10.01.10 — Thrilla in Manila









Friday, October 1, 2010





Puzzle by David J. Kahn, edited by Will Shortz




Thirty-five years ago the ALI-FRAZIER FIGHT (40A. Memorable 10/1/75 event), the THRILLA IN MANILA (7D. 40-Across, familiarly) took place in the PHILIPPINES (3D. Where the 40-Across was held). This Friday’s knockout crossword celebrates that anniversary including BOXING (16A. 40-Across activity) and 11D. The Louisville LIP (40-Across winner’s nickname), THE GREATEST (27D. 40-Across winner’s nickname), SMOKIN’ JOE (67A. With 62-Down, 40-Across loser’s nickname) and TKO (71A. 40-Across ending, for short).





Other, eight-letter — AGITATOR (17A. Troublemaker), GODZILLA (25D. 164-foot-tall movie star), IRONHEAD (63A. Nickname for racer Dale Earnhardt Sr., so called because of his stubbornness), LARGESSE (68A. Generosity), MOONEYES (21D. Silvery fish), NEHEMIAH (14A. Hebrew leader who rebuilt the walls of Jerusalem).





Sixes and Sevens — AMELIA (8A. Henry Fielding title heroine), ARM HOLE (28D. Tee shirt opening), BOPPER (18A. Big home run hitter, in slang), EXPERT (10D. Pro), OPALINE (23D. Iridescent), PAJAMA (60A. Bed piece?), REPORT (49D. Bang or boom), RETAKE (47D. Second shot), SENATOR (22D. Cicero or Publius), SIT-INS (5D. March alternatives), SOOTHER (29D. Balm), SPEEDS (69A. Does 85, say).





Five — AMANA, ANGLO, DANCE, ELMER, IMAGE, LASER, MOOGS, NAPPY, RANGE, RESET, SOLON (32A. Statesman of old Athens), SPINY, SRTAS, STROH, TIMID.





Short stuff — ABBA, AER and AGR, ALP and AMP, ANA, ANTE, APE, ASK, ASST, DELE, “In excelsis DEO“, EFS, EMO, EPPS, ETE, INE, ITD, LEG, Director LENI Riefenstahl, NCR, ONER, PAST, PSS, RAN, SAO and SOI, SHE, SPF, TANS, “Comin’ THRO the Rye“, TIN, YRS.




————————




































Click on image to enlarge.



Puzzle available on the internet at THE NEW YORK TIMES — Crossword Puzzles and Games. If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.



Remaining clues — ACROSS: 1. Monte Leone, for one; 4. Secy., e.g.; 20. Likeness; 22. “___ heard”; 24. White, in a way; 26. Sp. Misses; 30. “House” actor; 35. British diaper; 37. Pony or alligator; 39. Funny Philips; 43. Tobacco holder; 44. Like some anteaters; 45. Brewer Bernard; 46. Humdinger; 48. Bugger of Bugs; 50. Take out; 51. Change, as a watch; 53. Kind of printer; 55. Atmosphere: Prefix; 56. Giant; 58. History; 70. “___ up!” (game cry). — DOWN: 1. “Wheel of Fortune purchase; 2. Advantage, with “up”; 4. Big appliance maker; 6. Brazil’s ___ José Bay; 8. Pop group whose first Top 40 album was, appropriately, “Arrival”; 9. Musical equipment popularized in the 1960s; 12. Carol ending?; 13. Cabinet dept.; 15. Time spent on la Côte d’Azur; 31. Block letters?; 33. A.T.M. maker; 36. Decade parts: Abbr.; 38. Flunking grades; 41. Big lug; 432. “___ be my pleasurre”; 52. Meek; 54. The Rockies, e.g.; 57. Gets some color; 59. “___ Walks in Beauty” (Byron poem); 60. Letter endings: Abbr.; 61. Speaker’s place; 64. Published; 65. Expect (of).



09.30.10 — "Uh-uh!"













————————





Thursday, September 30, 2010





Puzzle by Victor Fleming, edited by Will Shortz




“Uh-uh!” is the clue for I WOULDN’T / IF I WERE YOU, BAD IDEA, BACK OFF, THINK AGAIN and DON’T DO IT in this talkative thumbs-up Thursday crossword. Four more vocables are OH WOW (46A. “That’s amazing!”), DARE ME (62A. “You think I won’t?!”), CAN TOO (11D. Shout in a playground debate), YES BUT (12D. “I’ll grant you that. However …”) and “Don’t have A COW!”







