Hbkernel32.sys, aliimz.sys, system.exe, koauolte.exe, cho22.tmp, etc. 1

Source: Internet
Author: User

Hbkernel32.sys, aliimz.sys, system.exe, koauolte.exe, cho22.tmp, etc. 1

 

Original endurer

1st

 

A friend said that his computer was automatically canceled after login. Please help me with the repair.

 

First try the security mode, and the fault persists.

 

This happens when userinit.exe is maliciously replaced.

 

Therefore, use the win peoptical disk to start and use fileinfoto check userinit.exe:

 

File Description: C:/Windows/system32/userinit.exe
Attribute: ---
Digital Signature: No
PE file: Yes
An error occurred while obtaining the file version information!
Creation Time:
Modification time:
Size: 1024 bytes, 1.0 kb
MD5: ab39ab1c7b0b5323dbedb336b0092307
Sha1: 4ef5f6ce1ccff37bdd8fa767c9b7dac9ac182421
CRC32: e6f5a115

Without Microsoft's digital signature, it was replaced, and the userinit.exe overwrite was restored from the Windows XP installation disc.

 

Restart your computer. This time you can log on normally.

Download the pe_xscan scan log analysis and find the following suspicious items:

Pe_xscan 08-08-01 by Purple endurer
17:18:48
Windows XP Service Pack 2 (5.1.2600)
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode
[System process] * 0
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 4:36:30
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 4:35:14
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/csrss.exe * 628 |
C:/Windows/system32/gdipro. dll | 4:31:45
C:/Windows/system32/sys05020.dll |
C:/Windows/system32/winlogon.exe * 652 |
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
System.exe * 1322
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Windows/system32/koauolte.exe * 1648
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/program files/Internet Explorer/iexplore.exe * 1832
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/program files/deepdo/deepdobar/favorite/favblock. dll
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
C:/Documents and Settings/Administrator/Local Settings/temp/svde. tmp * 2052
C:/Windows/system32/hbmhly. dll | 3:28:43
C:/Windows/system32/hbjxsj. dll |
C:/Windows/system32/hbwow. dll | 3:29:21
C:/Windows/system32/hbtl. dll |
C:/Windows/system32/hbqqxx. dll |
C:/Windows/system32/hbwd. dll | 3:29:40
C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
C:/Windows/system32/e0d39066. dll | 3:23:37
C:/Windows/system32/caba599d. dll | 3:16:34
C:/Windows/system32/9f684de8. dll |
C:/Windows/system32/12b02216. dll |
C:/Windows/system32/9ca963ca. dll | 2008-10-21 4: 36: 30l
C:/Windows/system32/08223b03. dll | 4:36:11
C:/Windows/system32/495271ca. dll | 4:35:52
C:/Windows/system32/8566f82e. dll | 4:35:33
C:/Windows/system32/58ff3024. dll | 2008-10-21 4: 35: 14l
C:/Windows/system32/b3721c07. dll | 4:34:55
C:/Windows/system32/da63e650. dll | 4:34:36
C:/Windows/system32/4bf9cba3. dll | 4:33:58
C:/Windows/system32/22d75360. dll | 4:33:39
C:/Windows/system32/7adc2ab1. dll | 4:33:20
C:/Windows/system32/ipv4a8c2. dll |
C:/Windows/system32/e4814792.dll | 4:32:23
C:/Windows/system32/c250cf20. dll |
C:/Windows/system32/a8fc611b. dll | 4:31:26
C:/Windows/system32/122b901e. dll |
C:/Windows/system32/d7c79813. dll | 4:30:48
C:/Windows/system32/de02f764. dll | 4:30:29
C:/Windows/system32/43acdcc5. dll | 3:30:37
C:/Windows/system32/e3104679.dll | 3:30:18
C:/Windows/system32/3d144530. dll | 3:29:59
O2-BHO favhook class-{CD8BFE70-5809-4C73-9EEE-E5672C2B79D7} = C:/program files/deepdo/deepdobar/favorite/favblock. dll | 7:48:13
O2-BHO-{F6A454AE-156A-415E-9F89-3795677A8A91} = C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
O4-HKLM/../run: [360ary] C:/Windows/system32/koauolte.exe
O4-HKLM/../run: [hbservice32] system.exe
O4-HKLM/../policies/Explorer/run: [nwiz] alivin.exe
O4-HKLM/../policies/Explorer/run: [svt23] C:/0001b531/685562
