12.01.09 -- Break FAST










-----------------







Tuesday, December 1, 2009







Puzzle by Jonah Kagan and Victor Fleming, edited by Will Shortz





BREAKFAST (56A. Part of a morning routine … or a literal hint to 18-, 22-, 35- and 49-Across), FAIRY DUST (18A. Golden egg layer of story), FALCON CREST (22A. 1980s soap opera set at a winery), FATHER KNOWS BEST (35A. Homecoming returnees, for short), FALL HARVEST (49A. Occasion for pumpkin picking) are the interrelated group of this Tuesday crossword.







Food and drink -- ALE (64A. Drink with a head), CARAFE (1D. Wine container) and CASKS (25D. Wine containers), DINED (63A. Ate in high style), ELBOW (9A. Macaroni shape), 61A. MOO goo gai pan, RUMS (27D. Jamaica exports), TIE ONE ON (37D. Get stewed).







People, animals, etc. -- ALEX (36D. The “A” in A-Rod); ALLEN (14A. Steve who was called Steverino); ALOMAR (2D. Six-time baseball All-Star Sandy); ALUMS (34A. Homecoming returnees, for short); AMIE (20A. French lady friend); ASNER (34D. Ed who played Lou Grant); 56D. George Thorogood stutter “B-B-B-B-BAD …”; GOOSE (16A. Golden egg layer of story); LLAMA (51D. Andean animal); ORCA (55A. Killer whale); RAS (19D. Univ. dorm supervisors); ROOST (17A. Rod in a henhouse); 41A. Alfred P. SLOAN Foundation.







Places -- BOUTIQUE (11D. Chic shop), CAIRO (1A. City near the Great Sphinx) and EGYPT (9D. 1-Across is its capital); EAST (28D. Atlantic Seaboard states, with “the”); ILO ILO (3D. Repetitively named Philippine province); NCAR (24D. Tenn. Neighbor); ONT (5D. Ottawa’s prov.).







Other -- ABOVE (60A. Not deigning to consider); AVERT (62A. Turn away); EROTICA (29A. Blue literature), ESCORT (46D. Front car in a motorcade); EVOLVE (44D. Change over time); E-ZINE (8D. Net mag); FAKED (49D. Not real); FLOOR (59A. Knock the socks off); ILIAD (40A. Tale of Troy); LASES (31A. Cuts with light); LYSOL (52D. “Disinfect to Protect” brand); NEARLY (53A. Almost); NESTS (65A. Fits one inside the next); OILED (23D. Like some smoothly running machines); RE-AIR (7D. Show again); RESECT (4D. Take out surgically); SOOTH (33D. Truth, old-style); STARTS (47D. Turns on, as a car); TWEEZES (43A. Plucks, as eyebrow hairs); ZEROES (45D. Homes in on).







Short stuff -- ALB, AQUA, ARF, EAVE, ENL, EXO, FAN, FEZ, FIRER, HAD, IRE, LODE (10A. Mine treasure) and ORE (6D.A. Mine treasure), OFF and OSS, REED, RBI, TOE, WAWA, WET.




For breaking up at breakfast, HERE.



------------------



For today’s cartoon, go to The Crossword Puzzle Illustrated.










Click on image to enlarge.







Puzzle available on the internet at












If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.









How to remove mvmgxe6.exe

mvmgxe6.exe
Files size 167,856 bytes
MD5: B7E098DD9D5C3B2FBA544AE98A7992ED
SHA-1: 406DC5AD586033FD2DDDF60522FF4ADED9CA8D95

bigdoor.exe
MD5: 0511E04FA25B80EDF2F0FDE5F1E34453
SHA-1:179DC277734AF05A465298AE2E705BD1F97B70E4
===============================================
Files created
%System%\bigdoor.exe
%System%\bigie0.dll (0-9)
%System%\bigmn0.dll (0-9)
X:\mvmgxe6.exe
X:\autorun.inf
(X:\= C:\ - Z:\)

Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\ProgID
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\Programmable
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}