Other — DECOROUS (13A. Marked by dignity and taste), FAUN and SATYR (38D. 8-Down’s Roman equivalent, 8D. Nymph pursuer), MR SPOCK (1A. Sci-fi-role starting in 1966), OMNIVORE (37D. Hardly a picky eater), SCORE PAD (3D. Bridge need), SUBMERSE (63A. Put under), TALLEST (65A. Guinness superlative).





Six-letter — ARROYO (10D. Arid region’s watercourse), ASTERN, BISTRO, E-TRADE, KUNG FU, LHASAN (44D. Like the Dalai Lama, historically), MACRAE, REAMER, SHARDS, STOICS, TO A MAN, U-TURNS, WIN OUT.





Five — ACORN, À GOGO, BRUCE, DWEEB, ENOLA (64A. Girl in “Waterworld”), ERIKA, GODLY, IRREG, KARMA, L’EGGS, MILAN, MODEL, POUTS, SERAI (31A. Destination for a Near Eastern caravan), STACY, RAT ON.





Short stuff — ACNE, ALP, BARB, BEDE, BEES, COD, EEL, ELBA and ELEA, FNMA (39D. Low-cost home loan corp.), HOV, HTML (55D. Webmaster’s lingo), ISS, MDI, MINA, MULE, NBA, NUM, ORLE, OTB, RAS, REW, ROOT, RTE, TCU, TET.




————————












 







Click on image to enlarge.



Puzzle available on the internet at THE NEW YORK TIMES — Crossword Puzzles and GamesIf you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.



Remaining clues — ACROSS: 8. Keach of “W.”; 15. He played opposite Jones in “Carousel” and “Oklahoma!”; 17. Reversals; 18. Map line: Abbr.; 19. Like the devout; 21. Wagering locale: Abbr.; 22. Some socials; 26. Backdrop for many a Winter Olympics; 27. Wayne or Lee; 28. It may be square; 29. It gets the juice out; 40. Brand associated with Everyday Knee Highs; 42. Unanimously; 43. Island in the Tyrrhenian Sea; 48. Deut. Preceder; 52. ___ Harker, wife in Bram Stoker’s “Dracula”; 53. Dorm V.I.P.’s, for short; 54. Part of a winter stash; 55. Letters on the road; 56. Behind. — DOWN: 1. Year Michelangelo began work on “David”; 2. VCR button; 4. Shows disappointment, in a way; 5. Heraldic band; 6. Mail order option; 7. Style of fighting; 9. Fort Worth sch.; 14. Greek philosophical group; 15. Pack carrier; 20. One who’s definitely not in the in-crowd; 22. Nasty remark; 23. Zeno’s locale; 24. Sale table notation; 25. Actress Alexander of “The Cosby Show”; 27. Eliot protagonist; 30. European fashion capital; 32. Betray; 35. Disco phrase; 41. Some broken glass; 43. Brokerage name since 1992; 45. Spot for a bite; 47. Emerge on top; 50. Fate; 51. Teen breakout; 52. Feature at an auto show, in two different ways; 57. Sushi fish; 59. Jazz group, for short; 60. Mag. Edition; 61. New Year festival overseas.



09.29.10 — Now Showing









Wednesday, September 29, 2010





Puzzle by Charles Gersch, edited by Will Shortz




Seven film titles constitute the interrelated group of this entertaining Wednesday crossword.




  • ANGER MANAGEMENT (14A. 2003 Sandler/Nicholson comedy)

  • ROAD TO SINGAPORE (17A. 1940 Crosby/Lamour/Hope film that was the firt of a “travel” series)

  • LAST PICTURE SHOW (37A. 1971 film that was Cybil Shepherd’s debut, with “The”)

  • ON THE WATERFRONT (41A. 1954 Elia Kazan Oscar winner)

  • HORTON HERS A WHO (59A. 2008 film derived from Dr. Seuss)

  • THE COLOR OF MONEY (62A. 1986 film for which Paul Newman won his only Oscar)

  • A NIGHT AT THE OPERA (7D. 1936 Marx Brothers romp)


































































































































































































































































































Other — AGAIN (3D.“Encore!“), AHOYS and ALOHA, AMPERE (26D. Current unit), ATEAM, ATRAS, BASRA (6D. Mideast city whose name, coincidentally, is an anagram of ARABS), BERET, CATCH, CIAOS, ENOLA, ENRON, HENCE, HOOTCH (45D. The sauce), IMPELS, Sierra LEONE, MOOLA, OCHRE, OLEOLE, PREFAB, RARER, REARM, ROGUE, STENOS, TOPPS, TOWNE, USERS, WHARF.





