Hbkernel32.sys, aliimz.sys, system.exe, koauolte.exe, cho22.tmp, etc. 1
Original endurer
1st
A friend said that his computer was automatically canceled after login. Please help me with the repair.
First try the security mode, and the fault persists.
This happens when userinit.exe is maliciously replaced.
Therefore, use the win peoptical disk to start and use fileinfoto check userinit.exe:
File Description: C:/Windows/system32/userinit.exe
Attribute: ---
Digital Signature: No
PE file: Yes
An error occurred while obtaining the file version information!
Creation Time:
Modification time:
Size: 1024 bytes, 1.0 kb
MD5: ab39ab1c7b0b5323dbedb336b0092307
Sha1: 4ef5f6ce1ccff37bdd8fa767c9b7dac9ac182421
CRC32: e6f5a115
Without Microsoft's digital signature, it was replaced, and the userinit.exe overwrite was restored from the Windows XP installation disc.
Restart your computer. This time you can log on normally.
Download the pe_xscan scan log analysis and find the following suspicious items:
Pe_xscan 08-08-01 by Purple endurer
17:18:48
Windows XP Service Pack 2 (5.1.2600)
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode
[System process] * 0
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 4:36:30
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 4:35:14
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/csrss.exe * 628 |
C:/Windows/system32/gdipro. dll | 4:31:45
C:/Windows/system32/sys05020.dll |
C:/Windows/system32/winlogon.exe * 652 |
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
System.exe * 1322
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Windows/system32/koauolte.exe * 1648
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/program files/Internet Explorer/iexplore.exe * 1832
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/program files/deepdo/deepdobar/favorite/favblock. dll
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Documents and Settings/Administrator/Local Settings/temp/svde. tmp * 2052
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
O2-BHO favhook class-{CD8BFE70-5809-4C73-9EEE-E5672C2B79D7} = C:/program files/deepdo/deepdobar/favorite/favblock. dll | 7:48:13
O2-BHO-{F6A454AE-156A-415E-9F89-3795677A8A91} = C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
O4-HKLM/../run: [360ary] C:/Windows/system32/koauolte.exe
O4-HKLM/../run: [hbservice32] system.exe
O4-HKLM/../policies/Explorer/run: [nwiz] alivin.exe
O4-HKLM/../policies/Explorer/run: [svt23] C:/0001b531/685562
O4-HKLM/../policies/Explorer/run: [svt233] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/cho22.tmp
O20-appinit_dlls = hbmhly. DLL, hbtl. DLL, hbqqxx. DLL, hbwd. DLL, e0d39066. DLL, caba599d. DLL, 9f684de8. DLL, 12b02216. DLL, 9ca963ca. DLL, 08223b03. DLL, 495271ca. DLL, 8566f82e. DLL, 58ff3024. DLL, b3721c07. DLL, da63e650. DLL, 4bf9cba3. DLL, 22d75360. DLL, 7adc2ab1. DLL, ipv4a8c2. DLL, e4814792.dll, c250cf20. DLL, a8fc611b. DLL, 122b901e. DLL, d7c79813. DLL, de02f764. DLL, 43acdcc5. DLL, e3366679.dll, 3d144530. DLL, hbwow. DLL, hbjxsj. DLL
O23-service: 4901228 (4901228)-C:/Windows/system32/4901228.sys | 3:30:37 (manual)