Values Added
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\VersionIndependentProgID\
(Default) = "IEHlprObj.IEHlprObj"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\ProgID\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\InprocServer32\
(Default) = "%System%\bigmn0.dll"
ThreadingModel = "Apartment"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\TypeLib\
(Default) = "{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}"
Version = "1.0"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid32\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\
(Default) = "IIEHlprObj"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0\win32\
(Default) = "%System%\bigmn0.dll"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\HELPDIR\
(Default) = "%System%\"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\FLAGS\
(Default) = "0"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\
(Default) = "IEHelper 1.0 Type Library"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\
(Default) = "{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1]
(Default) = "IEHlprObj Class"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
bigsoft = "%System%\bigdoor.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091

URLs to be download / data identified
http://kjhncd.net/1hg/ah1.rar %Temp%\ah1.rar


=======================================================
วิธีกำจัด/แก้ virus : mvmgxe6.exe
=======================================================


How to remove mvmgxe6.exe

mvmgxe6.exe
Files size 167,856 bytes
MD5: B7E098DD9D5C3B2FBA544AE98A7992ED
SHA-1: 406DC5AD586033FD2DDDF60522FF4ADED9CA8D95

bigdoor.exe
MD5: 0511E04FA25B80EDF2F0FDE5F1E34453
SHA-1:179DC277734AF05A465298AE2E705BD1F97B70E4
===============================================
Files created
%System%\bigdoor.exe
%System%\bigie0.dll (0-9)
%System%\bigmn0.dll (0-9)
X:\mvmgxe6.exe
X:\autorun.inf
(X:\= C:\ - Z:\)

Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\ProgID
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\Programmable
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}

Values Added
HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\VersionIndependentProgID\
(Default) = "IEHlprObj.IEHlprObj"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\ProgID\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\InprocServer32\
(Default) = "%System%\bigmn0.dll"
ThreadingModel = "Apartment"

HKLM\SOFTWARE\Classes\CLSID\
{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\TypeLib\
(Default) = "{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}"
Version = "1.0"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid32\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\ProxyStubClsid\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\
{7F23592C-8F2C-4C08-83A8-BBE01BF9CC64}\
(Default) = "IIEHlprObj"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\0\win32\
(Default) = "%System%\bigmn0.dll"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\HELPDIR\
(Default) = "%System%\"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\FLAGS\
(Default) = "0"

HKLM\SOFTWARE\Classes\TypeLib\
{7F235922-8F2C-4C08-83A8-BBE01BF9CC64}\1.0\
(Default) = "IEHelper 1.0 Type Library"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\
(Default) = "{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1]
(Default) = "IEHlprObj Class"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
bigsoft = "%System%\bigdoor.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091

URLs to be download / data identified
http://kjhncd.net/1hg/ah1.rar %Temp%\ah1.rar


=======================================================
วิธีกำจัด/แก้ virus : mvmgxe6.exe
=======================================================


How to remove rg.exe

rg.exe , bigdoor.exe
Files size 175,346 bytes
MD5: CE9B6CFA4C6367BE9971DF4EB0D6842D
SHA-1: A5B35F1A5F511FE11AE870E3A33CA0F530DD0D57
=================================================
Files created
%System%\bigdoor.exe
%System%\bigie0.dll (0-9)
%System%\bigmn0.dll (0-9)
X:\rg.exe
X:\autorun.inf
(X:\ = C:\-Z:\)

Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}
HHKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ProgID
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\Programmable
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}

Values Added
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\VersionIndependentProgID\
(Default) = "IEHlprObj.IEHlprObj"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ProgID\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\InprocServer32\
(Default) = "%System%\bigmn0.dll"
ThreadingModel = "Apartment"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib\
(Default) = "{238C32A2-955D-4707-AAB9-C9B3AB8D4225}"
Version = "1.0"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid32\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\
(Default) = "IIEHlprObj"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0\win32\
(Default) = "%System%\bigmn0.dll"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\HELPDIR\
(Default) = "%System%\"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\FLAGS\
(Default) = "0"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\
(Default) = "IEHelper 1.0 Type Library"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\
(Default) = "{238C32AB-955D-4707-AAB9-C9B3AB8D4225}"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\
(Default) = "IEHlprObj Class"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
bigsoft = "%System%\bigdoor.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091

URLs to be download / data identified
http://kjhncd.net/1hg/ah1.rar > %Temp%\ah1.rar

=======================================================
วิธีกำจัด/แก้ virus : rg.exe ,bigdoor.exe
=======================================================