Short stuff — ABO, AGAR, ALOT, BAA and BAN, BABE, BATH (25D. Setting for candelit romance), really?, CWTS, EAT, EGGS, ELIS, ENLS, ESTO, HOE, HOCH and LOCH IONA, ILES, IWON, LAOS, LAHR, LEN, LOO, MRT, OATH,OH TO be in England …”, ORG, PARR, PIA, RAN, REDS, ROTH, SEAS, SMU, SRTA, STES, TANK, THOR, TIC, TKO, TOA, WBA.




I promise you I'll never desert you again because after 'Salome' we'll make another picture and another picture. You see, this is my life! It always will be! Nothing else! Just us, the cameras, and those wonderful people out there in the dark!... All right, Mr. DeMille, I'm ready for my close-up. ~ Gloria Swanson as Norma Desmond in “Sunset Boulevard”





————————











































Click on image to enlarge.



Puzzle available on the internet at

THE NEW YORK TIMES — Crossword Puzzles and Games.

If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.



Remaining clues — ACROSS: 1. Supply with more ammo, say; 6. Term of endearment; 10. Bits of land in la Seine; 18. Yalies; 19. Part of NATO: Abbr.; 2. “Mad Men” extras; 21. Conducted; 22. Actor Bert; 24. Mystery writer Deighton; 25. It may make a ewe turn; 27. Big name in baseball cards; 30. Starters; 33. Gelantinous ingredient in desserts; 34. First X or Q, say; 42. Bout stopper; 43. Author Philip; 44. Some razors; 45. Ergo; 46. Pugilists’ grp.; 47. Blood-typing syst.; 49. Mystery writer Edward D. ___; 51. Ode title starter; 54. World Cup chant; 57. Singer-actress Zadora; 58. Lamond, e.g.; 63. Inauguration Day highlight; 64. Proverbial heptad; 65. Addicts. — DOWN: 1. Less well done; 2. ___ Gay, historic plane displayed by the Smithsonian; 4. N. L. Central team; 5. “I pity the fool” speaker; 8. Proscribe; 9. Drives (on); 10. Drives; 12. Bankrupt company in 2001-001 news; 13. Fr. Holy women; 15. Lettuce or kale; 16. Corrode; 23. Ne’er-do-well; 28. Henry VIII’s sixth; 29. Like some suburban homes; 30. Scads; 32. “___ perpetua” (Idaho’s motto); 34. Thursday’s eponym; 35. College in New Rochelle, N.Y.; 36. 100-lb. units; 38. Triumphant cry; 39. Fisherman’s 10-pounder, e.g.; 450. Mex. Miss; 46. Fisherman’s spot; 47. Lei-person’s greeting?; 48. Covering for la tête; 50. Piertro’s at-tas; 51. Olde ___ (historic area, quaintly), 52. Orangish shade; 53. Shipboard cries; 55. Old card game with foreits; 56. Photo blowups: Abbr.; 58. Vietiane’s country; 60. Implement in a Millet painting; 61. Dallas sch.





09.28.10 — NO PAR














————————





Tuesday, September 28, 2010





Puzzle by Michael Torch, edited by Will Shortz





PAIRAGRAPHS (20A. Two charts?), PAREAPHRASE (58A. Edit?), PEARAMOUNT (11D. A bushel of Boscs?) and PEREAMOURS (29D. French father’s affairs?) are the interrelated group of this Tuesday crossword, and uh… perhaps NO PAR (41A. Like some stock).





Other — BUS STOP (9D. Point on a line?), DEPLETED (51A. Drained), DRAPERS (45D. Fabric dealers, to Brits), HIT HARD (25A. Severely affected), HOP ON POP (27A. Dr. Seuss title), SAMBAED (53A. Danced at Rio’s Carnival, maybe), RIP APART (42D. Shred), WING SPAN (5D. Bird spec).





Mid-size — ACUTE, ALCOA, BIPED, CORER, DOSED, DRAMA, EASES, ERROR, EUROPE (52D. One side of “the pond”), KNEAD, LYMPH, PIPED, PLOWS, SATIN, SEPIA, SPACE, STEREO, UTERO.





Short stuff — ADDA, ADIA, AKIN, ALPH, ANAT, ANNS, APU, ARRS, ASIA and ASIT, BARB and CARB and CARP, DOOM, DUAL, EDEN, ENS and ENDS, EYES, HID, HOCK, HOLD, INKY, ITE, MEIR, NAPE, NNE, NORM, OKAY and OKRA, ONOR, ORAN, ORE, OTOS, PINE, PLO, RIFE, SAND, SEA, SLED, TEE, WANE, WIFI, WOOL.




————————















Click on image to enlarge.





