Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 31 March 2008

Don't Be A Fool! Don't Click on New Storm Email!

Posted on 12:36 by Unknown
The Storm Worm is at it again, spamming Holiday related spam to infect our machines.

Beginning around noon on March 31st, UAB's Spam Data Mine began receiving email containing a familiar pattern - a holiday related subject line, with an IP number as the URL to a website the spammer wished us to visit.

Subject lines we've seen so far include:


  • All Fools' Day
  • Gotcha! April Fool!
  • Happy April Fool's Day.
  • I am a Fool for your Love
  • Surprise! The joke's on you.
  • Today's Joke!
  • Wise Men Have Learned More from Fools...

The email bodies are just a single phrase followed by a link to a malware website:


  • All Fools' Day (link)
  • Doh! All's Fool. (link)
  • Happy April Fool's Day. (link)
  • Happy April Fools! (link)
  • I am a Fool for your Love (link)
  • Join the Laugh-A-Lot! (link)
  • Surprise! The joke's on you. (link)
  • Gotcha! April Fool!
  • Happy April Fool's Day.


Some of the spammed servers are actually still hosting a previous version of the malware, called "e-card.exe", which has been detected since March 11th. (Although there are still 13 AV companies, according to "VirusTotal.com", including Symantec, which do not detect this old version as a virus.

While some of the servers are offering an old "e-card.exe" version, most have changed to look like this:



The new executable names are "foolsday.exe" and "kickme.exe". Both are the same file, which as of this writing is 139,776 bytes in size, and has an MD5 value of:

7bc0344370ce5e6dd6e1a99e8ce347e0

I was the first to upload the new version of the virus to VirusTotal (or at least it did not say "this file has previously been analyzed", as it does when you are not the first.) At this time, coverage is very spotty. For instance, AVG, ClamAV, F-Prot, McAfee, Microsoft, NOD32, Panda, Symantec, and Sophos all say "No virus found". In fact, of the 32 antivirus products checked by VirusTotal, only 5 named this as a virus, and three of those based this on the fact that it was a "Packed Executable".

UAB researchers have found the same "FoolsDay" version of the malware on more than a dozen servers so far, and, as is usual for storm, most of these are cable modem attached PCs belonging to Americans. Sites in cities like Los Angeles, Miami were prevalent, while we did see one site in Russia (79.164.169.26), and one in Turkey (78.166.30.169) so far.

What happened to Easter?

Several people in the AV community have been wondering, "What happened to Easter?" One theory is that our criminals are Christian on some level and decided not to use the resurrection of Christ to spread viruses. The other theory (which I prefer) is that Russian Orthodox Easter isn't until April 14th, and the virus writers got caught sleeping, not remembering that we in the West don't celebrate Easter when they do.
Read More
Posted in | No comments

Tuesday, 25 March 2008

Phishers Seek Google Adword Accounts

Posted on 04:12 by Unknown
In recent months we have seen occasions where Advertisements placed with Google have actually pointed consumers to sites which would attempt to infect their computers with various forms of malware. A new Phishing Campaign discovered in the UAB Spam Data Mine may indicate this form of attack is about to get a lot worse.

Google has been very quick to identify and terminate the accounts of these malware advertisers, but what will their response be when long-time "known good" advertisers suddenly start having malware pop up in their ads?

This seems to be the focus of a new phishing campaign.

The email which comes from:

adwords-noreply@google.com

Looks like this:




Dear Google AdWords Customer!


In order to update your billing information, please sign in
to your AdWords account at https://adwords.google.com, and submit your
billing information. Your account will be reactivated as soon as you have
entered your payment details. Your ads will show immediately if you
decide to pay for clicks via credit or debit card. If you decide to pay
by direct debit, we may need to receive your signed debit authorization
before your ads start running, depending on your location. If you
choose bank transfer, your ads will show as soon as we receive your
first payment. (Payment options vary by location.)

Thank you for choosing AdWords. We look forward to providing you with
the most effective advertising available.

