IFrames,RealPlayer exploit...
hxxp://8v8.biz/
One more RealPlayer,and an.ani exploit also afterwards...
hxxp://s.222360.com/6.gif
hxxp://s.222360.com/ads.c
And the result...
hxxp://ads.adslooks.info/ads/ads.exe
And a couple of unsorted ones...
hxxp://www.333292.com/cb.js
hxxp://www.w3c-org.com/w3.exe
hxxp://rising.w3c-org.com/re.exe
This last one informs his 'friend' here...
hxxp://rebot1.whatthisdown.com/post.asp