Reference:
http://novirusthanks.org/blog/2009/11/blackhat-seo-used-to-spread-systemveteran-rogue-software/Some domains missing on mdl:
hxxp://get2.tv/ Serve False Codecs
hxxp://setxlif.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://szickfrost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://sickfrost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://szick-frost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://sick-frost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
get2.tv has always new urls for "codec"...