How to remove rg.exe

rg.exe , bigdoor.exe
Files size 175,346 bytes
MD5: CE9B6CFA4C6367BE9971DF4EB0D6842D
SHA-1: A5B35F1A5F511FE11AE870E3A33CA0F530DD0D57
=================================================
Files created
%System%\bigdoor.exe
%System%\bigie0.dll (0-9)
%System%\bigmn0.dll (0-9)
X:\rg.exe
X:\autorun.inf
(X:\ = C:\-Z:\)

Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}
HHKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ProgID
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\Programmable
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\
{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\
{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}

Values Added
HKLM\SOFTWARE\Classes\CLSID\
{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\VersionIndependentProgID\
(Default) = "IEHlprObj.IEHlprObj"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ProgID\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\InprocServer32\
(Default) = "%System%\bigmn0.dll"
ThreadingModel = "Apartment"

HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib\
(Default) = "{238C32A2-955D-4707-AAB9-C9B3AB8D4225}"
Version = "1.0"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid32\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid\
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKLM\SOFTWARE\Classes\Interface\{238C32AC-955D-4707-AAB9-C9B3AB8D4225}\
(Default) = "IIEHlprObj"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0\win32\
(Default) = "%System%\bigmn0.dll"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\HELPDIR\
(Default) = "%System%\"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\FLAGS\
(Default) = "0"

HKLM\SOFTWARE\Classes\TypeLib\{238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\
(Default) = "IEHelper 1.0 Type Library"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\
(Default) = "IEHlprObj.IEHlprObj.1"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\
(Default) = "IEHlprObj Class"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\
(Default) = "{238C32AB-955D-4707-AAB9-C9B3AB8D4225}"

HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\
(Default) = "IEHlprObj Class"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
bigsoft = "%System%\bigdoor.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091

URLs to be download / data identified
http://kjhncd.net/1hg/ah1.rar > %Temp%\ah1.rar

=======================================================
วิธีกำจัด/แก้ virus : rg.exe ,bigdoor.exe
=======================================================



AVDB-019 update

01/12/2009 New update !
PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-018
Add new virus singature database
=======================================================
10fnsh.exe
9npxi.bat
bigdoor.exe
hps.bat
inhm0.exe
isaecyu.exe
qw6vege.exe
rfv0x.exe
suqfl.exe
t0ecj8.exe
uyulb.exe
yf6qkh.exe
zoorfat.exe

winhlp.dll
bigie0.dll (0-9)
bigmn0.dll (0-9)
bitkv0.dll (0-9)
zorie0.dll (0-9)
zormn0.dll (0-9)

AVDB-019 update

01/12/2009 New update !
PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-018
Add new virus singature database
=======================================================
10fnsh.exe
9npxi.bat
bigdoor.exe
hps.bat
inhm0.exe
isaecyu.exe
qw6vege.exe
rfv0x.exe
suqfl.exe
t0ecj8.exe
uyulb.exe
yf6qkh.exe
zoorfat.exe

winhlp.dll
bigie0.dll (0-9)
bigmn0.dll (0-9)
bitkv0.dll (0-9)
zorie0.dll (0-9)
zormn0.dll (0-9)

AVDB-018 update

30/11/2009 New update ! (2) Time 19:40 น.
PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-018
Add new virus singature database
=======================================================
6ruaqx.exe
curqp.exe
lphfa.exe
q93fi6kf.exe
wu1n.exe
ahndoor0.dll (0-9)

AVDB-018 update

30/11/2009 New update ! (2) Time 19:40 น.
PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-018
Add new virus singature database
=======================================================
6ruaqx.exe
curqp.exe
lphfa.exe
q93fi6kf.exe
wu1n.exe
ahndoor0.dll (0-9)

AVDB-017 Update

30/11/2009 New update !

PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-017
=============================================
b9w9.exe
q3kku.exe
r8wb.bat
wfx062.exe
forxuan.dll

AVDB-017 Update

30/11/2009 New update !

PeeTechFix-win32/PSW.OnlineGame 2.0.5 AVDB-017
=============================================
b9w9.exe
q3kku.exe
r8wb.bat
wfx062.exe
forxuan.dll

11.30.09 -- TRAP






Monday, November 30, 2009



Puzzle by Oliver Hill, edited by Will Shortz




TRAP (66A. Word that can follow the ends of 18-, 25-, 43- and 58-Across), LIGHT SPEED (18A. 186,000 miles per second), AS QUIET AS A MOUSE (25A. Not making any sounds), BLUE-FOOTED BOOBY (43A. Seabird native to the Galápagos Islands) and GEORGE SAND (58A. French novelist who had an affair with Frédéric Chopin), e.g., speed trap, mousetrap, booby trap and sand trap, are the interrelated group of this post-tryptophanic-leftovers-weekend Monday crossword.