Sincerely,

The Google AdWords Team




The problem is that the Adwords link doesn't go to Google. In a review of fifty samples of the email collected from the UAB Spam Data Mine, fifteen counterfeit "Google AdWords" websites were identified:

http://adwords.google.com.049jfm.cn/select/Login/

http://adwords.google.com.0k8ujd.cn/select/Login/

http://adwords.google.com.adwordsgl.cn/select/Login/

http://adwords.google.com.fgreo3.cn/select/Login/

http://adwords.google.com.fnjdk.cn/select/Login/

http://adwords.google.com.fr4ck.cn/select/Login/

http://adwords.google.com.fri23.cn/select/Login/

http://adwords.google.com.fruwa0b.cn/select/Login/

http://adwords.google.com.googadw.cn/select/Login/

http://adwords.google.com.irf12.cn/select/Login/

http://adwords.google.com.kdje332.cn/select/Login/

http://adwords.google.com.ork0r.cn/select/Login/

http://adwords.google.com.r4oik.cn/select/Login/

http://adwords.google.com.session932.cn/select/Login/

http://adwords.google.com.treoo.cn/select/Login/


In what is now becoming a familiar pattern, criminals are using previous crimes to enable future crimes. In the current example of the Google Adwords phishing spam, although the "From" addresses say the email came from Google, the rest of the header makes it clear that these emails were sent from logged in Yahoo and Hotmail accounts.

Whether these accounts were created as throw away accounts for this spam campaign, or are actually accounts which were broken into and used without their owners' permission is still being investigated. The lists of yahoo and hotmail accounts have been shared with investigators, and those, as well as the counterfeit website lists, have been sent to the FBI's Digital PhishNet for further investigation.




(screen shot of http://adwords.google.com.adwordsgl.cn/select/Login/ - 24MAR08 0630AM CST)

Emails were received from Brazil, Germany, India, the Netherlands, Russia, Spain, Switzerland, Turkey, Uruguay, but also from California, Florida, Georgia, Indiana, and Massachusetts.



The UAB Spam Data Mine is operated by UAB Computer Forensics Research, a Joint Operation of the Department of Computer & Information Sciences and the Department of Justice Sciences at The University of Alabama at Birmingham.
Read More
Posted in phishing | No comments

Thursday, 28 February 2008

Smiling Bob Forfeits $33 Million

Posted on 15:11 by Unknown
Back in 2002, USA Today had a story about Smiling Bob, the first penis enlargement program to have television advertisements. A snip from that article:


The folks who market Enzyte offer up their "Independent Customer Study," which involved mailing a questionnaire with the product to 70 men.

According to a company brochure, the most-improved volunteers reported that the length and circumference of their erect penis increased a total of four inches.

"It makes no sense medically," counters Dallas urologist Kenneth Goldberg. There's no way that increasing blood flow to the penis, as Enzyte claims to do, will actually increase its size, he says.


Well, Dr. Goldberg was proved right this week in a Cincinnati court room.

Steven Warshak is the president and owner of Berkeley Premium Nutraceuticals, the makers of "Enzyte" which you might have seen advertised by "Smiling Bob" if you watch Spike TV. It turns out that the product was sold through advertising that included fake "size increase" testimonials, fake customer satisfaction ratings, and fictitious doctors.

The jury also found that it was a common business practice to bill customers who asked for a free-trial, and to refuse to honor money-back guarantees.

The US Postal Inspection Service, the FBI's Cincinnati Field Office, the IRS, and the FDA all provided evidence in the jury trial today in the Southern District of Ohio.

Warshak was convicted of 5 counts of conspiracy to commit money laundering and various types of fraud, conspiracy to obstruct proceedings before the US Federal Trade Commission, 12 counts of mail fraud, three counts of bank fraud, and 73 counts of money laundering.

His mother, Harriet Warshak, aged 75, got 8 counts of conspiracy, bank fraud and money laundering.

His lawyer, Paul Kellogg, aged 41, was convicted of 6 counts of conspiracy including conspiracy to obstruct proceedings before the FDA and FTC, and money laundering.

Steven Pugh, a warehouse manager for Warshak, got 1 count of conspiracy to obstruct proceedings before the FDA.

TCI Media and Berkeley Premium Nutraceuticals were also charged.

The most exciting news is that the jury also found for forfeiture of $33,190,000 worth of assets, including real estate, bank accounts, cars, and insurance policies.