Puzzle available on the internet at




THE NEW YORK TIMES — Crossword Puzzles and Games.





If you subscribe to home delivery of The New York Times you are eligible to access the daily crossword via The New York Times - Times Reader, without additional charge, as part of your home delivery.



Remaining clues — ACROSS: 1. Cornfield sounds; 5. Scarf material; 9. Any member of the genus Homo; 14. “___ happens …”; 15. Black; 16. In ___ (not yet born); 17. Prevalent; 18. Having two or three kids in a family, nowadays; 19. What to “Come see the softer side of,” in a slogan; 23. ___ v. Wade; 24. Nav. Rank; 25. Severely affected; 32. Gloom’s partner; 33. Shipment to a smeltery; 34. Audited a class, say; 36. Winter highway department needs; 43. With 39-Across, kind of engine; 44. Massage; 46. Retro photo tone; 48. New Orleans-to-Detroit dir.; 49. Some airport data: Abbr.; 51. Drained; 53. Danced at Rio’s Carnival, maybe; 56. Homer Simpson’s Indian friend; 57. Mideast grp.; 64. Sharp; 66. Recipe step starter; 67. Approve; 68. Implement for an apple; 69. Israel’s Golda; 70. “Lonesome” tree; 71. Lets (up); 72. Basic subj. for a surgeon; 73. Goals. — DOWN: 1. Fault-find; 2 Large part of a world atlas; 3. Coffee shop convenience for a laptop; 4. Not mono; 6. ___ about (approximately), 7. Gumbo staple; 8. ___ node; 10. Suffix with suburban; 12. Boo-boo; 13. Gave medicine; 21. Raggedy ___ (dolls); 22. Concealed; 26. Full or half nelson; 27. What a debtor might be in; 28. Algerian port; 30. Western tripe; 31. Spoke (up); 35 Back of the neck; 37. Ebb; 38. Toboggan, e.g.; 40. Cutting remark; 47. Coleridge’s sacred river; 50. Large quantity; 53. Gap; 54. Foil-making giant; 55. Comedy alternative; 59. Fall place; 60. 1998 Sarah McLachlan song; 61. Related; 62. Hourglass fill; 63. Prominent features of a “Cats” poster; 65. Plumbing fitting.





How to remove hanruo.exe

hanruo.exe , next.exe

MD5 : 15a5ab1cb4fc74c605f2c1d5cc97428a
SHA1 : a29409d7c3532cbfc8c2bb021baf622cfcc4b731
...
AhnLab-V32010.09.27.012010.09.27Dropper/Win32.OnlineGameHack
AntiVir7.10.12.312010.09.26-
Antiy-AVL2.0.3.72010.09.26-
Authentium5.2.0.52010.09.27W32/Packed.Krap.A!Eldorado
Avast4.8.1351.02010.09.26-
Avast55.0.594.02010.09.26-
AVG9.0.0.8512010.09.26Klone.AP
BitDefender7.22010.09.27-
CAT-QuickHeal11.002010.09.27(Suspicious) - DNAScan
ClamAV0.96.2.0-git2010.09.27-
Comodo62082010.09.27-
DrWeb5.0.2.033002010.09.27-
Emsisoft5.0.0.372010.09.27Worm.Win32.Taterf!IK
eSafe7.0.17.02010.09.26-
eTrust-Vet36.1.78752010.09.25-
F-Prot4.6.2.1172010.09.27W32/Packed.Krap.A!Eldorado
F-Secure9.0.15370.02010.09.27-
Fortinet4.1.143.02010.09.26-
GData212010.09.27-
IkarusT3.1.1.88.02010.09.27Worm.Win32.Taterf
Jiangmin13.0.9002010.09.27-
K7AntiVirus9.63.26082010.09.25Riskware
Kaspersky7.0.0.1252010.09.27-
McAfee5.400.0.11582010.09.27-
McAfee-GW-Edition2010.1C2010.09.27Heuristic.BehavesLike.Win32.Spyware.B
Microsoft1.62012010.09.27Worm:Win32/Taterf.B
NOD3254812010.09.26-
Norman6.06.062010.09.26W32/Viking.gen5
nProtect2010-09-27.032010.09.27Trojan/W32.Agent.196508
Panda10.0.2.72010.09.26Trj/CI.A
PCTools7.0.3.52010.09.27-
Prevx3.02010.09.27-
Rising22.66.06.012010.09.27Packer.Win32.Mian007.a
Sophos4.58.02010.09.27Sus/UnkPack-C
Sunbelt69322010.09.27Worm.Win32.Taterf.b (v)
SUPERAntiSpyware4.40.0.10062010.09.27-
Symantec20101.1.1.72010.09.27-
TheHacker6.7.0.0.0352010.09.27-
TrendMicro9.120.0.10042010.09.27-
TrendMicro-HouseCall9.120.0.10042010.09.27-
VBA323.12.14.12010.09.24BScope.Trojan-PSW.AmGames
ViRobot2010.8.31.40172010.09.27-
VirusBuster12.65.27.32010.09.26-
PeeTechFix2.0.7.1152010.09.27Win32.PSW.OnlineGames
...
Hijack log
Process
dosRpta.exe