Seven- and eight-letter entries include AL DENTE (35A. Not too soft, as pasta), NOT A BIT (42D. Zilch), PLAYMATE (20A. Child’s friend), ROD CAREW (54A. Only American League player to win a batting crown without hitting a home run) and TRAYFUL (4D. Amount of food at a cafeteria).







Six-letter -- APERCU (10D. Hasty glance); BOUGHS (43D. Tree branches); DADDY-O (47D. Cool cat); E BONDS (46D. Old U.S. gov’t investments); ENLACE (5D. Intertwine); LONERS (44D. Recluses); NURSED (14A. Breast-fed); QUIT IT (6D. “Cut that out!”); SEEN AS (11D. Perceived to be); STERNA (22A. Breastbones); TRENDY (62A Chic); UNMASK (51A. Reveal); UPDATE (12D. Supply with more recent info); UPMOST (45D. Like Brahmins in the caste system).







Five -- AGENT (28D. 15-percenter); 41D. CESAR Romero, onetime player of the Joker); CROON (41A. Sing like Bing Crosby); 5. EQUAL sign (=); GALAS (33A. Fetes); 65A. PESOS (19D. Mexican moolah); RATSO Rizzo, Dustin Hoffman role).







Short stuff -- ALT, APE, ARF, ASH and ASU, AVER, BAIT, BETE, BIC, DOO and LOO, DST, ETTA, EVIL, EXO, FOCI, HRS, IATE, INB, KERR, LETS, MAE, “Après MOI le déluge”NONO, OOPS, PAUL, PEP, QUO, RANT, RIGA, SAN and SAX, SCAT, SEA, SEGA, SGT, SST, SCAT, RANT, REAR, TOY, URGE, WARP, WEEP, WEST, ZIT and ZOO.




One more trap! 



---------------------



For today’s cartoon, go to The Crossword Puzzle Illustrated.







Click on image to enlarge.







Puzzle available on the internet at












If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.




Remaining clues -- Across: 1. Sunset direction; 10. Tempe sch.; 13. State as fact; 16. Vigor; 17. Latvia’s capital; 23. Central points; 24. Nonsense singing; 32. Left-handed Beatle; 34. Prefix with skeleton; 38. Clearasil target; 42. Taboo; 49. “My bad!”; 50. Worms, for a fisherman; 60. ___ noire; 61. 60-min. periods; 63. “I can’t believe ___ the whole thing!”; 64. Fast jet, for short. Down: 1. Twist out of shape; 2. Blackhearted; 3. Dreamcast game company; 7. Feel the ___; 8. Cigarette’s end; 9. “___ Go Crazy” (#1 Prince hit); 21. “Après ___ le déluge”; 25. Mimic; 26. “Wailing” instrument; 27. Status ___: 29. ___ Fernando Valley; 30. PC key; 31. Fannie ___ (home financing group); 35. Terrier’s bark; 36. London lavatory; 37. Scooby-___; 38. Where to see elephants and elands; 39. Schubert’s Symphony No. 8 ___ Minor; 40. Many an item in Santa’s bag; 48. Inexpensive pen; 52. ___ Pepper; 53. Deborah of “The King and I”; 54. Diatribe; 55. Derrière; 56. Jazzy James; 57. Bawl; 59. Adriatic or Aegean.








11.29.09 -- Cued Up










-----------------







Sunday, November 29, 2009







CUED UP, Puzzle by Will Nediger, edited by Will Shortz





In this Sunday crossword, the commonly combined letters Q and U are added to seal of approval, wildebeest, easy rider, almsgiving, ain’t misbehaving’, shepherd’s pie and vanishing act, resulting in SQUEAL OF APPROVAL (22A. Delighted exclamation?); WILDE BEQUEST (36A. Part of an Irish playwright’s will?); QUEASY RIDER (68A. Carsick passenger?); QUALMS GIVING (94A. Causing uneasiness?); QUAINT MISBEHAVIN’ (113A. Carryin’ on, in olden times?); SHEPHERD’S PIQUE (4D. Anger at losing one’s flock?); VANQUISHING ACT (50D. Subjugation?).