O23-service: 5102a80 (5102a80)-C:/Windows/system32/5102a80. sys | (manual)
O23-service: 8882fa1 (8882fa1)-C:/Windows/system32/8882fa1. sys | 4:33:57 (manual)
O23-service: 8b52f47 (8b52f47)-C:/Windows/system32/8b52f47. sys | 3:29:59 (manual)
O23-service: 9fd8db (9fd8db)-C:/Windows/system32/9fd8db. sys | (manual)
O23-service: aecff9 (aecff9)-C:/Windows/system32/aecff9.sys | (manual)
O23-service: aliimz ()-system32/Drivers/aliimz. sys (manual)
O23-service: beep ()-C:/Windows/system32/Drivers/beep. sys | 12:28:16 (system)
O23-service: hbkernel32 (hbkernel32 driver)-system32/Drivers/hbkernel32.sys (pilot)
O24-shlexechook: [2]-{3d144530-4310847cc-b7c7-a3a9f3b9a6b2} = 3d144530. dll
O24-shlexechook: [B]-{E3367679-4775-4244-A62E-4CFE58FC850B} = e3366679.dll
O24-shlexechook: [8]-{43acdcc5-9009-4af4-b80a-93bc656ef298} = 43acdcc5. dll
O24-shlexechook: [f]-{DE02F764-C51A-4788-9597-D78ECC2AC08F} = de02f764. dll
O24-shlexechook: [3]-{D7C79813-9233-4AE0-832C-99B2E8019673} = d7c79813. dll
O24-shlexechook: [c]-{122b901e-493f-4ad9-bc69-7de8c3e52fcc} = 122b901e. dll
O24-shlexechook: [7]-{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57} = a8fc611b. dll
O24-shlexechook: [B]-{C250CF20-5F89-4310-9854-4BC261FB14FB} = c250cf20. dll
O24-shlexechook: [8]-{E4814792-EFA3-4C20-93D0-8B130A59F9A8} = e4814792.dll
O24-shlexechook: [0]-{4154a8c2-bef9-46c8-983a-a26a0030ec30} = 4154a8c2. dll
O24-shlexechook: [c]-{7adc2ab1-5c6a-4408-8241094863354af7c} = 7adc2ab1. dll
O24-shlexechook: [6]-{22d75360-199d-4f79-880d-82e766675f06} = 22d75360. dll
O24-shlexechook: [f]-{4bf9cba3-8dee-41a1-8bdb-fc28d30e949f} = 4bf9cba3. dll
O24-shlexechook: [B]-{DA63E650-537C-4042-87BB-9D19D844680B} = da63e650. dll
O24-shlexechook: [f]-{B3721C07-62B3-411A-9DC7-F5F27E3E21FF} = b3721c07. dll
O24-shlexechook: [e]-{58ff3024-8a83-4b1a-88e9-302f47646eee} = 58ff3024. dll
O24-shlexechook: [1]-{8566f82e-03a4-416e-aeac-66600d8881f1} = 8566f82e. dll
O24-shlexechook: [0]-{495271ca-d0c6-4052-abe6-5b01c73cdfb0} = 495271ca. dll
O24-shlexechook: [e]-{08223b03-1b38-4a33-a83a-a4d3cc1d6e4e} = 08223b03. dll
O24-shlexechook: [3]-{9ca963ca-417c-4089-b0ab-31380f90d7e3} = 9ca963ca. dll
O24-shlexechook: [1]-{12b02216-ac3f-42a7-8313-449771237061} = 12b02216. dll
O24-shlexechook: [1]-{9f684de8-3e87-4404-9033-e02a3dfd8b61} = 9f684de8. dll
O24-shlexechook: [f]-{CABA599D-5089-4865-9420-E41FA3C1F55F} = caba599d. dll
O24-shlexechook: [f]-{E0D39066-96D7-4891-8527-488ADAFCD60F} = e0d39066. dll
O24-shlexechook: []-{F6A454AE-156A-415E-9F89-3795677A8A91} = C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
O24-shlexechook: []-{5b77087d-ab76-4c22-b0a6-c34d1f438e55} = C:/program files/common files/Microsoft shared/msinfo/come_system.sys | 0:32:31
O26-ifeo: 360loader.exe-> svchost.exe
O26-ifeo: 360safebox.exe-> ntsd-d
O26-ifeo: ccenter.exe-> svchost.exe
O26-ifeo: icesword-> svchost.exe
O26-ifeo: kppmain.exe-> ntsd-d
O26-ifeo: ravmon.exe-> svchost.exe
O26-ifeo: ravmond.exe-> svchost.exe
O26-ifeo: ravstub.exe-> svchost.exe
O26-ifeo: ravtask.exe-> svchost.exe
O26-ifeo: rstray.exe-> svchost.exe
O26-ifeo: thunder5.exe-> svchost.exe
O26-ifeo: tqat.exe-> ntsd-d
(To be continued)