Registry
O4 - HKCU\..\Run: [hanruo] C:\WINDOWS\system32\hanruo.exe
O4 - HKCU\..\Run: [api32] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\apiqq.exe

Files Added
%System%\hanruo.exe
%System%\m.exe
%System%\hanruo10.dll
%System%\hanruo11.dll
%System%\hanruo12.dll
%System%\hanruo20.dll
%System%\hanruo21.dll
%System%\hanruo22.dll
%System%\vmpus0..dll (0-9)
%Windir%\dosrpta.exe (notepad)
%Temp%\apiqq.exe
%Temp%\apiqq0.dll (0-9)

Keys added
HKLM\SOFTWARE\Classes\CLSID\MADOWN

HKLM\SOFTWARE\Classes\CLSID\NOD32KVBIT
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-B9B3-483E-C484D4B20B72}
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\ProgID
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\Programmable
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DA7060E6-F54B-42AE-A337-7D26827AA890}

Values added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo: "dswdfre.x"
HKLM\SOFTWARE\Classes\CLSID\NOD32KVBIT\KVBIT_2: "611"
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}\InprocServer32\: "C:\WINDOWS\system32\vmpus0.dll"
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}\InprocServer32\ThreadingModel: "Apartment"
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-B9B3-483E-C484D4B20B72}\VcbitExeModuleName: "C:\WINDOWS\system32\m.exe"
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-B9B3-483E-C484D4B20B72}\VcbitDllModuleName: "C:\WINDOWS\system32\vmpus0.dll"
HKLM\SOFTWARE\Classes\CLSID\{B03A4BE6-5E5A-B9B3-483E-C484D4B20B72}\VcbitSobjEventName: "CVBASDDOOPADSAMN_0"
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\VersionIndependentProgID\: "IEHlprObj.IEHlprObj"
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\ProgID\: "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\InprocServer32\: "C:\WINDOWS\system32\hanruo20.dll"
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\InprocServer32\ThreadingModel: "Apartment"
HKLM\SOFTWARE\Classes\CLSID\{DA7060E6-F54B-42AE-A337-7D26827AA890}\: "IEHlprObj Class"
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\TypeLib\: "{DA7060E2-F54B-42AE-A337-7D26827AA890}"
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\TypeLib\Version: "1.0"
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\ProxyStubClsid32\: "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\ProxyStubClsid\: "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{DA7060E5-F54B-42AE-A337-7D26827AA890}\: "IIEHlprObj"
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\0\win32\: "C:\WINDOWS\system32\hanruo20.dll"
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\HELPDIR\: "C:\WINDOWS\system32\"
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\FLAGS\: "0"
HKLM\SOFTWARE\Classes\TypeLib\{DA7060E2-F54B-42AE-A337-7D26827AA890}\1.0\: "IEHelper 1.0 Type Library"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\: "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\: "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\: "{DA7060E6-F54B-42AE-A337-7D26827AA890}"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\: "IEHlprObj Class"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}: "hook dll rising"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
hanruo: "C:\WINDOWS\system32\hanruo.exe"
api32: "%Temp%\apiqq.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000

Effect : MSN /Windows live messenger error and disconnect
http://hotzone-it.blogspot.com/2010/06/msn-disconect.html
==================================================
วิธีกำจัด / แก้ไวรั: hanruo.exe
==================================================



หมายเหตุ : ท่านใดที่ได้รับผลกระทบจากไวรัสตัวนี้ โืดย MSN จะ Error และ Disconnect
ก็ลองเอาไปแก้ดูนะครับ
------------------------------------------------------------------------------

หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เพื่อป้องกันการเรียกใช้ autorun
เช่น

Program Advice (Stop AutoRun function/autorun.inf)

NoAutoRun (.REG)
http://www.mediafire.com/?ammmxwhqmnm
or

Panda USB Vaccine
http://www.mediafire.com/download.php?qig0nmnm4ld

or
KB971029, KB967715
http://hotzone-it.blogspot.com/2009/08/kb971029-fix-autorun-microsoft.html