Seven- and eight-letter entries include APROPOS (109A. Germaine); AUDIBLE (92D. Within earshot); CAUSEWAY (3D. Florida Keys connector), BOB SAGET (41D. Narrator of “How I Met Your Mother”), IDEA MAN (27A. Inventive type); INDIAN TEA (106A. Darjeeling, e.g.), MINI GOLF (47D. It may feature a windmill), MIST OVER (86D. Get fogged up) and ONE-HITTER (29A. Pitcher’s feat); PLOTTED (6D. Conspired).










Six - ADHERE (96D. Cleave); BEAVIS (56A. TV character often seen in a Metallica T-shirt); BE NICE (64A. “Don’t fight”); BREMEN (76D. German city where Beck’s beer is brewed); DANUBE (75A. Bratislava’s river); EAGLET (17D. Bald baby?); FERMAT (58D. French mathematician who pioneered in the theory of probability); FLANGE (58A. Pipe attachment); GENTLE (33A. Tame); IMPALA (98D. Chevy model); INMATE (15D. One surrounded by cell walls); INVADE (11D. Maraud); LET’S GO (77A. “Come on, guys!”); LIE LOW (97D. Try to avoid detection); QUAFFS (94D. Hearty drafts); RISQUE (44D. Blue); SCOWLS (16D. Looks sore); SEQUEL (28D. “The Dark Knight,” for one); SNYDER (43A. Tom of “The Tomorrow Show”); SPLITS (5D. Gymnastic feat); TASMAN (85A. New Zealand’s discoverer); TIMELY (102D. Opportune); UNSEAT (95D. Prevent from being reelected); UNDIES (104A. Drawers, e.g.); USAGES (72A. Conventions); VERILY (99D. Forsooth); VISHNU (14D. Krishna is one of his avatars); ZOOMED (10D. Whizzed along).







Five -- ABYSS, AGAIN, ASHEN, ASIDE, ATOLL, BELLY, CHICA, DEBIT, ENTER, EVIAN, GUARD, ICANT, IMAGO, INCUR, INEPT, INFRA, IRONY, ISITI, KORAN, NEAPS, ONAIR, PEALE, PETIT, PLANA, RILEY, SHAWL, SLIDE, SPOOL, SPRIT, TONAL, TRAIL.







Four --ACME, AUEL, BETH, CEDE, CERT, DOCS, EXEC, FARO, FEEL, GANG, GERM, INCA, IRAQ, IRON, LAPD, LOCI, MERE, NAAN and NOUN, NASA, NCAA, OMAN and OMAR, OPAH, ORGS, OVER, PIUS, QUIP, ROWE, SETH, SKIP and SNIP and SIPS, TIED, VISE, WIDE, ZINE.







Three -- AAH, ALI, and ARI, ASS, BEN and DEN, BUG, COD, DOS, EAU and EMU, ELL, GEM, IDO, NED, OAF, OPQ, OUT, QBS, SOL, TAC.




-----------------



For today’s cartoon, go to The Crossword Puzzle Illustrated.









Click on image to enlarge.







Puzzle available on the internet at











If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.



Remaining clues -- Across: 1. Government pubs., say; 5. Twine holder; 10. Amateur publication, for short; 14. What a migraine might feel like; 18. Moonfish; 19. Primary stratagem; 20. Like much music; 21. Old alpaca wool gatherer; 25. Cough cause; 26. Sail extender; 28. Bit of attire for a carriage ride; 32. One all, say; 34. “Tamerlane” dramatist Nicholas; 35. V-chip target; 38. Museum worker; 40. Bank statement entry; 42. It came up from Down Under; 45. Fish-and-chips fish; 46. Sultan’s land; 49. Aquafina competitor; 54. Impertinent sort; 59. Needle problem; 62. Tests the water?; 66. Game grp.; 67. Many curves, in math; 70. Bon mot; 71. Babylon’s site, today; 73. Starting point; 74. Some pieces in an archaeological museum; 79. “Jour de Fete” star director and writer, 1949; 81. Neighbor of a shift key; 82. “Little Women” woman; 83. Iranian supreme leader ___ Khamenei; 89. 49-Across, e.g.; 91. Red leader?; 93. Spanish girl; 101. Not safe; 103. Schools of thought; 105. Plain and simple; 108. White as a sheet; 111. Last stage of insect development; 117. Gambling game enjoyed by Wyatt Earp; 118. Paunch; 119. Wake Island, e.g.; 120. Turn over; 121. Irish ___; 122. Put in stiches; 123. Poet who wrote “An’ the Gobble-uns ‘at gits you / Ef you / Don’t / Watch / Out!”); 124. Walked. Down: 1. Bobs and such; 2. Alphabetic trio; 7. Unlikely ballet dancer; 8. Signing warning people to be quiet; 9. Columbo’s employer, for short; 12. Tandoor-baked bread; 13. Head of lettuce?; 20. Bring up the rear; 23. N.L. West team, on scoreboards; 24. ___ four; 29. Assns.; 30. It may be declined; 31. Suit; 33. Absolute beauty; 36. Call on a pitch; 37. Nebraska senator Nelson; 39. Easy chair site; 46. Superior to; 48. “Don’t Be Cruel” vis-à-vis “Hound Dog”; 51. Bring about; 52. Time’s partner; 53. Some tides; 55. Name shared by 12 popes; 57. Big gulf; 59. Water park feature; 50. Sura source; 61. “Impossible!”; 63. Positive thinking proponent; 65. Legal writ, in brief; 69. Clockmaker Thomas; 78. “Our ___”; 80. Certain X or O; 82. Programming problem; 84. Wood alternative; 87. Greatest flowering; 88. Astronaut’s insignia; 90. Dolt; 91. Like a butterfingers; 100. It may be dramatic; 107. Sound at a spa; 109. “The Clan of the Cave Bear” author; 110. Baseball G.M. Minaya; 113. Montana and others, for short; 114. Helios’ counterpart; 115. It may be said before a kiss; 116. ___ Land of “Twenty Thousand Leagues Under the Sea”.






11.28.09 -- In So Many Words





Night Goblin Cave, Warhammer Online







------------------







Saturday, November 28, 2009







Puzzle by Karen M. Tracey, edited by Will Shortz




Saturday, or in so many words…




Across -- 1. Goes off, ERRS; 5. Sty resident, SLOB; 9. Part of the Dallas-Fort Worth metroplex, PLANO; 14. Dash feature, TACH; 15. Travel by bus, say, TOUR; 16. Zero, RESET; 17. Baron, CZAR; 18. Shell alternative, ESSO; 19. French floor, ESTAGE; 20. Hoisted, as a sail, HOVE; 21. Keep from going through, VETO; 22. Cruise place, LINER; 23. Part of “The Jungle Book”, RIKKI TIKKI TAVI; 26. Opening string, ABC; 27. Outdoor signage option; NEON LAMP; 28. Quaint fashion accessory, HAT PIN; 30. Follow, GET; 31. Argument makers: Abbr., ATTS; 35. One with a hard, weather-resistant coat, SCOTTIE; 37. Round opening, TEE SHOT; 39. Callaloo ingredient, OKRA; 40. Hi-tech heart, CPU; 42. Good way to choose, WISELY; 43. Amassing amply, RAKING IN; 46. When France’s Philip I took the throne, MLX; 47. What a student might not go without?, PERMISSION SLIP; 51. AVOIR froid (be cold: Fr.); 52. Some parlors, for short, OTBS; 53. The redbud is one of its symbols: Abbr., OKLA; 55. Criterion, GAUGE; 56. Borscht flavorer, DILL; 57. Deity worshiped with much sensuality, BAAL; 58. 18-season Mariner Martinez, EDGAR; 59. Singer/songwriter Sands, EVIE; 60. Trimming and smoothing aid, ADZE; 61. Time of one’s life, TEENS; 62. Text message status, SENT; 63. No mere chuckle, ROAR.







