDigiCom.BG Network<br />ns1:	ns.digicom.bg<br />ns2:	ns2.digicom.bg<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wielkilukwarty.pl/english.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2558177</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.16]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2558177</guid>
			<pubDate>2012-11-08T22:50:33+01:00</pubDate>
			<description><![CDATA[id:	2558177<br />first:	1352411433<br />last:	0<br />md5:	3b3472d928e45c270e22fd83b6c14baa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b3472d928e45c270e22fd83b6c14baa<br />vt_score:	23/46 (50%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.BS.16<br />url:	http://wielkilukwarty.pl/english.html<br />recent:	up<br />response:	alive<br />ip:	89.161.243.136<br />as:	AS12824<br />review:	89.161.243.136<br />domain:	wielkilukwarty.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.192.0 - 89.161.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://voxinterium.rockmetal.art.pl/biografia.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2558174</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS:Malware-gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2558174</guid>
			<pubDate>2012-11-08T22:50:33+01:00</pubDate>
			<description><![CDATA[id:	2558174<br />first:	1352411433<br />last:	0<br />md5:	676ba79ba56c3919eb5b81cd9a794bec<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=676ba79ba56c3919eb5b81cd9a794bec<br />vt_score:	15/36 (41.7%)<br />scanner:	Avast<br />virusname:	VBS:Malware-gen<br />url:	http://voxinterium.rockmetal.art.pl/biografia.html<br />recent:	up<br />response:	alive<br />ip:	213.5.10.139<br />as:	AS49895<br />review:	213.5.10.139<br />domain:	rockmetal.art.pl<br />country:	PL<br />source:	RIPE<br />email:	info@dcenter.pl<br />inetnum:	213.5.8.0 - 213.5.15.255<br />netname:	DCENTER-NET<br />descr:	dcenter.pl sp. z o.o.Al.Jerozolimskie 8102-001 WarszawaDCENTER-NETWarsaw, PolandDCENTER-NETWarsaw, Poland<br />ns1:	antyk.fs.com.pl<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tongshing.com.hk/eweb/2006-12-20.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557940</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Fujack.Inf.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557940</guid>
			<pubDate>2012-11-08T22:00:26+01:00</pubDate>
			<description><![CDATA[id:	2557940<br />first:	1352408426<br />last:	0<br />md5:	ce78ca2f57cc561db90d36cdfbdd8e29<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ce78ca2f57cc561db90d36cdfbdd8e29<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	WORM/Fujack.Inf.2<br />url:	http://tongshing.com.hk/eweb/2006-12-20.htm<br />recent:	up<br />response:	alive<br />ip:	123.242.226.10<br />as:	AS38478<br />review:	123.242.226.10<br />domain:	tongshing.com.hk<br />country:	HK<br />source:	APNIC<br />email:	hostmaster@netfinity.com.hk<br />inetnum:	123.242.226.0 - 123.242.226.255<br />netname:	NETFINITY<br />descr:	Network Infinity Technology Limited<br />ns1:	ns2.onlinenic.com.hk<br />ns2:	ns1.onlinenic.com.hk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://th.pe/sd_carillas.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557937</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557937</guid>
			<pubDate>2012-11-08T22:00:26+01:00</pubDate>
			<description><![CDATA[id:	2557937<br />first:	1352408426<br />last:	0<br />md5:	d4a610a99b1f1661158f4beb177b147b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d4a610a99b1f1661158f4beb177b147b<br />vt_score:	8/36 (22.2%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://th.pe/sd_carillas.html<br />recent:	up<br />response:	alive<br />ip:	69.73.179.243<br />as:	AS3595<br />review:	69.73.179.244<br />domain:	th.pe<br />country:	US<br />source:	ARIN<br />email:	abuse@jaguarpc.com<br />inetnum:	69.73.128.0 - 69.73.191.255<br />netname:	LH-GOLD-NETWORK<br />descr:	Landis Holdings Inc LANDI-3 PO BOX 1108 Fulshear TX 77441<br />ns1:	ns1.idwhosting.biz<br />ns2:	ns2.idwhosting.biz<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://the-sealanders.ch/paintball/admin/lib/js_functions.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557936</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557936</guid>
			<pubDate>2012-11-08T22:00:26+01:00</pubDate>
			<description><![CDATA[id:	2557936<br />first:	1352408426<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://the-sealanders.ch/paintball/admin/lib/js_functions.js<br />recent:	up<br />response:	alive<br />ip:	78.46.93.6<br />as:	AS24940<br />review:	undef<br />domain:	the-sealanders.ch<br />country:	DE<br />source:	ARIN<br />email:	abuse@hetzner.de<br />inetnum:	78.46.64.0 - 78.46.95.255<br />netname:	HETZNER-RZ-NBG-NET<br />descr:	Hetzner Online AG<br />ns1:	ns175.hoststar.ch<br />ns2:	ns176.hoststar.ch<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sennhof-knoll.at/Copy_of_UPS_Label.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557582</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Oficla.887956]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557582</guid>
			<pubDate>2012-11-08T21:19:59+01:00</pubDate>
			<description><![CDATA[id:	2557582<br />first:	1352405999<br />last:	0<br />md5:	17cb5c33aaea2e9fb02b05a739481e79<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=17cb5c33aaea2e9fb02b05a739481e79<br />vt_score:	22/32 (68.8%)<br />scanner:	avira<br />virusname:	TR/Oficla.887956<br />url:	http://sennhof-knoll.at/Copy_of_UPS_Label.zip<br />recent:	up<br />response:	alive<br />ip:	77.74.56.128<br />as:	ASNA.77.0.0.0 - 95.255.255.255<br />review:	77.74.56.128<br />domain:	sennhof-knoll.at<br />country:	CY<br />source:	RIPE<br />email:	abuse@mesh.eu<br />inetnum:	77.0.0.0 - 95.255.255.255<br />netname:	CY-INNTERNET-OPS-I<br />descr:	I.W. Innter.Net Webservice Ltd.I.W. Innter.Net Webservice LtdProviderservices<br />ns1:	pns.innterdns.net<br />ns2:	tns.innterdns.net<br />ns3:	sns.innterdns.net<br />ns4:	qns.innterdns.eu<br />ns5:	rns.innterdns.asia<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sebastianmila.pl/galeria/austria2/ext/js/index.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557581</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.JS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557581</guid>
			<pubDate>2012-11-08T21:19:59+01:00</pubDate>
			<description><![CDATA[id:	2557581<br />first:	1352405999<br />last:	0<br />md5:	8afdf1d680fb74d1b233515fd38ba793<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8afdf1d680fb74d1b233515fd38ba793<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.JS<br />url:	http://sebastianmila.pl/galeria/austria2/ext/js/index.js<br />recent:	up<br />response:	alive<br />ip:	193.218.152.21<br />as:	AS41079<br />review:	193.218.152.21<br />domain:	sebastianmila.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@superhost.pl<br />inetnum:	193.218.152.0 - 193.218.155.255<br />netname:	SUPERHOST-PL<br />descr:	SuperHost.pl Sp. z o.o.<br />ns1:	ns1.superhost.pl<br />ns2:	ns2.superhost.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sda.art.pl/sda/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557580</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/JS.Crytper.VIP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557580</guid>
			<pubDate>2012-11-08T21:19:59+01:00</pubDate>
			<description><![CDATA[id:	2557580<br />first:	1352405999<br />last:	0<br />md5:	95d8e5ce93f9706fecd6f5512b6b8190<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=95d8e5ce93f9706fecd6f5512b6b8190<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	SPR/JS.Crytper.VIP<br />url:	http://sda.art.pl/sda/<br />recent:	up<br />response:	alive<br />ip:	79.96.52.17<br />as:	AS12824<br />review:	79.96.52.17<br />domain:	sda.art.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://salou.pl/plugins/content/sige/plugin_sige/shadowbox.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2557578</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.JS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2557578</guid>
			<pubDate>2012-11-08T21:19:59+01:00</pubDate>
			<description><![CDATA[id:	2557578<br />first:	1352405999<br />last:	0<br />md5:	f524f51013217fff7212194bddcbd355<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f524f51013217fff7212194bddcbd355<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.JS<br />url:	http://salou.pl/plugins/content/sige/plugin_sige/shadowbox.js<br />recent:	up<br />response:	alive<br />ip:	212.85.124.232<br />as:	AS12824<br />review:	212.85.124.232<br />domain:	salou.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.114.0 - 212.85.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pw-bot.at.ua/bot.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556612</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Graftor.26751]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556612</guid>
			<pubDate>2012-11-08T20:40:38+01:00</pubDate>
			<description><![CDATA[id:	2556612<br />first:	1352403638<br />last:	0<br />md5:	1e8a5399f72c8cb1118807a1fa0e6d4f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1e8a5399f72c8cb1118807a1fa0e6d4f<br />vt_score:	13/46 (28.3%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Graftor.26751<br />url:	http://pw-bot.at.ua/bot.rar<br />recent:	up<br />response:	alive<br />ip:	195.216.243.42<br />as:	AS41947<br />review:	195.216.243.142<br />domain:	pw-bot.at.ua<br />country:	GB<br />source:	RIPE<br />email:	abuse@compubyte.vg<br />inetnum:	195.216.243.0 - 195.216.243.255<br />netname:	COMPUBYTE-NET<br />descr:	Compubyte LimitedCompubyte Ltd.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://przedszkole32konin.pl/galeria_prace/swfobject.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556611</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZL Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556611</guid>
			<pubDate>2012-11-08T20:40:38+01:00</pubDate>
			<description><![CDATA[id:	2556611<br />first:	1352403638<br />last:	0<br />md5:	4bd173852aa324a07be2f94d2c42b09f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4bd173852aa324a07be2f94d2c42b09f<br />vt_score:	0/46 (0.0%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZL Trj<br />url:	http://przedszkole32konin.pl/galeria_prace/swfobject.js<br />recent:	up<br />response:	alive<br />ip:	93.159.16.132<br />as:	AS12968<br />review:	193.218.152.20<br />domain:	przedszkole32konin.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@superhost.pl<br />inetnum:	93.159.16.128 - 93.159.16.159<br />netname:	SUPERHOST-PL<br />descr:	SuperHost.pl Sp. z o.o.<br />ns1:	dns1.mserwis.pl<br />ns2:	dns2.mserwis.pl<br />ns3:	dns3.mserwis.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ppi.com.ar/360/especialcatedral.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556609</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.ZX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556609</guid>
			<pubDate>2012-11-08T20:40:38+01:00</pubDate>
			<description><![CDATA[id:	2556609<br />first:	1352403638<br />last:	0<br />md5:	827202515c2c32065de6318dd81b4151<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=827202515c2c32065de6318dd81b4151<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.ZX<br />url:	http://ppi.com.ar/360/especialcatedral.html<br />recent:	up<br />response:	alive<br />ip:	200.6.158.110<br />as:	AS16626<br />review:	200.6.158.110<br />domain:	ppi.com.ar<br />country:	VE<br />source:	LACNIC<br />email:	noc@privateipservices.com<br />inetnum:	200.6.152.0 - 200.6.159.255<br />netname:	VE-PISE-LACNIC<br />descr:	Private Ip ServicesAvenida Guzman Lander entre calle 7 y 8., --,-- - Barcelona - --Av. Guzman Lander, Quinta Amarilla., n/a,6023 - Barcelona - An<br />ns1:	ns1.tfiapplications.com<br />ns2:	ns2.tfiapplications.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pacc.info/calendar.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556574</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Redirector.CA.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556574</guid>
			<pubDate>2012-11-08T20:19:58+01:00</pubDate>
			<description><![CDATA[id:	2556574<br />first:	1352402398<br />last:	0<br />md5:	d77c9857bab69a5684099bf798cbf8bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=692c91f52e9ddf0104a37e5f8ac9fd10<br />vt_score:	14/44 (31.8%)<br />scanner:	avira<br />virusname:	HTML/Redirector.CA.1<br />url:	http://pacc.info/calendar.asp<br />recent:	up<br />response:	alive<br />ip:	64.64.214.138<br />as:	AS1616<br />review:	64.64.214.138<br />domain:	pacc.info<br />country:	US<br />source:	ARIN<br />email:	ipadmin@corelink.com<br />inetnum:	64.64.214.128 - 64.64.214.159<br />netname:	LAS01-SUBSTREAM-001<br />descr:	5858 S. Pecos Rd. Suite 400a Las Vegas NV 89120<br />ns1:	ns1.substorm.com<br />ns2:	ns2.substorm.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://newdata.box.sk/neworder/u/awcrack.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556554</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556554</guid>
			<pubDate>2012-11-08T20:00:00+01:00</pubDate>
			<description><![CDATA[id:	2556554<br />first:	1352401200<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://newdata.box.sk/neworder/u/awcrack.zip<br />recent:	up<br />response:	alive<br />ip:	88.212.3.8<br />as:	AS42841<br />review:	88.212.3.8<br />domain:	box.sk<br />country:	SK<br />source:	RIPE<br />email:	abuse@antik.sk<br />inetnum:	88.212.0.0 - 88.212.63.255<br />netname:	SK-ANTIK-20051208<br />descr:	Antik Computers and Communications s.r.o.<br />ns1:	elf2.box.sk<br />ns2:	elf.box.sk.sk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://malerbetrieb-fritsche.de/js/navigation.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556511</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556511</guid>
			<pubDate>2012-11-08T19:09:57+01:00</pubDate>
			<description><![CDATA[id:	2556511<br />first:	1352398197<br />last:	0<br />md5:	628096884260be32579f27b96385c862<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=628096884260be32579f27b96385c862<br />vt_score:	24/46 (52.2%)<br />scanner:	AntiVir<br />virusname:	JS/Twetti.E<br />url:	http://malerbetrieb-fritsche.de/js/navigation.js<br />recent:	up<br />response:	alive<br />ip:	217.119.54.183<br />as:	AS31100<br />review:	217.119.54.183<br />domain:	malerbetrieb-fritsche.de<br />country:	DE<br />source:	RIPE<br />email:	hostmaster@synserver.de<br />inetnum:	217.119.49.0 - 217.119.54.255<br />netname:	SYNNET-WE1<br />descr:	synergetic Medien- und Systemtechnologie AGsynnet internet servicessynergetic Medien- und Systemtechnologie AGsynnet internet services<br />ns1:	ns3.loomes.net<br />ns2:	ns2.loomes.net<br />ns3:	ns1.loomes.net<br />ns4:	ns4.loomes.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://light048.com.ne.kr/kwang2.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556499</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Changeset.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556499</guid>
			<pubDate>2012-11-08T19:00:01+01:00</pubDate>
			<description><![CDATA[id:	2556499<br />first:	1352397601<br />last:	0<br />md5:	24698994cc51e563ab48dbabc67a93c7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=24698994cc51e563ab48dbabc67a93c7<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	VBS/Changeset.A<br />url:	http://light048.com.ne.kr/kwang2.htm<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://levocidentro.it/shipping_label_usps.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556498</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Barys.EB.40]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556498</guid>
			<pubDate>2012-11-08T19:00:01+01:00</pubDate>
