<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" href="/stylesheets/rss.xsl"?>
<rss version="2.0">
  <channel>
    <title>Site Reviews by bdmeyer</title>
    <description>Site Reviews by bdmeyer in the Norton Safe Web community</description>
    <pubDate>Tue May 22 14:53:12 +0000 2012</pubDate>
    <link>http://safeweb.norton.com/profile/bdmeyer</link>
    <item>
      <title>publicservicedegrees.com   :    Possible fake diploma mill..</title>
      <description>Spam offering low cost degree's in many fields. I would be very cautious in dealing with them.</description>
      <pubDate>Thu, 01 Apr 2010 12:53:26 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=publicservicedegrees.com</link>
    </item>
    <item>
      <title>teamzobbe.dk   :    Found referenced five times with a virus download</title>
      <description>Example (Obfuscated)
Visited: &amp;amp;lt;user&amp;gt;@http://174.57.186.216/d=www[dot]teamzobbe[dot]dk/0x3E8/view/console=yes/setup.exe</description>
      <pubDate>Thu, 25 Mar 2010 13:58:56 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=teamzobbe.dk</link>
    </item>
    <item>
      <title>muqo.com   :    Found in Suspicious Location </title>
      <description>While analyzing an infected hard drive for a new variant of torpig, I found muqo.com in a physical memory dump.
Info is below:

4 Hits in 3 Files - QUERY: (RealHardDisk) -- 1 Hit - [physmem.dmp_07]  cdavis_laptop\NONAME-NTFS\physmem.dmp_07
	NamedO F1AE348-21FE-4A3B \\.\&amp;amp;lt;&amp;amp;lt;realharddisk&amp;gt;&amp;gt; shutdown    {5F1AE348 Drivers\*.syst VERSION\RUN MUQO.COM AS.HTM MUQO.COM/AS/ run</description>
      <pubDate>Mon, 22 Mar 2010 20:23:22 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=muqo.com</link>
    </item>
    <item>
      <title>as.ro   :    Contained this domain in injected hal.dll</title>
      <description>This site is referenced inside a hal.dll from an infected machines memory capture.
ftp.as.ro
(Is it really hosted in us wit ha .ro ?)</description>
      <pubDate>Thu, 18 Mar 2010 16:01:51 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=as.ro</link>
    </item>
    <item>
      <title>y123.com   :    Found inside an ijected hal.dll</title>
      <description>This site is referenced inside a hal.dll from an infected machines memory capture.</description>
      <pubDate>Thu, 18 Mar 2010 15:58:32 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=y123.com</link>
    </item>
    <item>
      <title>buyftpservice.com   :    Found this on several machines</title>
      <description>Found reference to this url in what we believe is a new variant of a combination Torpig / Conficker (PigFicker ?) Memory capture from several analysed machines.

Bruce D. Meyer</description>
      <pubDate>Tue, 16 Mar 2010 14:02:34 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=buyftpservice.com</link>
    </item>
    <item>
      <title>slaphappy.com   :    Proxy Bypass</title>
      <description>This site claims to help users bypass security proxies. This would then make a machine possibly more open to compromise as it is now able to visit sites that you are attempting to block at your proxy.</description>
      <pubDate>Wed, 17 Feb 2010 18:04:55 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=slaphappy.com</link>
    </item>
    <item>
      <title>darelease.com   :    Possible warez site</title>
      <description>While searching for a pent testing tool, this site kept coming up with what appear to be downloads for purchased software for free. McAfee site advisor had one review that said software from here has viruses on it. I would rate it at least as suspcious until Safe Web completes it's testing. </description>
      <pubDate>Sat, 23 Jan 2010 18:38:09 +0000</pubDate>
      <link>http://safeweb.norton.com/report/show?url=darelease.com</link>
    </item>
  </channel>
</rss>