Although Warshak was indicted back on September 21, 2006, the trial just concluded today.

I know I saw Smiling Bob ads as recently as two weeks ago. I'll have to watch Spike TV tonight and see if they are still airing.

The FBI Press Release on the jury's verdict was released on February 26th.
Read More
Posted in | No comments

Wednesday, 16 January 2008

Storm Loves You!

Posted on 21:37 by Unknown
The Storm Worm (yes, I know its not a worm, but that's what its called!) has mutated once again and is back in the full swing of "SP" mode, or "Storm Propagation" mode.

Beginning around 3 AM on January 15th, we started seeing new spam messages attempting to infect people with the Storm malware by tricking them into viewing a dangerous website.

Not sure if this is a COMPLETE list of subjects and bodies, but I'm seeing quite a few of them. I'm guessing you can mix and match some of the nouns and adjectives in the subjects below. I'm also guessing that the subjects and bodies may be interchangable.

The big news is that the URLs are no longer using Fast Flux domain names, which means that the Storm folks have to go back to using IP addresses as URLs.

Here are some of the Subjects used by the current storm campaign.

A Is For Attitude
A Kiss So Gentle
A Rose for My Love
A Toast My Love
A Token of My Love
Come Dance with Me
Come Relax with Me
Destiny
Eternity of Your Love
Hugging My Pillow
I am Complete
I Love Thee
I Love You Soo Much
In Your Arms
Inside My Heart
Last Night
Love Remains
Magic Power of Love
Miracle of Love
Our Journey
Our Love is Free
Pages from My Heart
Sending You All My Love
Sent with Love
The Mood for Love
When Love Comes Knocking
When You Fall in Love
You... In My Dreams
You're my Dream
You're the One
Your Love has Opened


Bodies:

A Is For Attitude (URL)
A Dream is a Wish (URL)
A Toast My Love (URL)
Come Dance with Me (URL)
Eternity of Your Love (URL)
Hugging My Pillow (URL)
If Loving You (URL)
I Love Thee (URL)
I Love You Soo Much (URL)
Inside My Heart (URL)
Last Night (URL)
Our Journey (URL)
Our Love is Strong (URL)
Our Love Nest (URL)
Sending You All My Love (URL)
Sent with Love (URL)
Miracle of Love (URL)
Path We Share (URL)
The Miracle of Love (URL)
The Mood for Love (URL)
The Moon & Stars (URL)
Words in my Heart (URL)
You're In My Thoughts (URL)
Wrapped in Your Arms (URL)
You're In My Thoughts (URL)

A few IPs I've got spam for:

24.13.25.195
24.29.57.5
24.98.163.49
24.147.84.166
24.158.201.51
24.182.164.166
58.8.154.229
59.93.124.61
61.254.150.135
62.30.214.249
64.130.186.121
64.131.210.85
65.127.69.227
65.189.144.143
66.56.162.236
66.65.246.186
67.170.38.85
68.52.93.226
68.91.149.33
69.153.229.224
69.236.21.121
70.119.36.227
70.237.140.25
70.237.219.11
70.251.159.54
71.224.194.223
71.228.87.148
75.18.129.8
75.46.65.147
75.74.12.93
75.132.167.64
75.176.123.128
75.181.155.252
76.86.247.98
76.87.138.125
76.108.103.196
76.211.9.128
76.223.80.123
76.117.96.98
76.255.55.200
77.244.67.25
79.120.46.50
79.176.169.98
116.126.30.18
125.184.241.30
190.47.48.223
190.50.109.86
190.172.254.93
200.8.248.51
200.126.102.5
201.223.179.88
208.38.67.197
218.238.54.74
218.190.195.185
220.77.192.117
220.79.184.205

--

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham
Read More
Posted in | No comments

Friday, 11 January 2008

New IRS Virus page taxes users

Posted on 20:27 by Unknown
A phishing site hosts fraudulent bank pages, and an IRS look-alike virus

A new round of spam, first noticed on January 8th, has been observed by anti-phishing researchers at the University of Alabama at Birmingham. In many ways the spam is typical phishing emails, trying to trick users into visiting a fraudulent website. This family of emails uses the domains listed below to host several different phishing campaigns, each in a different subdirectory. For example:

/_mem_bin/formslogin.asp = Intelligent Finance
/default.aspx = NatWest Bank
/confirm.asp = Royal Bank of Scotland

But in addition to the traditional phishing, or bank fraud websites, which try to steal userids and passwords for online banking accounts, this spam campaign also includes a fake Internal Revenue Service website - and it isn't asking for your password!