Down -- 1. Do some impressions, ETCH; 2. Sharp, narrow range of hills, RAZORBACK; 3. Early LP issuer, RCA VICTOR; 4. Title film character who says “Donkey, two things, O.K.? Shut … up!”, SHREK; 5. “Talk to Me” singer, 1985, STEVIE NICKS; 6. Be bested by, LOSE TO; 7. Bouncer’s job, OUSTING; 8. A little running water?, BROOKLET; 9. Heat, for short, PRELIM; 10. Take the situation in stride, LET IT PASS; 11. Yoga posture, ASANA; 12. It comprises the southern half of Israel, NEGEV; 13. “Scary Movie” actress, 2000, OTERI; 24. Grow together, KNIT; 25. Six-time Oscar nominee with a 2008 win, KATE WINSLET; 26. “Gotcha,” humorously, AHSO; 29. Fully feather-footed flier, PTARMIGAN; 32. “Pooh-Bah” source, THE MIKADO; 33. Where the going rate is charged?, TOLL PLAZA; 34. Final course?, STYX; 36. Series composition, EPISODES; 38. One abroad, EINS; 41. Promoting harmony, UNITIVE; 44. Drying racks, AIRERS; 45. Little mischief-maker, GOBLIN; 47. Pathology pioneer Sir James PAGET; 48. Shake, EVADE; 49. Compact stuff, ROUGE; 50. Kind of pneumonia, LOBAR; 54. Any pro designated hitter, briefly, ALER.







Words, words, words...




-----------------



For today’s cartoon, go to The Crossword Puzzle Illustrated.







Click on image to enlarge.







Puzzle available on the internet at












If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.









How to remove Advanced Virus Remover

Fake : Advanced Virus remover (2009 - 2010)


Photobucket


Files Created
C:\Program Files\AdvancedVirusRemover\PAVRM.exe
C:\Program Files\AdvancedVirusRemover\AVR.exe
C:\Program Files\AdvancedVirusRemover\Viruses.bdt
C:\Program Files\AdvancedVirusRemover\AdvancedVirusRemover.exe

C:\Windows\system32\AVR10.exe
C:\Windows\system32\41.exe
C:\Windows\system32\winupdate86.exe
C:\Windows\system32\winhelper86.dll
C:\Windows\system32\critical_warning.html
C:\s


%UserProfile%\Desktop\Viruses.bdt
%UserProfile%\Desktop\Advanced Virus Remover.lnk
%UserProfile%\Start Menu\Advanced Virus Remover.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\
Quick Launch\AdvancedVirusRemover.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\
Advanced Virus Remover.lnk
%UserProfile%\Application Data\Mozilla\Firefox\Profiles\s1jqw0bz.default\cookies.sqlite

Registry Modifications
Keys Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKCU\Software\AVR

Values Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\
NoChangingWallpaper = 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
NoSetActiveDesktop = 0x00000001
NoActiveDesktopChanges = 0x00000001

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKCU\\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
winupdate86.exe = C:\Windows\System32\winupdate86.exe"
Advanced Virus Remover = C:\ProgramFiles\AdvancedVirusRemover\AVR.exe
AdvancedVirusRemover = C:\ProgramFiles\AdvancedVirusRemover\AVR.exe
PAVRM.exe = C:\Program Files\AdvancedVirusRemover\PAVRM.exe
PAVRM = C:\Program Files\AdvancedVirusRemover\PAVRM.exe
AVR = C:\Program Files\AdvancedVirusRemover\PAVRM.exe

HKCU\Software\
8636065b-fef0-4255-b14f-54639f7900a4 =
"8636065b-fef0-4255-b14f-54639f7900a4"

5222009A-DD62-49c7-A735-7BD18ECC7350 =
"5222009A-DD62-49c7-A735-7BD18ECC7350"
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
Wallpaper = "%System%\critical_warning.html"

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoSetActiveDesktop = 0x00000001
NoActiveDesktopChanges = 0x00000001

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\
NoChangingWallpaper = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableTaskMgr = 0x00000001

HKCU\Software\Microsoft\Internet Explorer\Main\
NotifyDownloadComplete = "yes

HKCU\Software\AVR\
LastVFC = "25"
VirList = "71255354154320429142454491823411617202092515"
LastD = "18"

LastVFC = "25"
VirList = "504115033127181484212398385028451851153126451537"
LastD = "20"
LastScan = "20.11.2009 08:16
Values deleted
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\
Wallpaper = ""
The following Registry Value was modified:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\
WallpaperLocalFileTime =

Hosts modified
89.149.210.61 www.google.com
89.149.210.61 www.google.de
89.149.210.61 www.google.fr
89.149.210.61 www.google.co.uk
89.149.210.61 www.google.com.br
89.149.210.61 www.google.it
89.149.210.61 www.google.es
89.149.210.61 www.google.co.jp
89.149.210.61 www.google.com.mx
89.149.210.61 www.google.ca
89.149.210.61 www.google.com.au
89.149.210.61 www.google.nl
89.149.210.61 www.google.co.za
89.149.210.61 www.google.be
89.149.210.61 www.google.gr
89.149.210.61 www.google.at
89.149.210.61 www.google.se
89.149.210.61 www.google.ch
89.149.210.61 www.google.pt
89.149.210.61 www.google.dk
89.149.210.61 www.google.fi
89.149.210.61 www.google.ie
89.149.210.61 www.google.no
89.149.210.61 search.yahoo.com
89.149.210.61 us.search.yahoo.com
89.149.210.61 uk.search.yahoo.com

URLs to be download / data identified
http://advanced-virusremover2010.com/buy/?code=00000920
http://advanced-virusremover2010.com/buy/jq.js
http://downloadavr10.com/loads.php?code=0001001
http://downloadavr10.com/dfghfghgfj.dll
http://testavrdown.com/cgi-bin/get.pl?l=0001001
http://downloadavr10.com/cgi-bin/download.pl?code=0001001
http://advanced-virusremover2010.com/buy/?code=0000112
http://downloadavr11.com/loads.php?code=0001122
http://downloadavr11.com/dfghfghgfj.dll
http://testavrdown.com/cgi-bin/get.pl?l=0001122
http://downloadavr11.com/cgi-bin/download.pl?code=0001122
http://downloadavr10.com/loads.php?code=0000070
http://downloadavr10.com/dfghfghgfj.dll
http://downloadavr10.com/cgi-bin/download.pl?code=0000070
http://testavrdown.com/cgi-bin/get.pl?l=0000070
http://advanced-virusremover2010.com/buy/?code=00000000
===================================================
วิธีกำจัด Fake : Advanced Virus remover (2009-2010)
===================================================

1. Run PeeTechFix-Advanced Virus remover 1.0
2. ใช้ Hijack This Fix บรรทัด 01 - Hosts

O1 - Hosts: 89.149.210.61 www.google.com
O1 - Hosts: 89.149.210.61 www.google.de
O1 - Hosts: 89.149.210.61 www.google.fr
O1 - Hosts: 89.149.210.61 www.google.co.uk
O1 - Hosts: 89.149.210.61 www.google.com.br
O1 - Hosts: 89.149.210.61 www.google.it
O1 - Hosts: 89.149.210.61 www.google.es
O1 - Hosts: 89.149.210.61 www.google.co.jp
O1 - Hosts: 89.149.210.61 www.google.com.mx
O1 - Hosts: 89.149.210.61 www.google.ca
O1 - Hosts: 89.149.210.61 www.google.com.au
O1 - Hosts: 89.149.210.61 www.google.nl
O1 - Hosts: 89.149.210.61 www.google.co.za
O1 - Hosts: 89.149.210.61 www.google.be
O1 - Hosts: 89.149.210.61 www.google.gr
O1 - Hosts: 89.149.210.61 www.google.at
O1 - Hosts: 89.149.210.61 www.google.se
O1 - Hosts: 89.149.210.61 www.google.ch
O1 - Hosts: 89.149.210.61 www.google.pt
O1 - Hosts: 89.149.210.61 www.google.dk
O1 - Hosts: 89.149.210.61 www.google.fi
O1 - Hosts: 89.149.210.61 www.google.ie
O1 - Hosts: 89.149.210.61 www.google.no
O1 - Hosts: 89.149.210.61 search.yahoo.com
O1 - Hosts: 89.149.210.61 us.search.yahoo.com
O1 - Hosts: 89.149.210.61 uk.search.yahoo.com
-----------------------------------------------------------------------
หรือ download Host จาก mvp.org
Download: hosts.zip [right-click - Select: Save Target As] [Updated NOV-13-2009]
โดยแตกไฟล์แล้ว run ไฟล์ MVPS.bat หรือนำไฟล์ Hosts ไปวางที่ตำแหน่ง
C:\WINDOWS\system32\drivers\etc
เพื่อ block website download fake
ส่วนใครที่ใครใช้ Windows vista ให้ศึกษาเพิ่มเติมจาก link นี้ครับ
Blocking Unwanted Parasites with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

และขอแนะนำให้ ติดตั้งโปรแกรม mcafee advisor เพื่อตรวจสอบ website ที่กำลังจะเข้าไปเยี่ยมชม