			<description><![CDATA[id:	2556498<br />first:	1352397601<br />last:	0<br />md5:	83abaf37035a994a3b34311a4ed44158<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=83abaf37035a994a3b34311a4ed44158<br />vt_score:	22/35 (62.9%)<br />scanner:	avira<br />virusname:	TR/Barys.EB.40<br />url:	http://levocidentro.it/shipping_label_usps.zip<br />recent:	up<br />response:	alive<br />ip:	93.186.240.105<br />as:	AS5602<br />review:	93.186.240.105<br />domain:	levocidentro.it<br />country:	IT<br />source:	RIPE<br />email:	abuse@9net.it<br />inetnum:	93.186.240.0 - 93.186.241.255<br />netname:	W1-9NET-1<br />descr:	9net srl<br />ns1:	ns2.websolutions.it<br />ns2:	ns1.websolutions.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3dwinrar+hrvatski&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556481</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556481</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556481<br />first:	1352396997<br />last:	0<br />md5:	c4480b34c461b7a455fbedea29e03746<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c4480b34c461b7a455fbedea29e03746<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3dwinrar+hrvatski&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.download-guru.com<br />ns2:	ns1.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lacuerdadelasflores.com.ar/home.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556480</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Afriem.U]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556480</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556480<br />first:	1352396997<br />last:	0<br />md5:	4be8e9e2abc0000f6429cf998abac9df<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4be8e9e2abc0000f6429cf998abac9df<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	HTML/Afriem.U<br />url:	http://lacuerdadelasflores.com.ar/home.htm<br />recent:	up<br />response:	alive<br />ip:	200.110.135.134<br />as:	AS18747<br />review:	200.110.135.134<br />domain:	lacuerdadelasflores.com.ar<br />country:	AR<br />source:	LACNIC<br />email:	operaciones.arin@ifxnw.com.ar<br />inetnum:	200.110.128.0 - 200.110.135.255<br />netname:	AR-INAS-LACNIC<br />descr:	IFX Networks Argentina S.R.L.Av. Belgrano, 1586, Piso 11C1093AAQ - Buenos Aires -Av. Belgrano, 1586, Piso 11C1093AAQ - Buenos Aires -<br />ns1:	ns1.lineadns.com<br />ns2:	ns2.lineadns.com<br />ns3:	ns3.lineadns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/TECHazot.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556479</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556479</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556479<br />first:	1352396997<br />last:	0<br />md5:	21f05831e5e3346e46749fcc477b2599<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=21f05831e5e3346e46749fcc477b2599<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/TECHazot.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns2.tutby.com<br />ns2:	ns1.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kirschmer-backnang.de/lerchenaecker.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556478</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Script-inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556478</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556478<br />first:	1352396997<br />last:	0<br />md5:	9fb765d0436cf577df5a9fe55be1dd83<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9fb765d0436cf577df5a9fe55be1dd83<br />vt_score:	0/36 (0.0%)<br />scanner:	Avast<br />virusname:	HTML:Script-inf<br />url:	http://kirschmer-backnang.de/lerchenaecker.htm<br />recent:	up<br />response:	alive<br />ip:	82.165.61.205<br />as:	AS8560<br />review:	82.165.61.205<br />domain:	kirschmer-backnang.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.48.0 - 82.165.63.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns43.1und1.de<br />ns2:	ns44.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p5p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556477</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556477</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556477<br />first:	1352396997<br />last:	0<br />md5:	9f9538618a95d6a86bfc673e5a0d3b4b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9f9538618a95d6a86bfc673e5a0d3b4b<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p5p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p321p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556476</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556476</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556476<br />first:	1352396997<br />last:	0<br />md5:	35cce17fda524c9c46541d873f6a9a8b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=35cce17fda524c9c46541d873f6a9a8b<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p321p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p319p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556475</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556475</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556475<br />first:	1352396997<br />last:	0<br />md5:	477cc9dbd6e151d2a90b8d1c8f639430<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=477cc9dbd6e151d2a90b8d1c8f639430<br />vt_score:	24/34 (70.6%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p319p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p300p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556474</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556474</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556474<br />first:	1352396997<br />last:	0<br />md5:	1806cdd1fd03cb85fff8c4b562719f29<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1806cdd1fd03cb85fff8c4b562719f29<br />vt_score:	23/30 (76.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p300p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p277p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556473</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556473</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556473<br />first:	1352396997<br />last:	0<br />md5:	01d0e59a17df8db2db2ef55b8696e092<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=01d0e59a17df8db2db2ef55b8696e092<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p277p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p250p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556472</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556472</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556472<br />first:	1352396997<br />last:	0<br />md5:	148ba2ad30133aa4891f0c3c6091ea29<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=148ba2ad30133aa4891f0c3c6091ea29<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p250p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ishadatar.org/main.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556470</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.JA.7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556470</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556470<br />first:	1352396997<br />last:	0<br />md5:	79d601ee40ef66120c1c6f2e05763f3e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=79d601ee40ef66120c1c6f2e05763f3e<br />vt_score:	14/30 (46.7%)<br />scanner:	avira<br />virusname:	HTML/IFrame.JA.7<br />url:	http://ishadatar.org/main.html<br />recent:	up<br />response:	alive<br />ip:	66.7.207.112<br />as:	AS33182<br />review:	66.7.207.112<br />domain:	ishadatar.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	66.7.192.0 - 66.7.223.255<br />netname:	DIMECNET<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns1.host-care.com<br />ns2:	ns2.host-care.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://internetgate.it/tmp/babioo/28/vrneboyanof.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556469</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Afriem.V]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556469</guid>
			<pubDate>2012-11-08T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2556469<br />first:	1352396997<br />last:	0<br />md5:	539c911fdaa7fc7f740cc4fb08289368<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=539c911fdaa7fc7f740cc4fb08289368<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	HTML/Afriem.V<br />url:	http://internetgate.it/tmp/babioo/28/vrneboyanof.html<br />recent:	up<br />response:	alive<br />ip:	85.235.155.111<br />as:	AS31034<br />review:	85.235.155.111<br />domain:	internetgate.it<br />country:	IT<br />source:	RIPE<br />email:	omero.narducci@widestore.net<br />inetnum:	85.235.128.0 - 85.235.159.255<br />netname:	IT-WIDESTORE-20050511<br />descr:	Widestore s.r.l.Widestore s.r.l. Network<br />ns1:	ns2.cassiopea.it<br />ns2:	ns.cassiopea.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hobbymarebari.it/media/system/js/core.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556392</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.Inf.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556392</guid>
			<pubDate>2012-11-08T17:59:59+01:00</pubDate>
			<description><![CDATA[id:	2556392<br />first:	1352393999<br />last:	0<br />md5:	4b59c964036a5a6ba36d4cfa34968c2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3d62e0c10a9ae6ca4b34e10d9cb0616b<br />vt_score:	18/38 (47.4%)<br />scanner:	avira<br />virusname:	JS/iFrame.Inf.5<br />url:	http://hobbymarebari.it/media/system/js/core.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.157<br />as:	AS31034<br />review:	62.149.128.72<br />domain:	hobbymarebari.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns3.arubadns.net<br />ns2:	dns2.technorail.com<br />ns3:	dns4.arubadns.cz<br />ns4:	dns.technorail.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ethos.org.br/ci2009dinamico/versao_espanhol/index.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556298</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.QTX]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556298</guid>
			<pubDate>2012-11-08T16:40:08+01:00</pubDate>
			<description><![CDATA[id:	2556298<br />first:	1352389208<br />last:	0<br />md5:	d4e4276171f7ed2ab35efcb487bf0b61<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d4e4276171f7ed2ab35efcb487bf0b61<br />vt_score:	0/46 (0.0%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.QTX<br />url:	http://ethos.org.br/ci2009dinamico/versao_espanhol/index.asp<br />recent:	up<br />response:	alive<br />ip:	200.169.96.111<br />as:	AS21911<br />review:	200.169.96.111<br />domain:	ethos.org.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@dualtec.com.br<br />inetnum:	200.169.96.0 - 200.169.111.255<br />netname:	058.671.835/0001-53<br />descr:	DUALTEC INFORMATICA LTDA<br />ns1:	easydns2.dualtec.com.br<br />ns2:	easydns1.dualtec.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ethos.org.br/ci2009dinamico/mostra/site]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556297</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.qtx.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556297</guid>
			<pubDate>2012-11-08T16:40:08+01:00</pubDate>
			<description><![CDATA[id:	2556297<br />first:	1352389208<br />last:	0<br />md5:	dce85ea4c42600269d487203e168ebaa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dce85ea4c42600269d487203e168ebaa<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/Agent.qtx.1<br />url:	http://ethos.org.br/ci2009dinamico/mostra/site<br />recent:	up<br />response:	alive<br />ip:	200.169.96.111<br />as:	AS21911<br />review:	200.169.96.111<br />domain:	ethos.org.br<br />country:	BR<br />source:	LACNIC<br />email:	abuse@dualtec.com.br<br />inetnum:	200.169.96.0 - 200.169.111.255<br />netname:	058.671.835/0001-53<br />descr:	DUALTEC INFORMATICA LTDA<br />ns1:	easydns2.dualtec.com.br<br />ns2:	easydns1.dualtec.com.br<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://enfoquevisual.es/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556255</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.KE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556255</guid>
			<pubDate>2012-11-08T16:22:46+01:00</pubDate>
			<description><![CDATA[id:	2556255<br />first:	1352388166<br />last:	0<br />md5:	fceeee0f009a33865d31cf657a4344b1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fceeee0f009a33865d31cf657a4344b1<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.KE<br />url:	http://enfoquevisual.es/<br />recent:	up<br />response:	alive<br />ip:	94.127.188.128<br />as:	AS43988<br />review:	217.160.27.188<br />domain:	enfoquevisual.es<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	94.127.184.0 - 94.127.191.255<br />netname:	DE-SCHLUND-20010307<br />descr:	1&1 Internet AGSCHLUND-PA-3<br />ns1:	dns.clave.com.es<br />ns2:	dns2.abserver.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dollarauctions.ws/home-garden/gardening-plants.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556223</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.JS.Agent.HFM]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556223</guid>
			<pubDate>2012-11-08T16:10:00+01:00</pubDate>
			<description><![CDATA[id:	2556223<br />first:	1352387400<br />last:	0<br />md5:	5d4f946a9507a8b5ce2be295268e4a93<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5d4f946a9507a8b5ce2be295268e4a93<br />vt_score:	12/36 (33.3%)<br />scanner:	BitDefender<br />virusname:	Trojan.JS.Agent.HFM<br />url:	http://dollarauctions.ws/home-garden/gardening-plants.html<br />recent:	up<br />response:	alive<br />ip:	98.129.229.86<br />as:	AS33070, AS19994, AS10532, AS27357<br />review:	98.129.229.86<br />domain:	dollarauctions.ws<br />country:	US<br />source:	ARIN<br />email:	abuse@rackspace.com<br />inetnum:	98.129.0.0 - 98.129.255.255<br />netname:	RSCP-NET-4<br />descr:	Rackspace Hosting RACKS-8 5000 Walzem Road San Antonio TX 78218<br />ns1:	dns2.stabletransit.com<br />ns2:	dns1.stabletransit.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://deadxhead.hardworld.org/band_eng.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556217</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556217</guid>
			<pubDate>2012-11-08T16:00:08+01:00</pubDate>
			<description><![CDATA[id:	2556217<br />first:	1352386808<br />last:	0<br />md5:	26361c38cc7515258db7d3dcea36f514<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=26361c38cc7515258db7d3dcea36f514<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://deadxhead.hardworld.org/band_eng.html<br />recent:	up<br />response:	alive<br />ip:	212.98.171.156<br />as:	AS12406<br />review:	212.98.171.156<br />domain:	hardworld.org<br />country:	by<br />source:	RIPE<br />email:	ripe@bn.by<br />inetnum:	212.98.171.0 - 212.98.171.255<br />netname:	BNET-3PHASE<br />descr:	Bisiness network jvLeased line 3 phase 02BUSINESS NETWORKBusiness network jvBelhard network part 1<br />ns1:	dns1.helpdesk.by<br />ns2:	dns2.helpdesk.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://capst.org/photos/YanTaoHui-1/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2556007</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2556007</guid>
			<pubDate>2012-11-08T15:20:07+01:00</pubDate>
			<description><![CDATA[id:	2556007<br />first:	1352384407<br />last:	0<br />md5:	48a410b2d04610bae002178b940abe1f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=48a410b2d04610bae002178b940abe1f<br />vt_score:	20/44 (45.5%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://capst.org/photos/YanTaoHui-1/index.htm<br />recent:	up<br />response:	alive<br />ip:	97.74.215.117<br />as:	AS26496<br />review:	97.74.215.117<br />domain:	capst.org<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns25.domaincontrol.com<br />ns2:	ns26.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://berg-golf.de/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2555919</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Script.Packed-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2555919</guid>
			<pubDate>2012-11-08T14:48:01+01:00</pubDate>
			<description><![CDATA[id:	2555919<br />first:	1352382481<br />last:	0<br />md5:	a799834cca0915fe415c26be9c75c937<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a799834cca0915fe415c26be9c75c937<br />vt_score:	9/34 (26.5%)<br />scanner:	clamav<br />virusname:	PUA.Script.Packed-2<br />url:	http://berg-golf.de/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	62.75.209.44<br />as:	AS8972<br />review:	85.25.100.166<br />domain:	berg-golf.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@justdsl.de<br />inetnum:	62.75.208.0 - 62.75.211.255<br />netname:	JustDSL<br />descr:	JustDSL Broadband Dialin<br />ns1:	ns10.nameserverservice.de<br />ns2:	ns9.nameserverservice.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://art-net.hu/js/accordion.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2555856</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.11]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2555856</guid>
			<pubDate>2012-11-08T14:30:00+01:00</pubDate>
			<description><![CDATA[id:	2555856<br />first:	1352381400<br />last:	0<br />md5:	da85c22bcb7a2298b6684795a90e804f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=da85c22bcb7a2298b6684795a90e804f<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/iFrame.BS.11<br />url:	http://art-net.hu/js/accordion.js<br />recent:	up<br />response:	alive<br />ip:	62.77.128.10<br />as:	AS15566<br />review:	62.77.128.10<br />domain:	art-net.hu<br />country:	HU<br />source:	RIPE<br />email:	sheep@infotechna.hu<br />inetnum:	62.77.128.0 - 62.77.128.255<br />netname:	INFOTECHNA<br />descr:	Infotechna Ltd.Internet Service ProviderINFOTECHNA-1<br />ns1:	ns4.infotechna.hu<br />ns2:	ns3.infotechna.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aiz.by/referenc/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2555018</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IframeCU.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2555018</guid>
			<pubDate>2012-11-08T13:50:46+01:00</pubDate>
			<description><![CDATA[id:	2555018<br />first:	1352379046<br />last:	0<br />md5:	f6bf2f60a673d3cd0f4d20505e9dba93<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f6bf2f60a673d3cd0f4d20505e9dba93<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	HTML/IframeCU.A<br />url:	http://aiz.by/referenc/<br />recent:	up<br />response:	alive<br />ip:	93.84.116.213<br />as:	AS6697<br />review:	93.84.116.213<br />domain:	aiz.by<br />country:	BY<br />source:	RIPE<br />email:	dimon@mck.beltelecom.by<br />inetnum:	93.84.112.0 - 93.84.119.255<br />netname:	BELTELECOM-DATACENTER<br />descr:	MCC & REGIONAL DCsDELEGATED FROM BELPAK<br />ns1:	ns2.medialine.by<br />ns2:	ns1.medialine.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://agrofrost.com.my/highlights.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2555016</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.inf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2555016</guid>
			<pubDate>2012-11-08T13:50:45+01:00</pubDate>
			<description><![CDATA[id:	2555016<br />first:	1352379045<br />last:	0<br />md5:	572650dfef252948ce89adbae4722e6c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=572650dfef252948ce89adbae4722e6c<br />vt_score:	22/34 (64.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.inf<br />url:	http://agrofrost.com.my/highlights.html<br />recent:	up<br />response:	alive<br />ip:	203.223.136.199<br />as:	AS24218<br />review:	203.223.136.199<br />domain:	agrofrost.com.my<br />country:	MY<br />source:	APNIC<br />email:	abuse@aims.com.my<br />inetnum:	203.223.128.0 - 203.223.159.255<br />netname:	GTC-MY-SIP-NET<br />descr:	Global Transit Communications, Malaysia, Networks - 203.223.128.0/19In case of abuse, please contact abuse@globaltransit.net<br />ns1:	ns1.wpdns.com<br />ns2:	ns2.wpdns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://202.206.208.43/2007jpkc/2007gdsx/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2554829</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2554829</guid>
			<pubDate>2012-11-08T13:20:25+01:00</pubDate>
			<description><![CDATA[id:	2554829<br />first:	1352377225<br />last:	0<br />md5:	2591556740d2a215cf747de4f34d7dbc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2591556740d2a215cf747de4f34d7dbc<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://202.206.208.43/2007jpkc/2007gdsx/<br />recent:	up<br />response:	alive<br />ip:	202.206.208.43<br />as:	AS4538<br />review:	202.206.208.43<br />domain:	202.206.208.43<br />country:	CN<br />source:	APNIC<br />email:	abuse@net.edu.cn<br />inetnum:	202.206.208.0 - 202.206.223.255<br />netname:	NCEPU-CN<br />descr:	~{;*115gA&4sQ'~}North China Electric Power UniversityBaoding, Hebei 071003, China<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zyx.zju.edu.cn/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547444</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Script-inf.G]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547444</guid>
			<pubDate>2012-11-07T20:10:09+01:00</pubDate>
			<description><![CDATA[id:	2547444<br />first:	1352315409<br />last:	0<br />md5:	dd5c2a2fa880fe3f7da8e4588abb5a16<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dd5c2a2fa880fe3f7da8e4588abb5a16<br />vt_score:	10/44 (22.7%)<br />scanner:	avira<br />virusname:	HTML/Script-inf.G<br />url:	http://zyx.zju.edu.cn/index.html<br />recent:	up<br />response:	alive<br />ip:	218.108.88.199<br />as:	AS24139<br />review:	218.108.88.199<br />domain:	zju.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	allon@chinahcn.com<br />inetnum:	218.108.0.0 - 218.109.255.255<br />netname:	WASU<br />descr:	WASU TV & Communication Holding Co.,Ltd.6/F, Jian Gong Building, NO.20 Wen San Road, Hangzhou,Zhejiang province, P.R.China 310012<br />ns1:	alpha.zju.edu.cn<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://withaoctavia.web.id/2web-about.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547439</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Drop.Agent.AB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547439</guid>
			<pubDate>2012-11-07T20:09:58+01:00</pubDate>
			<description><![CDATA[id:	2547439<br />first:	1352315398<br />last:	0<br />md5:	e8c6b2fc1ce71974ac600e1fcb459832<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e8c6b2fc1ce71974ac600e1fcb459832<br />vt_score:	35/44 (79.5%)<br />scanner:	avira<br />virusname:	HTML/Drop.Agent.AB<br />url:	http://withaoctavia.web.id/2web-about.html<br />recent:	up<br />response:	alive<br />ip:	216.244.85.211<br />as:	AS23033<br />review:	67.231.242.138<br />domain:	web.id<br />country:	US<br />source:	ARIN<br />email:	abuse@turnkeyinternet.net<br />inetnum:	216.244.64.0 - 216.244.95.255<br />netname:	TURNKEY-INTERNET<br />descr:	Turnkey Internet Inc. TURNK-1 4 Airline Drive Suite 105 Albany NY 12205<br />ns1:	b.dns.id<br />ns2:	c.dns.id<br />ns3:	d.dns.id<br />ns4:	e.dns.id<br />ns5:	f.dns.id<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://videant.hu/angol/bmain.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547414</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.T]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547414</guid>
			<pubDate>2012-11-07T20:00:00+01:00</pubDate>
			<description><![CDATA[id:	2547414<br />first:	1352314800<br />last:	0<br />md5:	44deaf32f9cc893d37c5ec936dab60f7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=44deaf32f9cc893d37c5ec936dab60f7<br />vt_score:	30/46 (65.2%)<br />scanner:	AntiVir<br />virusname:	JS/Twetti.T<br />url:	http://videant.hu/angol/bmain.htm<br />recent:	up<br />response:	alive<br />ip:	195.56.193.43<br />as:	AS3340<br />review:	195.56.193.43<br />domain:	videant.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@gts.hu<br />inetnum:	195.56.0.0 - 195.56.255.255<br />netname:	HU-DATANET-960426<br />descr:	GTS - DataNet Telecommunication Ltd<br />ns1:	ns4.m.glbns.com<br />ns2:	ns2.m.glbns.com<br />ns3:	ns3.m.glbns.com<br />ns4:	ns1.m.glbns.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://twojetrojmiasto.pl/programy/rozne8/unlocker1.8.7.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547324</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[APPL/Yabector.Gen5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547324</guid>
			<pubDate>2012-11-07T19:39:58+01:00</pubDate>
			<description><![CDATA[id:	2547324<br />first:	1352313598<br />last:	0<br />md5:	ec50443abb2b49942ebb151e7b2779af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ec50443abb2b49942ebb151e7b2779af<br />vt_score:	23/44 (52.3%)<br />scanner:	avira<br />virusname:	APPL/Yabector.Gen5<br />url:	http://twojetrojmiasto.pl/programy/rozne8/unlocker1.8.7.zip<br />recent:	up<br />response:	alive<br />ip:	79.96.63.141<br />as:	AS12824<br />review:	79.96.63.141<br />domain:	twojetrojmiasto.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.0.0 - 79.96.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://titlelssd.bookonline.com.cn/images/ad/435_62.swf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547319</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/FlashFrame.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547319</guid>
			<pubDate>2012-11-07T19:29:57+01:00</pubDate>
			<description><![CDATA[id:	2547319<br />first:	1352312997<br />last:	0<br />md5:	0dc4c77c7f3593fc7a584c7b10684cd2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0dc4c77c7f3593fc7a584c7b10684cd2<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	HTML/FlashFrame.Gen<br />url:	http://titlelssd.bookonline.com.cn/images/ad/435_62.swf<br />recent:	up<br />response:	alive<br />ip:	124.248.34.115<br />as:	AS4134<br />review:	124.248.34.115<br />domain:	bookonline.com.cn<br />country:	CN<br />source:	APNIC<br />email:	panys@263.net<br />inetnum:	124.248.0.0 - 124.248.127.255<br />netname:	HRXT<br />descr:	Beijing HongRuiXunTong science & technologyDevelopment Co. ltd403, administration Mansion,No.83 FuXing Road, Beijing<br />ns1:	f1g1ns2.dnspod.net<br />ns2:	f1g1ns1.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/lafaetrac.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547193</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547193</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547193<br />first:	1352312396<br />last:	0<br />md5:	3532b19e578284bda3f8add1de6e1476<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3532b19e578284bda3f8add1de6e1476<br />vt_score:	24/43 (55.8%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/lafaetrac.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/fudronace.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547192</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547192<br />first:	1352312396<br />last:	0<br />md5:	02ba4937d5622b3902ec17705eb5d8bb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02ba4937d5622b3902ec17705eb5d8bb<br />vt_score:	25/42 (59.5%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/fudronace.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/chiredelm.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547191</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547191</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547191<br />first:	1352312396<br />last:	0<br />md5:	51bb12b7e0ef40064e9cd8b3ba92898e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=51bb12b7e0ef40064e9cd8b3ba92898e<br />vt_score:	25/43 (58.1%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/chiredelm.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://technogistics.co.za/rttimport/files/carokodro.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547190</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Crypted.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547190</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547190<br />first:	1352312396<br />last:	0<br />md5:	53fe2398f748b50fc2de8d7feb0e4f2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=53fe2398f748b50fc2de8d7feb0e4f2a<br />vt_score:	25/43 (58.1%)<br />scanner:	avira<br />virusname:	HTML/Crypted.Gen<br />url:	http://technogistics.co.za/rttimport/files/carokodro.html<br />recent:	up<br />response:	alive<br />ip:	205.186.141.145<br />as:	AS31815<br />review:	205.186.141.145<br />domain:	technogistics.co.za<br />country:	US<br />source:	ARIN<br />email:	abuse@mediatemple.net<br />inetnum:	205.186.128.0 - 205.186.191.255<br />netname:	MEDIATEMPLE-106<br />descr:	Media Temple, Inc. MEDIAT-10 8520 National Blvd. Building B Culver City CA 90232<br />ns1:	ns1.datapro.co.za<br />ns2:	ns3.datapro.co.za<br />ns3:	ns2.datapro.co.za<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://szczytno.org/hf2009d2]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547186</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.CF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547186</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547186<br />first:	1352312396<br />last:	0<br />md5:	494085f23fbd26340f3d85187ce1e3b0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=494085f23fbd26340f3d85187ce1e3b0<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.CF<br />url:	http://szczytno.org/hf2009d2<br />recent:	up<br />response:	alive<br />ip:	62.129.200.54<br />as:	AS12824<br />review:	62.129.200.54<br />domain:	szczytno.org<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sscan.co.kr/sscan/images/s_home.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547181</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547181</guid>
			<pubDate>2012-11-07T19:19:56+01:00</pubDate>
			<description><![CDATA[id:	2547181<br />first:	1352312396<br />last:	0<br />md5:	04817af8f3fb5324d6003e43abafaac0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=04817af8f3fb5324d6003e43abafaac0<br />vt_score:	17/35 (48.6%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen3<br />url:	http://sscan.co.kr/sscan/images/s_home.gif<br />recent:	up<br />response:	alive<br />ip:	116.126.142.109<br />as:	AS9318<br />review:	116.126.142.109<br />domain:	sscan.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	116.120.0.0 - 116.127.255.255<br />netname:	broadNnet-KR<br />descr:	SK Broadband Co Ltd<br />ns1:	ns1.cafe24.com<br />ns2:	ns2.cafe24.com<br />ns3:	ns0.cafe24.com<br />ns4:	ns.cafe24.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://schenkit.de/js/afunc.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547068</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ZY]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547068</guid>
			<pubDate>2012-11-07T18:49:58+01:00</pubDate>
			<description><![CDATA[id:	2547068<br />first:	1352310598<br />last:	0<br />md5:	c6f3a53b49438ad7fb49de1e4a5604bb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c6f3a53b49438ad7fb49de1e4a5604bb<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.ZY<br />url:	http://schenkit.de/js/afunc.js<br />recent:	up<br />response:	alive<br />ip:	77.75.250.242<br />as:	AS34432<br />review:	77.75.250.242<br />domain:	schenkit.de<br />country:	DE<br />source:	RIPE<br />email:	noc@allied-internet.ag<br />inetnum:	77.75.250.0 - 77.75.250.255<br />netname:	PROFIHOST-NET<br />descr:	allied internet agAm Mittelfelde 29, 30519 Hannover, GermanyColo HannoverProfiHost via h-cix.net<br />ns1:	nsb3.schlundtech.de<br />ns2:	nsd3.schlundtech.de<br />ns3:	nsc3.schlundtech.de<br />ns4:	nsa3.schlundtech.de<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ragverp.nl/images/kruikenbokaal2008/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547059</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.azb]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547059</guid>
			<pubDate>2012-11-07T18:39:58+01:00</pubDate>
			<description><![CDATA[id:	2547059<br />first:	1352309998<br />last:	0<br />md5:	1155cba7e70f15ec02aa901c9ed3e4e8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2424ee2c60e56f9ebe899647e5dc5fba<br />vt_score:	13/36 (36.1%)<br />scanner:	undef<br />virusname:	HTML/IFrame.azb<br />url:	http://ragverp.nl/images/kruikenbokaal2008/index.html<br />recent:	up<br />response:	alive<br />ip:	213.188.129.144<br />as:	AS12994<br />review:	188.93.150.31<br />domain:	ragverp.nl<br />country:	NL<br />source:	RIPE<br />email:	noc@mijndomein.nl<br />inetnum:	213.188.128.0 - 213.188.134.255<br />netname:	NL-MIJNDOMEIN-20090514<br />descr:	mijndomein.nl BVmijndomein.nl BV<br />ns1:	dns21.activeisp.com<br />ns2:	dns20.activeisp.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://privateequity.pl/js/popup.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2547058</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Redirector-ZL [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2547058</guid>
			<pubDate>2012-11-07T18:39:58+01:00</pubDate>
			<description><![CDATA[id:	2547058<br />first:	1352309998<br />last:	0<br />md5:	6e0038c8d522527feb6e507f24bdbaf8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6e0038c8d522527feb6e507f24bdbaf8<br />vt_score:	12/35 (34.3%)<br />scanner:	Avast<br />virusname:	JS:Redirector-ZL [Trj]<br />url:	http://privateequity.pl/js/popup.js<br />recent:	up<br />response:	alive<br />ip:	93.157.100.34<br />as:	AS44514<br />review:	93.157.100.34<br />domain:	privateequity.pl<br />country:	PL<br />source:	RIPE<br />email:	admin@ogicom.pl<br />inetnum:	93.157.96.0 - 93.157.103.255<br />netname:	OGICOM<br />descr:	Ogicom Sp. z o.o.Ogicom Sp. z o.o.<br />ns1:	dns2.spider.pl<br />ns2:	dns1.spider.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://oohstickyou.co.uk/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546993</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.EOP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546993</guid>
			<pubDate>2012-11-07T18:10:15+01:00</pubDate>
			<description><![CDATA[id:	2546993<br />first:	1352308215<br />last:	0<br />md5:	cadf3c03eaf3522693666da4cb88bf12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cadf3c03eaf3522693666da4cb88bf12<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	JS/Agent.EOP<br />url:	http://oohstickyou.co.uk/<br />recent:	up<br />response:	alive<br />ip:	208.113.133.230<br />as:	AS26347<br />review:	66.33.222.34<br />domain:	oohstickyou.co.uk<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	208.113.128.0 - 208.113.223.255<br />netname:	DREAMHOST-BLK1<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns1.dreamhost.com<br />ns2:	ns3.dreamhost.com<br />ns3:	ns2.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://oblstat.mogilev.by/arc_06_2012.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546990</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Drop.Agent.AB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546990</guid>
			<pubDate>2012-11-07T18:10:15+01:00</pubDate>
			<description><![CDATA[id:	2546990<br />first:	1352308215<br />last:	0<br />md5:	dfcce2bc79edf00d3aea5edd8514c946<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dfcce2bc79edf00d3aea5edd8514c946<br />vt_score:	1/36 (2.8%)<br />scanner:	AntiVir<br />virusname:	HTML/Drop.Agent.AB<br />url:	http://oblstat.mogilev.by/arc_06_2012.htm<br />recent:	up<br />response:	alive<br />ip:	194.158.206.224<br />as:	AS6697<br />review:	194.158.206.224<br />domain:	mogilev.by<br />country:	BY<br />source:	RIPE<br />email:	admin@telecom.mogilev.by<br />inetnum:	194.158.206.0 - 194.158.206.255<br />netname:	BELPAK<br />descr:	Republican Unitary Enterprise BELTELECOMMOGILEV branchRepublic of BelarusDELEGATED FROM BELPAK<br />ns1:	ns1.mogilev.by<br />ns2:	ns2.mogilev.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://oblstat.mogilev.by/arc_05_2012.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546989</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Drop.Agent.AB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546989</guid>
			<pubDate>2012-11-07T18:10:15+01:00</pubDate>
			<description><![CDATA[id:	2546989<br />first:	1352308215<br />last:	0<br />md5:	b25200b679697f0de7a9252283a23ec8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b25200b679697f0de7a9252283a23ec8<br />vt_score:	1/36 (2.8%)<br />scanner:	AntiVir<br />virusname:	HTML/Drop.Agent.AB<br />url:	http://oblstat.mogilev.by/arc_05_2012.htm<br />recent:	up<br />response:	alive<br />ip:	194.158.206.224<br />as:	AS6697<br />review:	194.158.206.224<br />domain:	mogilev.by<br />country:	BY<br />source:	RIPE<br />email:	admin@telecom.mogilev.by<br />inetnum:	194.158.206.0 - 194.158.206.255<br />netname:	BELPAK<br />descr:	Republican Unitary Enterprise BELTELECOMMOGILEV branchRepublic of BelarusDELEGATED FROM BELPAK<br />ns1:	ns1.mogilev.by<br />ns2:	ns2.mogilev.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://noris-united.de/media/system/js/caption.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546987</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546987</guid>
			<pubDate>2012-11-07T18:10:13+01:00</pubDate>
			<description><![CDATA[id:	2546987<br />first:	1352308213<br />last:	0<br />md5:	bf5ea8c6ebb92e86ac7cefcf65fd7a2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bf5ea8c6ebb92e86ac7cefcf65fd7a2a<br />vt_score:	14/41 (34.1%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://noris-united.de/media/system/js/caption.js<br />recent:	up<br />response:	alive<br />ip:	83.246.91.7<br />as:	AS24679<br />review:	83.246.91.7<br />domain:	noris-united.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@padberg-it.com<br />inetnum:	83.246.91.0 - 83.246.91.255<br />netname:	PADBERG-IT-NET<br />descr:	Padberg-IT, Inhaber Peter PadbergEscherstrasse 6, D-30159 Hannover, GermanyColocation @ RZ Hannover<br />ns1:	ns1.padberg-it.net<br />ns2:	ns2.padberg-it.net<br />ns3:	ns3.padberg-it.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://members.optushome.com.au/fiveroses/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546920</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.NL.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546920</guid>
			<pubDate>2012-11-07T17:40:06+01:00</pubDate>
			<description><![CDATA[id:	2546920<br />first:	1352306406<br />last:	0<br />md5:	0ead7c424e807dfb371f43fa679efab3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0ead7c424e807dfb371f43fa679efab3<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	JS/iFrame.NL.2<br />url:	http://members.optushome.com.au/fiveroses/<br />recent:	up<br />response:	alive<br />ip:	211.29.152.71<br />as:	AS4804<br />review:	211.29.152.71<br />domain:	optushome.com.au<br />country:	AU<br />source:	APNIC<br />email:	ipadmin@optus.net.au<br />inetnum:	211.28.0.0 - 211.31.255.255<br />netname:	OPTUSINTERNET-AU<br />descr:	OPTUS INTERNET - RETAILINTERNET SERVICESChatswood, Sydney<br />ns1:	ns1.optusnet.com.au<br />ns2:	ns2.optusnet.com.au<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lzanholt.de/sites/brands/rush/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546787</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.agp]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546787</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546787<br />first:	1352304639<br />last:	0<br />md5:	2936a746d795f8ed5b281906ee7779f6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2936a746d795f8ed5b281906ee7779f6<br />vt_score:	22/35 (62.9%)<br />scanner:	avira<br />virusname:	HTML/IFrame.agp<br />url:	http://lzanholt.de/sites/brands/rush/index.htm<br />recent:	up<br />response:	alive<br />ip:	212.172.221.9<br />as:	AS12312<br />review:	212.172.221.9<br />domain:	lzanholt.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@webhoster.de<br />inetnum:	212.172.221.0 - 212.172.221.255<br />netname:	TIS-D406966-NET<br />descr:	webhoster.de AG<br />ns1:	w1.dnsservice.net<br />ns2:	w2.dnsservice.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lgxy.jnu.edu.cn/eec/Admin/Admin_login.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546784</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546784</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546784<br />first:	1352304639<br />last:	0<br />md5:	1c0c7bcfd1c149747eefed9da69ed23f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://lgxy.jnu.edu.cn/eec/Admin/Admin_login.asp<br />recent:	up<br />response:	alive<br />ip:	202.116.0.132<br />as:	AS24564<br />review:	202.116.0.132<br />domain:	jnu.edu.cn<br />country:	CN<br />source:	APNIC<br />email:	cernet-helpdesk-ip@net.edu.cn<br />inetnum:	202.0.0.0 - 203.255.255.255<br />netname:	JINAN-CN<br />descr:	Jinan UniversityGuangzhou, Guangdong Province<br />ns1:	mainb.jnu.edu.cn<br />ns2:	maina.jnu.edu.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546782</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.653825]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546782</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546782<br />first:	1352304639<br />last:	0<br />md5:	9267ea3d91deb98afbfc8d567685af32<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9267ea3d91deb98afbfc8d567685af32<br />vt_score:	20/38 (52.6%)<br />scanner:	avira<br />virusname:	TR/Rogue.KD.653825<br />url:	http://ld.download-guru.com?&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3dmandidee-pixandvideo&amp;]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546781</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546781</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546781<br />first:	1352304639<br />last:	0<br />md5:	f75f457d6d723ac154b38d6977c11fe2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f75f457d6d723ac154b38d6977c11fe2<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3dmandidee-pixandvideo&amp;<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3d3d3d3d&]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546779</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546779</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546779<br />first:	1352304639<br />last:	0<br />md5:	c1703acafe9f005ed7aae0dd95018815<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c1703acafe9f005ed7aae0dd95018815<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3d3d3d3d&<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdezentr.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546776</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546776</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546776<br />first:	1352304639<br />last:	0<br />md5:	6d73e96a9764fd682aa930ffd0009f68<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6d73e96a9764fd682aa930ffd0009f68<br />vt_score:	12/33 (36.4%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdezentr.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kola.by/DISKdezentp.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546775</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Packed.AP.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546775</guid>
			<pubDate>2012-11-07T17:10:39+01:00</pubDate>
			<description><![CDATA[id:	2546775<br />first:	1352304639<br />last:	0<br />md5:	ccbb6456718a5e5ad956ed896196a185<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ccbb6456718a5e5ad956ed896196a185<br />vt_score:	12/35 (34.3%)<br />scanner:	avira<br />virusname:	JS/Packed.AP.1<br />url:	http://kola.by/DISKdezentp.htm<br />recent:	up<br />response:	alive<br />ip:	91.149.157.42<br />as:	AS6697<br />review:	91.149.157.42<br />domain:	kola.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	91.149.157.0 - 91.149.157.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kobacki.eu/shipping_label_usps.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546773</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Graftor.49667]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546773</guid>
			<pubDate>2012-11-07T17:10:38+01:00</pubDate>
			<description><![CDATA[id:	2546773<br />first:	1352304638<br />last:	0<br />md5:	7d9662f5cd7ce9dfd2f56737a3006eee<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7d9662f5cd7ce9dfd2f56737a3006eee<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Graftor.49667<br />url:	http://kobacki.eu/shipping_label_usps.zip<br />recent:	up<br />response:	alive<br />ip:	89.161.156.226<br />as:	AS12824<br />review:	89.161.156.226<br />domain:	kobacki.eu<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.128.0 - 89.161.191.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns2.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p6p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546694</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546694</guid>
			<pubDate>2012-11-07T16:40:40+01:00</pubDate>
			<description><![CDATA[id:	2546694<br />first:	1352302840<br />last:	0<br />md5:	50a1fc669b87ae6809e782f361c71915<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50a1fc669b87ae6809e782f361c71915<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p6p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ice-boy.at.ua/_ld/0/9_hphack.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546658</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Wpepro.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546658</guid>
			<pubDate>2012-11-07T16:20:34+01:00</pubDate>
			<description><![CDATA[id:	2546658<br />first:	1352301634<br />last:	0<br />md5:	13d24cb7ed7c92cc5418dcc60ce1bf0e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=13d24cb7ed7c92cc5418dcc60ce1bf0e<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	SPR/Wpepro.A<br />url:	http://ice-boy.at.ua/_ld/0/9_hphack.rar<br />recent:	up<br />response:	alive<br />ip:	217.199.217.16<br />as:	AS34221<br />review:	217.199.217.16<br />domain:	ice-boy.at.ua<br />country:	RU<br />source:	RIPE<br />email:	dn@quickline.ru<br />inetnum:	217.199.217.0 - 217.199.217.255<br />netname:	UCOZ<br />descr:	UCOZJSC QUICKLINE<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://girlish.com.au/gallery2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546540</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HEUR/HTML.Malware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546540</guid>
			<pubDate>2012-11-07T16:10:11+01:00</pubDate>
			<description><![CDATA[id:	2546540<br />first:	1352301011<br />last:	0<br />md5:	d29ce4afbd1e5a2f604a93735c482b36<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d29ce4afbd1e5a2f604a93735c482b36<br />vt_score:	12/36 (33.3%)<br />scanner:	AntiVir<br />virusname:	HEUR/HTML.Malware<br />url:	http://girlish.com.au/gallery2.html<br />recent:	up<br />response:	alive<br />ip:	202.146.209.82<br />as:	AS24469<br />review:	202.146.209.82<br />domain:	girlish.com.au<br />country:	AU<br />source:	APNIC<br />email:	abuse@netquadrant.com<br />inetnum:	202.146.208.0 - 202.146.215.255<br />netname:	NETQ-SYD<br />descr:	Net Quadrant Pty LtdHosting ProviderAustralia<br />ns1:	ns3.qnetau.com<br />ns2:	ns1.qnetau.com<br />ns3:	ns2.qnetau.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://druidsway-orientals.co.uk/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546292</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546292</guid>
			<pubDate>2012-11-07T15:29:57+01:00</pubDate>
			<description><![CDATA[id:	2546292<br />first:	1352298597<br />last:	0<br />md5:	85bf0e3080c49f635be33c3a272bc7c4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=85bf0e3080c49f635be33c3a272bc7c4<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://druidsway-orientals.co.uk/index.htm<br />recent:	up<br />response:	alive<br />ip:	91.103.216.116<br />as:	AS29550<br />review:	91.103.216.55<br />domain:	druidsway-orientals.co.uk<br />country:	GB<br />source:	RIPE<br />email:	abuse@dataflame.co.uk<br />inetnum:	91.103.216.0 - 91.103.216.255<br />netname:	DFL-NET<br />descr:	DFL-NET<br />ns1:	ns2.dfsv34.com<br />ns2:	ns1.dfsv34.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://deadxhead.hardworld.org/lyrics123.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546140</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546140</guid>
			<pubDate>2012-11-07T15:00:33+01:00</pubDate>
			<description><![CDATA[id:	2546140<br />first:	1352296833<br />last:	0<br />md5:	0d707abbcd15a9ca0bf119b39a68e097<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0d707abbcd15a9ca0bf119b39a68e097<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://deadxhead.hardworld.org/lyrics123.html<br />recent:	up<br />response:	alive<br />ip:	212.98.171.156<br />as:	AS12406<br />review:	212.98.171.156<br />domain:	hardworld.org<br />country:	by<br />source:	RIPE<br />email:	ripe@bn.by<br />inetnum:	212.98.171.0 - 212.98.171.255<br />netname:	BNET-3PHASE<br />descr:	Bisiness network jvLeased line 3 phase 02BUSINESS NETWORKBusiness network jvBelhard network part 1<br />ns1:	dns1.helpdesk.by<br />ns2:	dns2.helpdesk.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://deadxhead.hardworld.org/lemur.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546139</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546139</guid>
			<pubDate>2012-11-07T15:00:33+01:00</pubDate>
			<description><![CDATA[id:	2546139<br />first:	1352296833<br />last:	0<br />md5:	fae75ba06e807c4f805025f5039def9c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fae75ba06e807c4f805025f5039def9c<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://deadxhead.hardworld.org/lemur.html<br />recent:	up<br />response:	alive<br />ip:	212.98.171.156<br />as:	AS12406<br />review:	212.98.171.156<br />domain:	hardworld.org<br />country:	by<br />source:	RIPE<br />email:	ripe@bn.by<br />inetnum:	212.98.171.0 - 212.98.171.255<br />netname:	BNET-3PHASE<br />descr:	Bisiness network jvLeased line 3 phase 02BUSINESS NETWORKBusiness network jvBelhard network part 1<br />ns1:	dns1.helpdesk.by<br />ns2:	dns2.helpdesk.by<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://comune.roncaro.pv.it/layout.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546136</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Agent-ANP Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546136</guid>
			<pubDate>2012-11-07T15:00:33+01:00</pubDate>
			<description><![CDATA[id:	2546136<br />first:	1352296833<br />last:	0<br />md5:	e4099a1903e64f2045324153bb23e183<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e4099a1903e64f2045324153bb23e183<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	JS:Agent-ANP Trj<br />url:	http://comune.roncaro.pv.it/layout.js<br />recent:	up<br />response:	alive<br />ip:	62.149.128.166<br />as:	AS31034<br />review:	62.149.128.157<br />domain:	pv.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bootsbau-liebner.de/drachen1.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546057</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Illredir-S Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546057</guid>
			<pubDate>2012-11-07T14:21:51+01:00</pubDate>
			<description><![CDATA[id:	2546057<br />first:	1352294511<br />last:	0<br />md5:	100da334afb5340eddda81d229346753<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=100da334afb5340eddda81d229346753<br />vt_score:	11/36 (30.6%)<br />scanner:	Avast<br />virusname:	JS:Illredir-S Trj<br />url:	http://bootsbau-liebner.de/drachen1.htm<br />recent:	up<br />response:	alive<br />ip:	82.165.105.240<br />as:	AS8560<br />review:	82.165.105.240<br />domain:	bootsbau-liebner.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns37.1und1.de<br />ns2:	ns38.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://awf-gorzow.edu.pl/cesh/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2546050</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2546050</guid>
			<pubDate>2012-11-07T14:19:58+01:00</pubDate>
			<description><![CDATA[id:	2546050<br />first:	1352294398<br />last:	0<br />md5:	b43d82831e4c2028684447e9c8938745<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b43d82831e4c2028684447e9c8938745<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://awf-gorzow.edu.pl/cesh/index.html<br />recent:	up<br />response:	alive<br />ip:	212.85.110.147<br />as:	AS12824<br />review:	212.85.110.147<br />domain:	awf-gorzow.edu.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.96.0 - 212.85.113.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://alfredvdijk.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2545981</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.ku.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2545981</guid>
			<pubDate>2012-11-07T13:40:07+01:00</pubDate>
			<description><![CDATA[id:	2545981<br />first:	1352292007<br />last:	0<br />md5:	dfbded2fbf41e7dc9ff236eed3ba9e1e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dfbded2fbf41e7dc9ff236eed3ba9e1e<br />vt_score:	13/34 (38.2%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.ku.1<br />url:	http://alfredvdijk.nl/<br />recent:	up<br />response:	alive<br />ip:	213.188.130.108<br />as:	AS12994<br />review:	213.188.130.108<br />domain:	alfredvdijk.nl<br />country:	NO<br />source:	RIPE<br />email:	abuse@mamutactive24.com<br />inetnum:	213.188.128.0 - 213.188.134.255<br />netname:	COM-ACTIVEISP<br />descr:	Active 24 ASA. Region Norway<br />ns1:	dns21.activeisp.com<br />ns2:	dns20.activeisp.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://661.com.cn/images/index0_22.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2545976</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2545976</guid>
			<pubDate>2012-11-07T13:40:07+01:00</pubDate>
			<description><![CDATA[id:	2545976<br />first:	1352292007<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://661.com.cn/images/index0_22.gif<br />recent:	up<br />response:	alive<br />ip:	219.140.195.178<br />as:	AS4134<br />review:	219.140.195.178<br />domain:	661.com.cn<br />country:	CN<br />source:	APNIC<br />email:	wxi@dc.wh.hb.cn<br />inetnum:	219.140.0.0 - 219.140.255.255<br />netname:	CHINANET-HB-WH<br />descr:	Chinanet network in Wuhan city Hubei province<br />ns1:	ns14.xincache.com<br />ns2:	ns13.xincache.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://189.254.225.18/manual/bot.txt???rrrrrrr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2545972</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/Pbot.A.9]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2545972</guid>
			<pubDate>2012-11-07T13:40:07+01:00</pubDate>
			<description><![CDATA[id:	2545972<br />first:	1352292007<br />last:	0<br />md5:	e40e3488996b67a6af3849f62b3c813b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e40e3488996b67a6af3849f62b3c813b<br />vt_score:	27/43 (62.8%)<br />scanner:	AntiVir<br />virusname:	PHP/Pbot.A.9<br />url:	http://189.254.225.18/manual/bot.txt???rrrrrrr<br />recent:	up<br />response:	alive<br />ip:	189.254.225.18<br />as:	AS8151<br />review:	189.254.225.18<br />domain:	189.254.225.18<br />country:	MX<br />source:	LACNIC<br />email:	gccips@reduno.com.mx<br />inetnum:	189.240.0.0 - 189.255.255.255<br />netname:	MX-USCV4-LACNIC<br />descr:	Uninet S.A. de C.V.Periferico Sur, 3190,01900 - Ciudad de México - DFPERIFERICO SUR, 3190, ALVARO OBREG01900 - MEXICO DF - DF<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wscop.org/Church%20of%20Pakistan.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529995</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529995</guid>
			<pubDate>2012-11-05T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2529995<br />first:	1352137797<br />last:	0<br />md5:	609539afdbf76f085e52fb3769b706cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=609539afdbf76f085e52fb3769b706cc<br />vt_score:	0/35 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/Rce.Gen3<br />url:	http://wscop.org/Church%20of%20Pakistan.html<br />recent:	up<br />response:	alive<br />ip:	184.107.50.225<br />as:	AS32613<br />review:	184.107.50.225<br />domain:	wscop.org<br />country:	CA<br />source:	ARIN<br />email:	abuse@noc.privatedns.com<br />inetnum:	184.107.0.0 - 184.107.255.255<br />netname:	IWEB-BLK-07<br />descr:	iWeb Technologies Inc. GIT-20 20, place du Commerce Montreal QC H3E-1Z6<br />ns1:	ns11.b2bhosting.net<br />ns2:	ns12.b2bhosting.net<br />ns3:	ns9.b2bhosting.net<br />ns4:	ns10.b2bhosting.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://windadopracy.pl/kontakt.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529972</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529972</guid>
			<pubDate>2012-11-05T18:39:58+01:00</pubDate>
			<description><![CDATA[id:	2529972<br />first:	1352137198<br />last:	0<br />md5:	1a82265c67cf64011696d82a80ba6185<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1a82265c67cf64011696d82a80ba6185<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://windadopracy.pl/kontakt.html<br />recent:	up<br />response:	alive<br />ip:	83.168.90.14<br />as:	AS31304<br />review:	83.168.90.14<br />domain:	windadopracy.pl<br />country:	PL<br />source:	RIPE<br />email:	lir@tstd.pl<br />inetnum:	83.168.64.0 - 83.168.127.255<br />netname:	PL-ESPOL-20040402<br />descr:	Espol Sp. z o. o.ESPOL<br />ns1:	83.168.111.10<br />ns2:	80.49.205.162<br />ns3:	80.55.152.210<br />ns4:	hunt.socket.pl<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://users.powernet.co.uk/sysserv1/killcmos.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529968</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/KillCMOS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529968</guid>
			<pubDate>2012-11-05T18:39:58+01:00</pubDate>
			<description><![CDATA[id:	2529968<br />first:	1352137198<br />last:	0<br />md5:	f10039174bc4e0a853aa58c731af3a95<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f10039174bc4e0a853aa58c731af3a95<br />vt_score:	29/35 (82.9%)<br />scanner:	avira<br />virusname:	TR/KillCMOS<br />url:	http://users.powernet.co.uk/sysserv1/killcmos.zip<br />recent:	up<br />response:	alive<br />ip:	195.60.3.47<br />as:	AS8689<br />review:	195.60.3.47<br />domain:	powernet.co.uk<br />country:	GB<br />source:	RIPE<br />email:	ripeadmin@power.net.uk<br />inetnum:	195.60.0.0 - 195.60.31.255<br />netname:	UK-POWERNET-960710<br />descr:	Power Internet LtdPower Internet Ltd<br />ns1:	dns1.power.net.uk<br />ns2:	dns0.power.net.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://scientia.hu/klimavaltozas/klimastyle.css]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529894</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Redirector.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529894</guid>
			<pubDate>2012-11-05T17:49:57+01:00</pubDate>
			<description><![CDATA[id:	2529894<br />first:	1352134197<br />last:	0<br />md5:	d452539a65ce37ca7b9fd157c8f2d1d4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d452539a65ce37ca7b9fd157c8f2d1d4<br />vt_score:	23/43 (53.5%)<br />scanner:	avira<br />virusname:	JS/Redirector.A<br />url:	http://scientia.hu/klimavaltozas/klimastyle.css<br />recent:	up<br />response:	alive<br />ip:	195.70.48.67<br />as:	AS8358<br />review:	195.70.48.67<br />domain:	scientia.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@interware.hu<br />inetnum:	195.70.48.64 - 195.70.48.79<br />netname:	IW-MEDIACENTER-NET<br />descr:	MediaCenter Hungary Kft.InterWare Inc.HU<br />ns1:	ns1.mediacenter.hu<br />ns2:	ns2.mediacenter.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mhp.co.uk/power/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529767</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529767</guid>
			<pubDate>2012-11-05T16:50:05+01:00</pubDate>
			<description><![CDATA[id:	2529767<br />first:	1352130605<br />last:	0<br />md5:	6edd068515363aa54ac943ad934cf3f0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6edd068515363aa54ac943ad934cf3f0<br />vt_score:	20/35 (57.1%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://mhp.co.uk/power/index.html<br />recent:	up<br />response:	alive<br />ip:	88.96.224.83<br />as:	AS13037<br />review:	88.96.224.83<br />domain:	mhp.co.uk<br />country:	GB<br />source:	RIPE<br />email:	ripe@zen.co.uk<br />inetnum:	88.96.0.0 - 88.99.255.255<br />netname:	UK-ZEN-20050803<br />descr:	Zen Internet LtdZen Internet Ltd<br />ns1:	ns1.tbdata.net<br />ns2:	ns2.tbdata.net<br />ns3:	ns3.tbdata.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mdxh.com.cn/cp-xd.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529766</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.avu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529766</guid>
			<pubDate>2012-11-05T16:50:05+01:00</pubDate>
			<description><![CDATA[id:	2529766<br />first:	1352130605<br />last:	0<br />md5:	eacb5ac4ca8868faa3f472a167486ea1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eacb5ac4ca8868faa3f472a167486ea1<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.avu<br />url:	http://mdxh.com.cn/cp-xd.htm<br />recent:	up<br />response:	alive<br />ip:	125.77.197.11<br />as:	AS4134<br />review:	125.77.197.11<br />domain:	mdxh.com.cn<br />country:	CN<br />source:	APNIC<br />email:	fjnic@fjdcb.fz.fj.cn<br />inetnum:	125.77.0.0 - 125.77.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET Fujian province networkChina Telecom7,East Street ,Fuzhou ,Fujian ,PRC<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://light048.com.ne.kr/art-2-01.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529765</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[VBS/Changeset.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529765</guid>
			<pubDate>2012-11-05T16:50:05+01:00</pubDate>
			<description><![CDATA[id:	2529765<br />first:	1352130605<br />last:	0<br />md5:	7dd94a170c7c05408306ec8d00ee1341<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7dd94a170c7c05408306ec8d00ee1341<br />vt_score:	33/35 (94.3%)<br />scanner:	avira<br />virusname:	VBS/Changeset.A<br />url:	http://light048.com.ne.kr/art-2-01.htm<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p368p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529750</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529750</guid>
			<pubDate>2012-11-05T16:19:59+01:00</pubDate>
			<description><![CDATA[id:	2529750<br />first:	1352128799<br />last:	0<br />md5:	633863d532419b713245b4885e062df6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=633863d532419b713245b4885e062df6<br />vt_score:	25/35 (71.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p368p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p360p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529749</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529749</guid>
			<pubDate>2012-11-05T16:19:59+01:00</pubDate>
			<description><![CDATA[id:	2529749<br />first:	1352128799<br />last:	0<br />md5:	529e384c50a18c9af97d8206a25285c1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=529e384c50a18c9af97d8206a25285c1<br />vt_score:	25/35 (71.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p360p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p260p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529748</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529748</guid>
			<pubDate>2012-11-05T16:19:59+01:00</pubDate>
			<description><![CDATA[id:	2529748<br />first:	1352128799<br />last:	0<br />md5:	59275147efe8186cc654876d71757aa8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=59275147efe8186cc654876d71757aa8<br />vt_score:	25/35 (71.4%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p260p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p188p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529747</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529747</guid>
			<pubDate>2012-11-05T16:19:59+01:00</pubDate>
			<description><![CDATA[id:	2529747<br />first:	1352128799<br />last:	0<br />md5:	0954142cb80eac550932903ff0718d3e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0954142cb80eac550932903ff0718d3e<br />vt_score:	26/35 (74.3%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p188p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jhinton.info/ancestors/william%20howard%20hinton.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529745</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bfi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529745</guid>
			<pubDate>2012-11-05T16:19:58+01:00</pubDate>
			<description><![CDATA[id:	2529745<br />first:	1352128798<br />last:	0<br />md5:	b13925fdc9d98a6d124afd5744b23589<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b13925fdc9d98a6d124afd5744b23589<br />vt_score:	0/45 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.bfi<br />url:	http://jhinton.info/ancestors/william%20howard%20hinton.htm<br />recent:	up<br />response:	alive<br />ip:	97.74.215.146<br />as:	AS26496<br />review:	97.74.215.146<br />domain:	jhinton.info<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	97.74.0.0 - 97.74.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns18.domaincontrol.com<br />ns2:	ns17.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://f.regx.in/451/mysexgame.jar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529532</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JAVA/Runem.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529532</guid>
			<pubDate>2012-11-05T15:39:58+01:00</pubDate>
			<description><![CDATA[id:	2529532<br />first:	1352126398<br />last:	0<br />md5:	8e727478a7aed15613b3710d6e9db1ca<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f8927453368ea4d58798fd098927306c<br />vt_score:	16/35 (45.7%)<br />scanner:	avira<br />virusname:	JAVA/Runem.A<br />url:	http://f.regx.in/451/mysexgame.jar<br />recent:	up<br />response:	alive<br />ip:	91.219.194.29<br />as:	AS49505<br />review:	91.219.194.29<br />domain:	regx.in<br />country:	RU<br />source:	RIPE<br />email:	michelin@best-hoster.ru<br />inetnum:	91.219.192.0 - 91.219.195.255<br />netname:	BEST-HOSTER-NET<br />descr:	Best-Hoster Group Co. Ltd.Best-Hoster Group Co. Ltd.<br />ns1:	ns31.dns-rus.net<br />ns2:	ns32.dns-rus.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dworjanin.ch/english/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529468</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.JS.IFR.as.4]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529468</guid>
			<pubDate>2012-11-05T15:00:45+01:00</pubDate>
			<description><![CDATA[id:	2529468<br />first:	1352124045<br />last:	0<br />md5:	bf96b7299140401463fccdc4b2f22989<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bf96b7299140401463fccdc4b2f22989<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Dldr.JS.IFR.as.4<br />url:	http://dworjanin.ch/english/home.html<br />recent:	up<br />response:	alive<br />ip:	208.99.113.74<br />as:	AS16724<br />review:	208.99.113.74<br />domain:	dworjanin.ch<br />country:	US<br />source:	ARIN<br />email:	noc@esnet.com<br />inetnum:	208.99.113.0 - 208.99.113.255<br />netname:	ESN-7-208-99-113-0<br />descr:	IDAGroup IDAGR 7143 SR 54 New Port Richey FL 34653<br />ns1:	dns2.ips.ch<br />ns2:	dns1.ips.ch<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bestpack.it/index.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529358</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529358</guid>
			<pubDate>2012-11-05T14:10:08+01:00</pubDate>
			<description><![CDATA[id:	2529358<br />first:	1352121008<br />last:	0<br />md5:	5ab533b3d52376daddb751cec2451afb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5ab533b3d52376daddb751cec2451afb<br />vt_score:	27/42 (64.3%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://bestpack.it/index.php<br />recent:	up<br />response:	alive<br />ip:	91.214.72.38<br />as:	AS49360<br />review:	91.214.72.38<br />domain:	bestpack.it<br />country:	IT<br />source:	RIPE<br />email:	alessandro.romano@rpeng.it<br />inetnum:	91.214.72.0 - 91.214.75.255<br />netname:	POSITIVONET-NET<br />descr:	Rp Engineering di Romano Alessandro & C. S.A.S.Positivo Net1<br />ns1:	ns3.rpengineering.it<br />ns2:	ns2.rpengineering.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://b2b.dk21.co.kr/popup.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529332</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.A.37]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529332</guid>
			<pubDate>2012-11-05T13:56:51+01:00</pubDate>
			<description><![CDATA[id:	2529332<br />first:	1352120211<br />last:	0<br />md5:	e588bbb91db1c8c32cde4af62f095adb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e588bbb91db1c8c32cde4af62f095adb<br />vt_score:	0/46 (0.0%)<br />scanner:	AntiVir<br />virusname:	HTML/IFrame.A.37<br />url:	http://b2b.dk21.co.kr/popup.html<br />recent:	up<br />response:	alive<br />ip:	219.253.207.202<br />as:	AS18302<br />review:	219.253.207.202<br />domain:	dk21.co.kr<br />country:	kr<br />source:	APNIC<br />email:	kim.yunsog@sk.com<br />inetnum:	219.253.0.0 - 219.253.255.255 ( - 219.253.255.255<br />netname:	SKNETWORKS-METRO-shinwoo<br />descr:	<br />ns1:	web_homepage<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://121.10.105.29:85/tt/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2529205</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2529205</guid>
			<pubDate>2012-11-05T13:19:57+01:00</pubDate>
			<description><![CDATA[id:	2529205<br />first:	1352117997<br />last:	0<br />md5:	189ecf635c172a01ef95206d3cb45cde<br />virustotal:	http://www.virustotal.com/analisis/21e4ba326f6ee3b71f26a4c1d5ece7d2e8528b47e86b098c8bcf972694403f9a-1270739471<br />vt_score:	37/39 (94.87%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://121.10.105.29:85/tt/1.exe<br />recent:	up<br />response:	alive<br />ip:	121.10.105.29<br />as:	AS4134<br />review:	121.10.105.29<br />domain:	121.10.105.29<br />country:	CN<br />source:	APNIC<br />email:	abuse@gddc.com.cn<br />inetnum:	121.8.0.0 - 121.15.255.255<br />netname:	CHINANET-GD<br />descr:	CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vandemoorteleitalia.it/js/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527154</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.aai.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527154</guid>
			<pubDate>2012-11-04T20:29:58+01:00</pubDate>
			<description><![CDATA[id:	2527154<br />first:	1352057398<br />last:	0<br />md5:	0f9b6ebe169cf7b0f07f3728150f1ced<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0f9b6ebe169cf7b0f07f3728150f1ced<br />vt_score:	21/36 (58.3%)<br />scanner:	avira<br />virusname:	JS/iFrame.aai.1<br />url:	http://vandemoorteleitalia.it/js/jquery.js<br />recent:	up<br />response:	alive<br />ip:	66.71.137.43<br />as:	AS31034<br />review:	66.71.137.43<br />domain:	vandemoorteleitalia.it<br />country:	US<br />source:	ARIN<br />email:	noc@9net.it<br />inetnum:	66.71.128.0 - 66.71.191.255<br />netname:	NETAPPSERV-1BLK<br />descr:	Network Application Services, Inc. NAS 1719 State Rt 10 Parsippany NJ 07054<br />ns1:	ns1.9netweb.it<br />ns2:	ns2.9netweb.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sukurs.palatyn.pl/sukurs/index.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527118</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.AZC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527118</guid>
			<pubDate>2012-11-04T19:49:57+01:00</pubDate>
			<description><![CDATA[id:	2527118<br />first:	1352054997<br />last:	0<br />md5:	8acb010c2d16640bf7ac26bd24916be8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8acb010c2d16640bf7ac26bd24916be8<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.AZC<br />url:	http://sukurs.palatyn.pl/sukurs/index.htm<br />recent:	up<br />response:	alive<br />ip:	212.85.120.195<br />as:	AS12824<br />review:	212.85.120.195<br />domain:	palatyn.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	212.85.114.0 - 212.85.127.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns3.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sniitnigeria.org/schooloflifelonglearning.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527094</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Nimda]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527094</guid>
			<pubDate>2012-11-04T19:11:09+01:00</pubDate>
			<description><![CDATA[id:	2527094<br />first:	1352052669<br />last:	0<br />md5:	8639ec136927dd93c619e18d041134eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8639ec136927dd93c619e18d041134eb<br />vt_score:	0/46 (0.0%)<br />scanner:	AhnLab_V3<br />virusname:	HTML/Nimda<br />url:	http://sniitnigeria.org/schooloflifelonglearning.html<br />recent:	up<br />response:	alive<br />ip:	174.123.45.202<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	94.76.229.2<br />domain:	sniitnigeria.org<br />country:	GB<br />source:	RIPE<br />email:	abuse@as29550.net<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	AS29550-infra<br />descr:	Canonical range for HP5-right<br />ns1:	ns1.weblagos.com<br />ns2:	ns2.weblagos.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sktd-lom.si/wp-includes/images/css.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527093</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/IRCBOT.AE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527093</guid>
			<pubDate>2012-11-04T19:11:09+01:00</pubDate>
			<description><![CDATA[id:	2527093<br />first:	1352052669<br />last:	0<br />md5:	f1a287689ccbfe03674d3d65c3a626d0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1a287689ccbfe03674d3d65c3a626d0<br />vt_score:	18/35 (51.4%)<br />scanner:	avira<br />virusname:	PHP/IRCBOT.AE<br />url:	http://sktd-lom.si/wp-includes/images/css.jpg<br />recent:	up<br />response:	alive<br />ip:	91.185.205.179<br />as:	AS41828<br />review:	91.185.205.179<br />domain:	sktd-lom.si<br />country:	NZ<br />source:	RIPE<br />email:	abuse@tusmobil.si<br />inetnum:	91.185.205.144 - 91.185.206.151<br />netname:	SI-TUSMOBIL-ETECH-MEDIA-2<br />descr:	ETECH MEDIA Ltd.Po box 36289Merivale ChristchurchTUSMOBIL d.o.o.<br />ns1:	ns1.si-shell.net<br />ns2:	ns2.si-shell.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://perincho.com.ar/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527055</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BS.16]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527055</guid>
			<pubDate>2012-11-04T18:49:56+01:00</pubDate>
			<description><![CDATA[id:	2527055<br />first:	1352051396<br />last:	0<br />md5:	fcd7ddc8eed11f397d67a69a93d689ce<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fcd7ddc8eed11f397d67a69a93d689ce<br />vt_score:	0/35 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.BS.16<br />url:	http://perincho.com.ar/<br />recent:	up<br />response:	alive<br />ip:	200.59.119.134<br />as:	AS11311<br />review:	31.170.162.245<br />domain:	perincho.com.ar<br />country:	US<br />source:	RIPE<br />email:	abuse@main-hosting.com<br />inetnum:	200.59.112.0 - 200.59.127.255<br />netname:	MAIN-HOSTING-SERVERS<br />descr:	Main Hosting Servers<br />ns1:	ns1.sinectis.com.ar<br />ns2:	ns2.sinectis.com.ar<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pafm.info/math/%D1%D4%C7%20%D5%C8%D1%ED.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527052</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/SrcInject.2899]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527052</guid>
			<pubDate>2012-11-04T18:49:56+01:00</pubDate>
			<description><![CDATA[id:	2527052<br />first:	1352051396<br />last:	0<br />md5:	3d6001dc412770dccdfd990fa7437e04<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3d6001dc412770dccdfd990fa7437e04<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	HTML/SrcInject.2899<br />url:	http://pafm.info/math/%D1%D4%C7%20%D5%C8%D1%ED.htm<br />recent:	up<br />response:	alive<br />ip:	209.212.145.13<br />as:	AS32181<br />review:	209.212.145.13<br />domain:	pafm.info<br />country:	US<br />source:	ARIN<br />email:	abuse@gigenet.com<br />inetnum:	209.212.144.0 - 209.212.159.255<br />netname:	GIGE<br />descr:	Ecomdevel, LLC ECOMD 545 E. Algonquin Rd Suite D Arlington Heights IL 60005<br />ns1:	ns3.qusra.net<br />ns2:	ns4.qusra.net<br />ns3:	ns1.qusra.net<br />ns4:	ns2.qusra.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mdxh.com.cn/old/zzqsy.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527013</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.avu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527013</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2527013<br />first:	1352047229<br />last:	0<br />md5:	9b90cc963f92fa03e49c7991809bcb73<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9b90cc963f92fa03e49c7991809bcb73<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.avu<br />url:	http://mdxh.com.cn/old/zzqsy.htm<br />recent:	up<br />response:	alive<br />ip:	125.77.197.11<br />as:	AS4134<br />review:	125.77.197.11<br />domain:	mdxh.com.cn<br />country:	CN<br />source:	APNIC<br />email:	fjnic@fjdcb.fz.fj.cn<br />inetnum:	125.77.0.0 - 125.77.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET Fujian province networkChina Telecom7,East Street ,Fuzhou ,Fujian ,PRC<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ld.download-guru.com?s=3dgta]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527005</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.364032]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527005</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2527005<br />first:	1352047229<br />last:	0<br />md5:	73c5895d39974c29df72dafc901b4cbb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=73c5895d39974c29df72dafc901b4cbb<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	TR/Agent.364032<br />url:	http://ld.download-guru.com?s=3dgta<br />recent:	up<br />response:	alive<br />ip:	95.211.162.230<br />as:	AS16265<br />review:	95.211.162.230<br />domain:	download-guru.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.download-guru.com<br />ns2:	ns2.download-guru.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://last0628.com.ne.kr/home/sub0.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527004</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.psa.24]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527004</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2527004<br />first:	1352047229<br />last:	0<br />md5:	4affe20b5ef1f1e19d417cd32b5a2703<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4affe20b5ef1f1e19d417cd32b5a2703<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.psa.24<br />url:	http://last0628.com.ne.kr/home/sub0.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kngf.info/uslugi9.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2527000</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2527000</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2527000<br />first:	1352047229<br />last:	0<br />md5:	0c8e9ef15c4adb3be42b84241d868bb0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0c8e9ef15c4adb3be42b84241d868bb0<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://kngf.info/uslugi9.html<br />recent:	up<br />response:	alive<br />ip:	90.156.201.47<br />as:	AS25532<br />review:	90.156.201.42<br />domain:	kngf.info<br />country:	RU<br />source:	RIPE<br />email:	abuse@masterhost.ru<br />inetnum:	90.156.201.0 - 90.156.201.255<br />netname:	MASTERHOST-HOSTING<br />descr:	Masterhost.ru is a hosting and technical support organization.<br />ns1:	ns2.masterhost.ru<br />ns2:	ns.masterhost.ru<br />ns3:	ns1.masterhost.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kngf.info/uslugi8.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526999</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526999</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2526999<br />first:	1352047229<br />last:	0<br />md5:	393546160e0d594682b0c3494922c258<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=393546160e0d594682b0c3494922c258<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://kngf.info/uslugi8.html<br />recent:	up<br />response:	alive<br />ip:	90.156.201.47<br />as:	AS25532<br />review:	90.156.201.41<br />domain:	kngf.info<br />country:	RU<br />source:	RIPE<br />email:	abuse@masterhost.ru<br />inetnum:	90.156.201.0 - 90.156.201.255<br />netname:	MASTERHOST-HOSTING<br />descr:	Masterhost.ru is a hosting and technical support organization.<br />ns1:	ns2.masterhost.ru<br />ns2:	ns.masterhost.ru<br />ns3:	ns1.masterhost.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kngf.info/uslugi2.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526998</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Rce.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526998</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2526998<br />first:	1352047229<br />last:	0<br />md5:	4e251662a37ec9949fb08f21b7a285f0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4e251662a37ec9949fb08f21b7a285f0<br />vt_score:	21/43 (48.8%)<br />scanner:	avira<br />virusname:	HTML/Rce.Gen3<br />url:	http://kngf.info/uslugi2.html<br />recent:	up<br />response:	alive<br />ip:	90.156.201.47<br />as:	AS25532<br />review:	90.156.201.47<br />domain:	kngf.info<br />country:	RU<br />source:	RIPE<br />email:	abuse@masterhost.ru<br />inetnum:	90.156.201.0 - 90.156.201.255<br />netname:	MASTERHOST-HOSTING<br />descr:	Masterhost.ru is a hosting and technical support organization.<br />ns1:	ns2.masterhost.ru<br />ns2:	ns.masterhost.ru<br />ns3:	ns1.masterhost.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://klopp-holz.de/media/system/js/mootools.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526997</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.BO.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526997</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2526997<br />first:	1352047229<br />last:	0<br />md5:	c14f6272a03a50a9cce52c3ddd4beeab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c14f6272a03a50a9cce52c3ddd4beeab<br />vt_score:	17/39 (43.6%)<br />scanner:	avira<br />virusname:	JS/iFrame.BO.1<br />url:	http://klopp-holz.de/media/system/js/mootools.js<br />recent:	up<br />response:	alive<br />ip:	83.246.64.43<br />as:	AS24679<br />review:	83.246.64.43<br />domain:	klopp-holz.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@hostway.de<br />inetnum:	83.246.0.0 - 83.246.127.255<br />netname:	DE-SSERV-20040422<br />descr:	Hostway Deutschland GmbH<br />ns1:	ns3.padberg-it.net<br />ns2:	ns1.padberg-it.net<br />ns3:	ns2.padberg-it.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p62p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526994</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526994</guid>
			<pubDate>2012-11-04T17:40:29+01:00</pubDate>
			<description><![CDATA[id:	2526994<br />first:	1352047229<br />last:	0<br />md5:	34c7f4b2ab34bc31338c65c2387b0ef1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=34c7f4b2ab34bc31338c65c2387b0ef1<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p62p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://foundation.net.in/js/main.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526845</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526845</guid>
			<pubDate>2012-11-04T16:10:19+01:00</pubDate>
			<description><![CDATA[id:	2526845<br />first:	1352041819<br />last:	0<br />md5:	e7bfe59e2470d6a07fac8c97069ef191<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e7bfe59e2470d6a07fac8c97069ef191<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/RunForest.B<br />url:	http://foundation.net.in/js/main.js<br />recent:	up<br />response:	alive<br />ip:	174.123.217.154<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.123.217.154<br />domain:	foundation.net.in<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	174.120.0.0 - 174.123.255.255<br />netname:	NETBLK-THEPLANET-BLK-16<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns.foundation.net.in<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://deltatheta.org/barcamp/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526255</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.alf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526255</guid>
			<pubDate>2012-11-04T15:50:10+01:00</pubDate>
			<description><![CDATA[id:	2526255<br />first:	1352040610<br />last:	0<br />md5:	d01c1d43a87eb08e0f59ca31cf134f73<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d01c1d43a87eb08e0f59ca31cf134f73<br />vt_score:	19/36 (52.8%)<br />scanner:	avira<br />virusname:	JS/Agent.alf<br />url:	http://deltatheta.org/barcamp/<br />recent:	up<br />response:	alive<br />ip:	67.205.50.41<br />as:	AS26347<br />review:	67.205.50.41<br />domain:	deltatheta.org<br />country:	US<br />source:	ARIN<br />email:	abuse@dreamhost.com<br />inetnum:	67.205.0.0 - 67.205.63.255<br />netname:	DREAMHOST-BLK7<br />descr:	New Dream Network, LLC NDN 417 Associated Rd. PMB #257 Brea CA 92821<br />ns1:	ns3.dreamhost.com<br />ns2:	ns1.dreamhost.com<br />ns3:	ns2.dreamhost.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dehoevelith.nl/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2526252</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2526252</guid>
			<pubDate>2012-11-04T15:50:10+01:00</pubDate>
			<description><![CDATA[id:	2526252<br />first:	1352040610<br />last:	0<br />md5:	9d6ea276a908e44c9001bdc6f543cb84<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=19bab035fa1cfb8742429f536ed7dc54<br />vt_score:	29/44 (65.9%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://dehoevelith.nl/<br />recent:	up<br />response:	alive<br />ip:	213.207.99.36<br />as:	AS9150<br />review:	213.207.99.36<br />domain:	dehoevelith.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@interconnect.nl<br />inetnum:	213.207.99.32 - 213.207.99.39<br />netname:	RESULT-IT<br />descr:	Result-ITtbv colo<br />ns1:	ns2.transip.net<br />ns2:	ns1.transip.net<br />ns3:	ns1.result-it.nl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://codingcrew.de/marty/downloads/traymenu.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525816</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Securisk]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525816</guid>
			<pubDate>2012-11-04T15:00:26+01:00</pubDate>
			<description><![CDATA[id:	2525816<br />first:	1352037626<br />last:	0<br />md5:	80f76c75726ee601846908f8f0294ae2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=80f76c75726ee601846908f8f0294ae2<br />vt_score:	17/31 (54.8%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Securisk<br />url:	http://codingcrew.de/marty/downloads/traymenu.zip<br />recent:	up<br />response:	alive<br />ip:	80.237.132.235<br />as:	AS20773<br />review:	80.237.132.235<br />domain:	codingcrew.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.132.128 - 80.237.132.255<br />netname:	HE-SH-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.de<br />ns1:	b1.wpns.hosteurope.de<br />ns2:	b1.wsns.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ateliercirkel.be/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525789</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.bnz]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525789</guid>
			<pubDate>2012-11-04T14:20:07+01:00</pubDate>
			<description><![CDATA[id:	2525789<br />first:	1352035207<br />last:	0<br />md5:	0ccb161c2401ea83c2ba2b2b5658893b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0ccb161c2401ea83c2ba2b2b5658893b<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.bnz<br />url:	http://ateliercirkel.be/<br />recent:	up<br />response:	alive<br />ip:	217.19.232.140<br />as:	AS34762<br />review:	217.19.232.140<br />domain:	ateliercirkel.be<br />country:	BE<br />source:	RIPE<br />email:	abuse@combell.com<br />inetnum:	217.19.224.0 - 217.19.232.251<br />netname:	COMBELL<br />descr:	COMBELL NetworkBrussels, Belgium<br />ns1:	ns3.combell.net<br />ns2:	ns4.combell.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://arkpro.org/soda/wor21]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525787</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.psa.11]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525787</guid>
			<pubDate>2012-11-04T14:20:06+01:00</pubDate>
			<description><![CDATA[id:	2525787<br />first:	1352035206<br />last:	0<br />md5:	668639ed85bba6dafe55198d2cc10a7d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=668639ed85bba6dafe55198d2cc10a7d<br />vt_score:	17/36 (47.2%)<br />scanner:	avira<br />virusname:	JS/iFrame.psa.11<br />url:	http://arkpro.org/soda/wor21<br />recent:	up<br />response:	alive<br />ip:	66.147.226.54<br />as:	AS23535<br />review:	66.147.226.54<br />domain:	arkpro.org<br />country:	US<br />source:	ARIN<br />email:	abuse@hostrocket.com<br />inetnum:	66.147.224.0 - 66.147.239.255<br />netname:	HRWEBSERVICES-2<br />descr:	HostRocket Web Services HRWE 21 Corporate Drive - Suite 203 Clifton Park NY 12065<br />ns1:	dns2.hrnoc.net<br />ns2:	dns1.hrnoc.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://albergopineta.it/_vti_bin/library.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525781</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Iframe-RB Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525781</guid>
			<pubDate>2012-11-04T14:20:06+01:00</pubDate>
			<description><![CDATA[id:	2525781<br />first:	1352035206<br />last:	0<br />md5:	25859b55d982ed73a698ed66c7f7e47b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=25859b55d982ed73a698ed66c7f7e47b<br />vt_score:	12/36 (33.3%)<br />scanner:	Avast<br />virusname:	JS:Iframe-RB Trj<br />url:	http://albergopineta.it/_vti_bin/library.js<br />recent:	up<br />response:	alive<br />ip:	217.73.238.20<br />as:	AS31034<br />review:	217.73.238.20<br />domain:	albergopineta.it<br />country:	IT<br />source:	RIPE<br />email:	ced@consultingweb.it<br />inetnum:	217.73.232.0 - 217.73.239.255<br />netname:	ALICOM<br />descr:	Alicom S.r.l. NetworkAlicom s.r.l. Network<br />ns1:	dns.consultingweb.it<br />ns2:	dns2.consultingweb.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aadigitalaerials.co.uk/aerial-services.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525778</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.axi.4]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525778</guid>
			<pubDate>2012-11-04T14:20:05+01:00</pubDate>
			<description><![CDATA[id:	2525778<br />first:	1352035205<br />last:	0<br />md5:	d4d80890533f5351f6012fb158d6c1f5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d4d80890533f5351f6012fb158d6c1f5<br />vt_score:	0/36 (0.0%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.axi.4<br />url:	http://aadigitalaerials.co.uk/aerial-services.html<br />recent:	up<br />response:	alive<br />ip:	173.254.28.117<br />as:	AS11798<br />review:	173.254.28.117<br />domain:	aadigitalaerials.co.uk<br />country:	US<br />source:	ARIN<br />email:	support@bluehost.com<br />inetnum:	173.254.0.0 - 173.254.127.255<br />netname:	BLUEHOST-NETWORK-8<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns3.pipedns.com<br />ns2:	ns1.pipedns.com<br />ns3:	ns2.pipedns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://61.19.100.58/yst/anewweb/database.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525777</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525777</guid>
			<pubDate>2012-11-04T14:20:05+01:00</pubDate>
			<description><![CDATA[id:	2525777<br />first:	1352035205<br />last:	0<br />md5:	192c694ce5d670722a1d455c0be93451<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=192c694ce5d670722a1d455c0be93451<br />vt_score:	15/35 (42.9%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://61.19.100.58/yst/anewweb/database.html<br />recent:	up<br />response:	alive<br />ip:	61.19.100.58<br />as:	AS9931<br />review:	61.19.100.58<br />domain:	61.19.100.58<br />country:	TH<br />source:	APNIC<br />email:	admin-thix@cat.net.th<br />inetnum:	61.19.64.0 - 61.19.127.255<br />netname:	CAT-ISP-NET<br />descr:	72 Charoenkrung Road Bangrak Bangkok THAILAND 10501<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://209.200.108.25/fr/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2525775</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Blacole.BF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2525775</guid>
			<pubDate>2012-11-04T14:20:05+01:00</pubDate>
			<description><![CDATA[id:	2525775<br />first:	1352035205<br />last:	0<br />md5:	b30327c37927cb9e380919b70e7c576a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b30327c37927cb9e380919b70e7c576a<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Blacole.BF<br />url:	http://209.200.108.25/fr/index.html<br />recent:	up<br />response:	alive<br />ip:	209.200.108.25<br />as:	AS14992<br />review:	209.200.108.25<br />domain:	209.200.108.25<br />country:	US<br />source:	ARIN<br />email:	abuse@crystaltech.com<br />inetnum:	209.200.64.0 - 209.200.127.255<br />netname:	CRYSTALTECH-BLK-5<br />descr:	CrystalTech Web Hosting Inc. CRTW 1125 W. Pinnacle Peak Road, Suite 103 Phoenix AZ 85027<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://capeannvernalpond.org/list/msg133614118300.txt]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2523497</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.JH.17]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2523497</guid>
			<pubDate>2012-11-04T00:20:00+01:00</pubDate>
			<description><![CDATA[id:	2523497<br />first:	1351984800<br />last:	0<br />md5:	d39144f77c0af2a307d1d387df1c84c8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d39144f77c0af2a307d1d387df1c84c8<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	TR/Agent.JH.17<br />url:	http://capeannvernalpond.org/list/msg133614118300.txt<br />recent:	up<br />response:	alive<br />ip:	69.90.211.15<br />as:	AS13768<br />review:	69.90.211.43<br />domain:	capeannvernalpond.org<br />country:	US<br />source:	ARIN<br />email:	net-admin@peer1.net<br />inetnum:	69.90.0.0 - 69.90.255.255<br />netname:	PEER1-BLK-08<br />descr:	Peer 1 Network Inc. PER1 75 Broad Street 2nd Floor New York NY 10004<br />ns1:	ns.addr.com<br />ns2:	ns2.addr.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://web-hamster.de/programme/progs/magnum.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522983</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JOKE/Gun]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522983</guid>
			<pubDate>2012-11-03T19:00:00+01:00</pubDate>
			<description><![CDATA[id:	2522983<br />first:	1351965600<br />last:	0<br />md5:	fa03a9890bd15ec9d1399cbd46d3b8d7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fa03a9890bd15ec9d1399cbd46d3b8d7<br />vt_score:	19/36 (52.8%)<br />scanner:	AntiVir<br />virusname:	JOKE/Gun<br />url:	http://web-hamster.de/programme/progs/magnum.zip<br />recent:	up<br />response:	alive<br />ip:	80.237.132.42<br />as:	AS20773<br />review:	80.237.132.42<br />domain:	web-hamster.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.132.0 - 80.237.132.127<br />netname:	HE-SH-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.deDE-HEC-80-237-128<br />ns1:	ns1.hans.hosteurope.de<br />ns2:	ns2.hans.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://upstart.de/media/gallery_urpferd_04.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522955</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.S.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522955</guid>
			<pubDate>2012-11-03T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2522955<br />first:	1351964997<br />last:	0<br />md5:	4dd7d01361c042399db811e5425cdf78<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4dd7d01361c042399db811e5425cdf78<br />vt_score:	18/36 (50%)<br />scanner:	avira<br />virusname:	JS/iFrame.S.2<br />url:	http://upstart.de/media/gallery_urpferd_04.jpg<br />recent:	up<br />response:	alive<br />ip:	80.237.132.10<br />as:	AS20773<br />review:	80.237.132.10<br />domain:	upstart.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.132.0 - 80.237.132.127<br />netname:	HE-SH-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.deDE-HEC-80-237-128<br />ns1:	c1.wpns.hosteurope.de<br />ns2:	c1.wsns.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://szczytno.org/hf2009d2/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522948</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Obfuscated.CF]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522948</guid>
			<pubDate>2012-11-03T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2522948<br />first:	1351964997<br />last:	0<br />md5:	494085f23fbd26340f3d85187ce1e3b0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=494085f23fbd26340f3d85187ce1e3b0<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/Obfuscated.CF<br />url:	http://szczytno.org/hf2009d2/<br />recent:	up<br />response:	alive<br />ip:	62.129.200.54<br />as:	AS12824<br />review:	62.129.200.54<br />domain:	szczytno.org<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	62.129.192.0 - 62.129.223.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://societyofalgorithm.org/publicationconversation/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522944</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/IFrame.Inje.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522944</guid>
			<pubDate>2012-11-03T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2522944<br />first:	1351964997<br />last:	0<br />md5:	c6326e23c323ef69d73670243bb87de1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c6326e23c323ef69d73670243bb87de1<br />vt_score:	29/44 (65.9%)<br />scanner:	avira<br />virusname:	HTML/IFrame.Inje.1<br />url:	http://societyofalgorithm.org/publicationconversation/<br />recent:	up<br />response:	alive<br />ip:	79.99.203.25<br />as:	AS44312<br />review:	79.99.203.25<br />domain:	societyofalgorithm.org<br />country:	BE<br />source:	RIPE<br />email:	support@all2all.org<br />inetnum:	79.99.202.0 - 79.99.203.255<br />netname:	ALL2ALL-MOVING-ART-STUDIO-POP2-DEDICATED-SERVERS<br />descr:	Moving Art Studio ASBL ALL2ALL, The Independent Network, Range Dedicated ServersBE-ALL2ALL.ORG-20080104<br />ns1:	dns3.all2all.org<br />ns2:	dns1.okno.be<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://silberporsche.de/images/63/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522943</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522943</guid>
			<pubDate>2012-11-03T18:49:57+01:00</pubDate>
			<description><![CDATA[id:	2522943<br />first:	1351964997<br />last:	0<br />md5:	b84cab237d1317465ab29a2a6f7562c0<br />virustotal:	<br />vt_score:	2/46 (4.3%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://silberporsche.de/images/63/index.html<br />recent:	up<br />response:	alive<br />ip:	62.75.193.203<br />as:	AS8972<br />review:	109.237.138.22<br />domain:	silberporsche.de<br />country:	DE<br />source:	RIPE<br />email:	hostmaster@alfahosting.de<br />inetnum:	62.75.192.0 - 62.75.193.255<br />netname:	ALFAHOSTING-NET<br />descr:	Alfahosting GmbHAlfahosting GmbH<br />ns1:	ns2.goracer.de<br />ns2:	ns1.goracer.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sbk.wap.vn/java/k3conline]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522865</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JAVA/SMSSend.CS]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522865</guid>
			<pubDate>2012-11-03T18:00:00+01:00</pubDate>
			<description><![CDATA[id:	2522865<br />first:	1351962000<br />last:	0<br />md5:	c7a068e3f9877135701af711cdbeedc1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c7a068e3f9877135701af711cdbeedc1<br />vt_score:	10/36 (27.8%)<br />scanner:	avira<br />virusname:	JAVA/SMSSend.CS<br />url:	http://sbk.wap.vn/java/k3conline<br />recent:	up<br />response:	alive<br />ip:	123.30.174.21<br />as:	AS7643<br />review:	123.30.187.21<br />domain:	wap.vn<br />country:	vn<br />source:	APNIC<br />email:	abuse@vnn.vn<br />inetnum:	123.30.0.0 - 123.31.255.255<br />netname:	VDC-NET<br />descr:	VietNam Data Communication Company (VDC)VietNam Post and Telecom Corporation (VNPT)VNPT-AS-AP<br />ns1:	ns2.inet.vn<br />ns2:	ns1.inet.vn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://peak.edu.np/willow.html?pso=oven]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522820</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.UC]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522820</guid>