/importantpubs/index.htm = Internal Revenue Service

After giving a warning to "Business/Corporate Treasury Managers and Accountants", the fraudulent IRS website claims to have "important recent changes to business and corporate tax laws".




Each of the links which claim to be a new document with important tax information actually is a link to a virus! With file names like:

ALL_TAXPAYERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
ESTATE_AND_TRUST_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXCISE_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXEMPT_ORG_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
FOREIGN_ISSUES_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
INDIVIDUALS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
IRA_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE

the virus attempts to trick users into opening the file. If successful, the user will think he is getting information to share his taxes with the IRS, but actually the user will begin to share their information with criminals instead!

Some of the domains hosting this virus so far:

New Sites
jan77.net
aut33.com
pid28.com
com61.net
inf32.net
sid24.net
chcpi.com
chk08.net
dll57.com
idp56.us
user94.net
Older sites
ssl--jan08.com
ssl--site.com
ssl-jan08site.com
url-sslsite.com
update-ssl.com
url-ssl.com
confirm--07jan.com
6jan-update.in
securesafesite.net
myupdatesite.net
comssl.net
secure--confirm.net
06jan--confirm.net
7jan--verify.net

REMEMBER! The IRS is not going to send you an email to warn you about new documents or ask you to login. Several major anti-virus products do not yet detect this virus! Be safe! Do not click on links sent to you in email. If you need new tax documents, visit the real website at: http://www.irs.gov/.



As we have seen in so much recent malware, the websites are being rotated to include hosting on many servers. Here are the sites which are serving the malware according to our most recent query, but there may be many many more.


83.9.136.40 - Warsaw, Poland
77.253.113.235 - Warsaw, Poland
24.93.127.106 - Columbus, Ohio
69.201.136.16 - New York, New York
128.118.145.125 - Penn State University
87.209.100.8 - Amsterdam, the Netherlands
144.162.93.16 - Dallas County Community College
80.85.229.201 - Tarnow, Poland

_-_
gary warner
http://www.cis.uab.edu/forensics/

Read More
Posted in | No comments

Thursday, 3 January 2008

Ralsky: Going Down

Posted on 15:17 by Unknown
***IMPORTANT UPDATE*** January 11, 2008!
Today Alan Ralsky was taken into custody - arrested after arriving from Germany and taken into custody.
**********************

Congratulations to First Assistant US Attorney Terrence Berg and his colleagues in Detroit for being willing to prosecute one of the top spammers, as revealed in a 41-count indictment unveiled today in Detroit!

According to the January 3, 2008 announcement by the US Department of Justice today, Scott Bradley and Judy Devenow were in court after being arrested today to hear the charges. John Hui was arrested in New York on January 2nd. The other defendants are at large and being sought. (Hint: You might check the Dominican Republic? Oh wait. Wrong spammer. That was Rizler.)

The full list of defendents is given below:

Alan M. Ralsky, 52, of West Bloomfield, Michigan

Scott K. Bradley, 46, of West Bloomfield, Michigan

Judy M. Devenow, 55, of Lansing, Michigan

John S. Bown, 47, of Poway, California

William C. Neil, 45, of Fresno, California

Anki K. Neil, 36, of Fresno, California

James E. Bragg, 39, of Queen Creek, Arizona

James E. Fite, 34, of Whittier, California

Peter Severa, age unknown, of Russia

How Wai John Hui, 49, of Vancouver, Canada and Hong Kong

Francis A. Tribble, of Los Angeles, California

Ralsky, who has his own Wikipedia page became one of the most famous spammers after an interview with the Detroit News in 2002. Pictures of his ill-gotten mansion are available at Archive.org.

The FBI raided Ralsky's home in 2005, and apparently today's indictments are the conclusion of that investigation, which DOJ says is now three years old!