O4-HKLM/../policies/Explorer/run: [svt233] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/cho22.tmp
O20-appinit_dlls = hbmhly. DLL, hbtl. DLL, hbqqxx. DLL, hbwd. DLL, e0d39066. DLL, caba599d. DLL, 9f684de8. DLL, 12b02216. DLL, 9ca963ca. DLL, 08223b03. DLL, 495271ca. DLL, 8566f82e. DLL, 58ff3024. DLL, b3721c07. DLL, da63e650. DLL, 4bf9cba3. DLL, 22d75360. DLL, 7adc2ab1. DLL, ipv4a8c2. DLL, e4814792.dll, c250cf20. DLL, a8fc611b. DLL, 122b901e. DLL, d7c79813. DLL, de02f764. DLL, 43acdcc5. DLL, e3366679.dll, 3d144530. DLL, hbwow. DLL, hbjxsj. DLL
O23-service: 4901228 (4901228)-C:/Windows/system32/4901228.sys | 3:30:37 (manual)
O23-service: 5102a80 (5102a80)-C:/Windows/system32/5102a80. sys | (manual)
O23-service: 8882fa1 (8882fa1)-C:/Windows/system32/8882fa1. sys | 4:33:57 (manual)
O23-service: 8b52f47 (8b52f47)-C:/Windows/system32/8b52f47. sys | 3:29:59 (manual)
O23-service: 9fd8db (9fd8db)-C:/Windows/system32/9fd8db. sys | (manual)
O23-service: aecff9 (aecff9)-C:/Windows/system32/aecff9.sys | (manual)
O23-service: aliimz ()-system32/Drivers/aliimz. sys (manual)
O23-service: beep ()-C:/Windows/system32/Drivers/beep. sys | 12:28:16 (system)
O23-service: hbkernel32 (hbkernel32 driver)-system32/Drivers/hbkernel32.sys (pilot)
O24-shlexechook: [2]-{3d144530-4310847cc-b7c7-a3a9f3b9a6b2} = 3d144530. dll
O24-shlexechook: [B]-{E3367679-4775-4244-A62E-4CFE58FC850B} = e3366679.dll
O24-shlexechook: [8]-{43acdcc5-9009-4af4-b80a-93bc656ef298} = 43acdcc5. dll
O24-shlexechook: [f]-{DE02F764-C51A-4788-9597-D78ECC2AC08F} = de02f764. dll
O24-shlexechook: [3]-{D7C79813-9233-4AE0-832C-99B2E8019673} = d7c79813. dll
O24-shlexechook: [c]-{122b901e-493f-4ad9-bc69-7de8c3e52fcc} = 122b901e. dll
O24-shlexechook: [7]-{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57} = a8fc611b. dll
O24-shlexechook: [B]-{C250CF20-5F89-4310-9854-4BC261FB14FB} = c250cf20. dll
O24-shlexechook: [8]-{E4814792-EFA3-4C20-93D0-8B130A59F9A8} = e4814792.dll
O24-shlexechook: [0]-{4154a8c2-bef9-46c8-983a-a26a0030ec30} = 4154a8c2. dll
O24-shlexechook: [c]-{7adc2ab1-5c6a-4408-8241094863354af7c} = 7adc2ab1. dll
O24-shlexechook: [6]-{22d75360-199d-4f79-880d-82e766675f06} = 22d75360. dll
O24-shlexechook: [f]-{4bf9cba3-8dee-41a1-8bdb-fc28d30e949f} = 4bf9cba3. dll
O24-shlexechook: [B]-{DA63E650-537C-4042-87BB-9D19D844680B} = da63e650. dll
O24-shlexechook: [f]-{B3721C07-62B3-411A-9DC7-F5F27E3E21FF} = b3721c07. dll
O24-shlexechook: [e]-{58ff3024-8a83-4b1a-88e9-302f47646eee} = 58ff3024. dll
O24-shlexechook: [1]-{8566f82e-03a4-416e-aeac-66600d8881f1} = 8566f82e. dll
O24-shlexechook: [0]-{495271ca-d0c6-4052-abe6-5b01c73cdfb0} = 495271ca. dll
O24-shlexechook: [e]-{08223b03-1b38-4a33-a83a-a4d3cc1d6e4e} = 08223b03. dll
O24-shlexechook: [3]-{9ca963ca-417c-4089-b0ab-31380f90d7e3} = 9ca963ca. dll
O24-shlexechook: [1]-{12b02216-ac3f-42a7-8313-449771237061} = 12b02216. dll
O24-shlexechook: [1]-{9f684de8-3e87-4404-9033-e02a3dfd8b61} = 9f684de8. dll
O24-shlexechook: [f]-{CABA599D-5089-4865-9420-E41FA3C1F55F} = caba599d. dll
O24-shlexechook: [f]-{E0D39066-96D7-4891-8527-488ADAFCD60F} = e0d39066. dll
O24-shlexechook: []-{F6A454AE-156A-415E-9F89-3795677A8A91} = C:/program files/Internet Explorer/53u1ttme. 2ys | 3:23:48
O24-shlexechook: []-{5b77087d-ab76-4c22-b0a6-c34d1f438e55} = C:/program files/common files/Microsoft shared/msinfo/come_system.sys | 0:32:31
O26-ifeo: 360loader.exe-> svchost.exe
O26-ifeo: 360safebox.exe-> ntsd-d
O26-ifeo: ccenter.exe-> svchost.exe
O26-ifeo: icesword-> svchost.exe
O26-ifeo: kppmain.exe-> ntsd-d
O26-ifeo: ravmon.exe-> svchost.exe
O26-ifeo: ravmond.exe-> svchost.exe
O26-ifeo: ravstub.exe-> svchost.exe
O26-ifeo: ravtask.exe-> svchost.exe
O26-ifeo: rstray.exe-> svchost.exe
O26-ifeo: thunder5.exe-> svchost.exe
O26-ifeo: tqat.exe-> ntsd-d

(To be continued)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.