			<pubDate>2012-11-03T17:10:32+01:00</pubDate>
			<description><![CDATA[id:	2522820<br />first:	1351959032<br />last:	0<br />md5:	7589b2b773b1b629754035843bdc7a3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7589b2b773b1b629754035843bdc7a3b<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	JS/iFrame.UC<br />url:	http://peak.edu.np/willow.html?pso=oven<br />recent:	up<br />response:	alive<br />ip:	72.29.65.177<br />as:	AS33182<br />review:	72.29.65.177<br />domain:	peak.edu.np<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	72.29.64.0 - 72.29.95.255<br />netname:	HOSTDIME-PI-1<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns2.webhostingdharan.com<br />ns2:	ns1.webhostingdharan.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://opmeeractueel.nl/luchtfotos/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522819</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML:Iframe-LX Trj]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522819</guid>
			<pubDate>2012-11-03T17:10:32+01:00</pubDate>
			<description><![CDATA[id:	2522819<br />first:	1351959032<br />last:	0<br />md5:	be8b6db2be62854f0ec24fe7027c239e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be8b6db2be62854f0ec24fe7027c239e<br />vt_score:	13/36 (36.1%)<br />scanner:	Avast<br />virusname:	HTML:Iframe-LX Trj<br />url:	http://opmeeractueel.nl/luchtfotos/index.html<br />recent:	up<br />response:	alive<br />ip:	83.96.159.51<br />as:	AS21155<br />review:	83.96.159.51<br />domain:	opmeeractueel.nl<br />country:	NL<br />source:	RIPE<br />email:	abuse@proserve.nl<br />inetnum:	83.96.159.0 - 83.96.159.127<br />netname:	NL-CUST-PROSERVE-ID-462<br />descr:	ProServe Customer ID 462<br />ns1:	ns1.webawere.nl<br />ns2:	ns2.webawere.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ofertaeprocura.pt/gorum/js/jquery/jquery.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522817</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.aai.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522817</guid>
			<pubDate>2012-11-03T17:10:32+01:00</pubDate>
			<description><![CDATA[id:	2522817<br />first:	1351959032<br />last:	0<br />md5:	2f707d60838815edabe31a749ef6ff40<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fa6fac9b45815a48585687970ae3ebbb<br />vt_score:	15/40 (37.5%)<br />scanner:	avira<br />virusname:	JS/iFrame.aai.1<br />url:	http://ofertaeprocura.pt/gorum/js/jquery/jquery.js<br />recent:	up<br />response:	alive<br />ip:	80.172.241.16<br />as:	AS5533<br />review:	80.172.241.16<br />domain:	ofertaeprocura.pt<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	80.172.240.0 - 80.172.241.255<br />netname:	ESOTERICA<br />descr:	Claranet's customer<br />ns1:	ns2.esoterica.com<br />ns2:	ns1.esoterica.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://liushi.com.cn/qyxf/mt.asp]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522801</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.EPI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522801</guid>
			<pubDate>2012-11-03T16:59:58+01:00</pubDate>
			<description><![CDATA[id:	2522801<br />first:	1351958398<br />last:	0<br />md5:	634c713c3dccd3487d2599f286d44ae9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=634c713c3dccd3487d2599f286d44ae9<br />vt_score:	14/44 (31.8%)<br />scanner:	avira<br />virusname:	JS/Agent.EPI<br />url:	http://liushi.com.cn/qyxf/mt.asp<br />recent:	up<br />response:	alive<br />ip:	222.76.126.50<br />as:	AS4134<br />review:	222.76.126.50<br />domain:	liushi.com.cn<br />country:	CN<br />source:	APNIC<br />email:	anti-spam@ns.chinanet.cn.net<br />inetnum:	222.76.0.0 - 222.79.255.255<br />netname:	CHINANET-FJ<br />descr:	CHINANET fujian province networkChina TelecomNo1,jin-rong StreetBeijing 100032<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://linkehumanisten-neuss.gmxhome.de/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522800</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Twetti.S]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522800</guid>
			<pubDate>2012-11-03T16:59:58+01:00</pubDate>
			<description><![CDATA[id:	2522800<br />first:	1351958398<br />last:	0<br />md5:	dde1282cd2ef7402818bb8ff938f0271<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=40ef18baafb6a0f623e95cad6fa767e5<br />vt_score:	21/44 (47.7%)<br />scanner:	avira<br />virusname:	JS/Twetti.S<br />url:	http://linkehumanisten-neuss.gmxhome.de/<br />recent:	up<br />response:	alive<br />ip:	82.165.50.17<br />as:	AS8560<br />review:	82.165.50.17<br />domain:	gmxhome.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.48.0 - 82.165.63.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns9.schlund.de<br />ns2:	ns10.schlund.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kenar.pl/kontakt.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522704</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Expack.SN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522704</guid>
			<pubDate>2012-11-03T16:19:58+01:00</pubDate>
			<description><![CDATA[id:	2522704<br />first:	1351955998<br />last:	0<br />md5:	e4405c2d3bbdd217c2c220ed7eda9e70<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e4405c2d3bbdd217c2c220ed7eda9e70<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	JS/Expack.SN<br />url:	http://kenar.pl/kontakt.html<br />recent:	up<br />response:	alive<br />ip:	89.161.217.191<br />as:	AS12824<br />review:	89.161.217.191<br />domain:	kenar.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	89.161.192.0 - 89.161.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns3.home.pl<br />ns2:	dns.home.pl<br />ns3:	dns2.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kacbetekom.be/uitslagen/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522703</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522703</guid>
			<pubDate>2012-11-03T16:19:58+01:00</pubDate>
			<description><![CDATA[id:	2522703<br />first:	1351955998<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://kacbetekom.be/uitslagen/index.html<br />recent:	up<br />response:	alive<br />ip:	193.109.189.100<br />as:	AS29587<br />review:	undef<br />domain:	kacbetekom.be<br />country:	BE<br />source:	ARIN<br />email:	ops@schedom.be<br />inetnum:	193.109.184.0 - 193.109.191.255<br />netname:	SCHEDOM-EUR<br />descr:	schedom vofschedom-europe.net european ip range<br />ns1:	ns2.schedom-europe.net<br />ns2:	ns6.schedom-europe.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p186p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522702</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522702</guid>
			<pubDate>2012-11-03T16:19:58+01:00</pubDate>
			<description><![CDATA[id:	2522702<br />first:	1351955998<br />last:	0<br />md5:	ab18ee91de4abdd911f725d39bb8cde3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ab18ee91de4abdd911f725d39bb8cde3<br />vt_score:	20/30 (66.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p186p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jong1025.com.ne.kr/html/sbr32/p120p.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522701</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/Agent.abx.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522701</guid>
			<pubDate>2012-11-03T16:19:57+01:00</pubDate>
			<description><![CDATA[id:	2522701<br />first:	1351955997<br />last:	0<br />md5:	9273ba210bf709982c3dc1d46f4da033<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9273ba210bf709982c3dc1d46f4da033<br />vt_score:	20/30 (66.7%)<br />scanner:	avira<br />virusname:	JS/Agent.abx.2<br />url:	http://jong1025.com.ne.kr/html/sbr32/p120p.html<br />recent:	up<br />response:	alive<br />ip:	211.119.245.183<br />as:	AS3786<br />review:	211.119.245.183<br />domain:	com.ne.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@bora.net<br />inetnum:	211.119.0.0 - 211.119.255.255<br />netname:	BORANET-NET-211-119<br />descr:	DACOM Corp.Facility-based Telecommunication Service Providerproviding Internet leased-ine, on-line service, BLL etc.<br />ns1:	a.ns.com.ne.kr<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://inet-tr.org.tr/inetconf7/inet-forum/]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522683</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522683</guid>
			<pubDate>2012-11-03T16:00:00+01:00</pubDate>
			<description><![CDATA[id:	2522683<br />first:	1351954800<br />last:	0<br />md5:	5f3b6c29936a412a8256fe0661e60c33<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5f3b6c29936a412a8256fe0661e60c33<br />vt_score:	22/27 (81.5%)<br />scanner:	avira<br />virusname:	HTML/Infected.WebPage.Gen2<br />url:	http://inet-tr.org.tr/inetconf7/inet-forum/<br />recent:	up<br />response:	alive<br />ip:	139.179.130.61<br />as:	AS8466<br />review:	139.179.130.61<br />domain:	inet-tr.org.tr<br />country:	TR<br />source:	RIPE<br />email:	cayfer@bilkent.edu.tr<br />inetnum:	139.179.0.0 - 139.179.255.255<br />netname:	TR-BILNET<br />descr:	Bilkent UniversityP.O. Box 806572 Maltepe, AnkaraBilkent UniversityBilkent, Ankara 06800TURKEYBilkent UniversityBilkent, Ankara 06800TURKEY<br />ns1:	akgul.bilkent.edu.tr<br />ns2:	arf.afl.org.tr<br />ns3:	admin.bilkent.edu.tr<br />ns4:	sinan.sfk.org.tr<br />ns5:	yuce.ubak.gov.tr<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ilducatodoro.it/home.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522682</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS:Iframe-BG [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522682</guid>
			<pubDate>2012-11-03T16:00:00+01:00</pubDate>
			<description><![CDATA[id:	2522682<br />first:	1351954800<br />last:	0<br />md5:	da32dad61a29ba0a7837c5f9dda8c9cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=da32dad61a29ba0a7837c5f9dda8c9cc<br />vt_score:	15/31 (48.4%)<br />scanner:	Avast<br />virusname:	JS:Iframe-BG [Trj]<br />url:	http://ilducatodoro.it/home.html<br />recent:	up<br />response:	alive<br />ip:	62.149.128.160<br />as:	AS31034<br />review:	62.149.128.154<br />domain:	ilducatodoro.it<br />country:	IT<br />source:	RIPE<br />email:	hostmaster@technorail.com<br />inetnum:	62.149.128.0 - 62.149.137.255<br />netname:	TECHNORAIL-NET<br />descr:	Technorail srlInternet Service and Access ProviderTechnorail S.r.l. - Aruba.it<br />ns1:	dns.technorail.com<br />ns2:	dns3.arubadns.net<br />ns3:	dns2.technorail.com<br />ns4:	dns4.arubadns.cz<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dolceterra.it/catalog/view/javascript/common.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522507</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.aai.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522507</guid>
			<pubDate>2012-11-03T14:29:58+01:00</pubDate>
			<description><![CDATA[id:	2522507<br />first:	1351949398<br />last:	0<br />md5:	2f960a218c1df6cf1aab715026959188<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f960a218c1df6cf1aab715026959188<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	JS/iFrame.aai.1<br />url:	http://dolceterra.it/catalog/view/javascript/common.js<br />recent:	up<br />response:	alive<br />ip:	66.71.139.116<br />as:	AS31034<br />review:	66.71.139.116<br />domain:	dolceterra.it<br />country:	US<br />source:	ARIN<br />email:	noc@9net.it<br />inetnum:	66.71.128.0 - 66.71.191.255<br />netname:	NETAPPSERV-1BLK<br />descr:	Network Application Services, Inc. NAS 1719 State Rt 10 Parsippany NJ 07054<br />ns1:	ns2.9netweb.it<br />ns2:	ns1.9netweb.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://controllogps.it/js/jquery-1.5.1.min.js]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522491</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Script.Packed-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522491</guid>
			<pubDate>2012-11-03T14:09:58+01:00</pubDate>
			<description><![CDATA[id:	2522491<br />first:	1351948198<br />last:	0<br />md5:	46e00e63fe45c4bc8301cea5c324bb89<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=46e00e63fe45c4bc8301cea5c324bb89<br />vt_score:	10/36 (27.8%)<br />scanner:	clamav<br />virusname:	PUA.Script.Packed-2<br />url:	http://controllogps.it/js/jquery-1.5.1.min.js<br />recent:	up<br />response:	alive<br />ip:	193.254.240.136<br />as:	AS31034<br />review:	193.254.240.136<br />domain:	controllogps.it<br />country:	IT<br />source:	RIPE<br />email:	omero.narducci@widestore.net<br />inetnum:	193.254.240.0 - 193.254.241.255<br />netname:	WIDESTORE-IT-01<br />descr:	Widestore s.r.l.Widestore s.r.l.<br />ns1:	ns2.cassiopea.it<br />ns2:	ns.cassiopea.it<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ckq.edu.vn/uploads/kt-tc/2012_10/cd-k4_5.xls]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522490</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.FN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522490</guid>
			<pubDate>2012-11-03T14:09:58+01:00</pubDate>
			<description><![CDATA[id:	2522490<br />first:	1351948198<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a488adbfc5481fce369e9db9ce88b985<br />vt_score:	36/41 (87.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.FN<br />url:	http://ckq.edu.vn/uploads/kt-tc/2012_10/cd-k4_5.xls<br />recent:	up<br />response:	alive<br />ip:	112.78.2.131<br />as:	AS45538<br />review:	112.78.2.131<br />domain:	ckq.edu.vn<br />country:	VN<br />source:	APNIC<br />email:	vanht@ods.vn<br />inetnum:	112.78.0.0 - 112.78.15.255<br />netname:	ODS-VNNIC-VN<br />descr:	Cong ty Co phan Dich vu du lieu Truc tuyenOnline data services JSC123 Truong Dinh, dist 3, HCMC<br />ns1:	ns1.matbao.vn<br />ns2:	ns2.matbao.vn<br />ns3:	ns-bak.matbao.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://a-k-s.de/seiten/aks_de.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522417</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/iFrame.yor]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522417</guid>
			<pubDate>2012-11-03T13:19:57+01:00</pubDate>
			<description><![CDATA[id:	2522417<br />first:	1351945197<br />last:	0<br />md5:	0b39e55bbaaa45c4c5827160d88b36ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0b39e55bbaaa45c4c5827160d88b36ef<br />vt_score:	16/35 (45.7%)<br />scanner:	avira<br />virusname:	JS/iFrame.yor<br />url:	http://a-k-s.de/seiten/aks_de.htm<br />recent:	up<br />response:	alive<br />ip:	80.237.132.213<br />as:	AS20773<br />review:	80.237.132.213<br />domain:	a-k-s.de<br />country:	DE<br />source:	RIPE<br />email:	net-abuse@hosteurope.de<br />inetnum:	80.237.132.128 - 80.237.132.255<br />netname:	HE-SH-CGN-NET<br />descr:	Hosteurope GmbHkoeln@hosteurope.de<br />ns1:	c1.wpns.hosteurope.de<br />ns2:	c1.wsns.hosteurope.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://voh.com.vn/default.htm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2522364</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2522364</guid>
			<pubDate>2012-11-03T12:40:33+01:00</pubDate>
			<description><![CDATA[id:	2522364<br />first:	1351942833<br />last:	0<br />md5:	470c6a06f7ea88055d363ef5b863605b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=046891bf415c4af517e3fa0b7995bf43<br />vt_score:	12/36 (33.3%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://voh.com.vn/default.htm<br />recent:	up<br />response:	alive<br />ip:	221.132.39.177<br />as:	AS7643<br />review:	221.132.39.177<br />domain:	voh.com.vn<br />country:	vn<br />source:	APNIC<br />email:	giangdo@hcmpt.com.vn<br />inetnum:	221.132.16.0 - 221.132.39.255<br />netname:	HCMPT-NET<br />descr:	Ho Chi Minh City Post and Telecom CompanyVietNam Post and Telecom Corporation (VNPT)VNPT-AS-AP<br />ns1:	dns2.netsoft.com.vn<br />ns2:	dns1.netsoft.com.vn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zs-dolha.drelow.pl/grafika/akcja/index.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2517981</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[HTML/Infected.WebPage.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2517981</guid>
			<pubDate>2012-11-02T18:40:08+01:00</pubDate>
			<description><![CDATA[id:	2517981<br />first:	1351878008<br />last:	0<br />md5:	6b3148ce7755b5b8a03148e0a7af919f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6b3148ce7755b5b8a03148e0a7af919f<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	HTML/Infe