While a total pricetag may never be placed on all of Ralsky's illegal profits, DOJ says he earned $3 Million just in the summer of 2005!

Ralsky has long been on the excellent Spamhaus Registry of Known Spam Offenders and was featured in the book "Spam Kings". Brian McWilliams, the author of Spam Kings, called Ralsky "the most successful spammer" in this Tech Soup Interview in 2004. Partly because he was still in business after the successful 2001 Verizon lawsuit against him. Three years later and he's still spamming!

Joel Kurth did an excellent profile on Ralsky in August of 2002 for the Detroit News, where Ralsky admits to maintaining a 150 million email address mailing list (though he points out there were 87 million email addresses that he does NOT send spam to because they unsubscribed.)

I wonder how many millions more people he's offended since 2002?

Congratulations again, Detroit, CCIPS, and thanks to the FBI, Postal Inspectors, and IRS Agents who assisted in bringing this to indictment.

Now if they can just get the other 8 co-defendants into custody . . .
Read More
Posted in | No comments

Wednesday, 2 January 2008

And on January 1st EVERYBODY SPAM!

Posted on 04:43 by Unknown
Its been a while since I've looked at a virus with a date-triggered behavior change, but that seems to be the case with the one I'm currently looking into.

I spent most of the day yesterday playing with a new spamming virus which "triggered" on January 1st to begin spamming "VPXL" male organ enlargement pills, after being dormant on a machine for almost two weeks.

I would very much appreciate any reports (which will be kept anonymous) regarding how wide-spread this virus may be, or whether anyone can identify the original point of infection.

This is currently the most widely spread spam campaign being observed by our Spam Data Mine at UAB. Its the same group that has been previously using the brands "King Replica" for counterfeit watches and "EliteHerbal" for pills.

The machine I was studying became infected on December 17th, after a "drive-by infection" sent it to the website "www.injectpanel.com" where it hit a file called "/us/ret.php", which caused it to download "index[1].exe". (We are working to get this site shutdown already).

Infected machines will be easily identified (now that Jan 1 has passed), by an enormous number of outbound SMTP connections.

Infected machines will probably have a large number of files in their root directory ending in ".tmp". Some of these files may be 42,496 bytes in size, which are copies of the .exe, while others will be 0 bytes in size.

Infected machines ARE rootkitted, with a couple files of true interest:
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\video.dll

(I found these with "RootKit Revealer", a Most Useful Tool!)

Infected machines will contact on each boot "www.injectpanel.com", and may also connect on each boot "www.botsys.net".

AV vendor PREVX had received 11 copies of this virus since December 18th, most commonly called "index[1].exe".

VirusTotal received its first copy on December 30th, and had a 43% detection. It was NOT detected by ClamAV, F-Prot, McAfee, NOD, Sunbelt, or Symantec. As of Jan 1, it showed 53% detection. (17 of 32 AV products could detect the virus.)

The copy I was dealing with had the MD5:

b7f085411871026218cc30b4a6c0363e

Other secondary infections have been seen being "dropped" from injectpanel.com. Including "Nurech" (AKA "Chepvil"), which also showed only a 13 of 32 detection rate on Jan 1.

Nurech places a large number of files in the Windows\System32 directory.
Some example names were:
imapi.exe
mnmsrvc.exe
msdtc.exe
netdde.exe
alg.exe.tmp
cisvc.exe.tmp

These will be copied to a "numbered" temp file, such as:

124671.exe
147359.exe

which can be found in memory and in the C:\Windows\Temp\ directory.

The file size of these files is "8,704".

MD5 for Nurech = 337915d40c893b64ef57fe3866dadb8f

If anyone else is experiencing these viruses, I'd love to learn any more details you might be able to share, but most importantly I'm trying to gage how widespread the infection is.

Windows XP Machines infected with Nurech may demonstrate the characteristic of "falling off" networks, getting stuck in an "acquiring network device" state. (Which may be an overwhelmed TCP stack from the many many copies of "svchost" that are trying to drive TCP connections.)

Thanks for any help!

Gary Warner
Director of Research in Computer Forensics
http://www.cis.uab.edu/forensics/
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile