瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 HBmhly.dll 病毒导致我的机器出问题。见附件。

1   1  /  1  页   跳转

[求助] HBmhly.dll 病毒导致我的机器出问题。见附件。

HBmhly.dll 病毒导致我的机器出问题。见附件。

我的机器莫名其妙地起机时加载很多没见过的dll文件,查了是病毒,但瑞星删不掉。
用system repair engineer 检查了,得到个日志,请高手给诊断一下。

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Maxthon; QQDownload 1.7; .NET CLR 1.1.4322)

附件附件:

文件名:SREngLOG.log
下载次数:80
文件类型:application/octet-stream
文件大小:
上传时间:2008-9-20 12:49:23
描述:log

分享到:
gototop
 

回复:HBmhly.dll 病毒导致我的机器出问题。见附件。

操作前强烈要求先断网
1.建议使用XDelBox删除以下文件:(Xdelbox1.7下载地址:http://www.qispace.com.cn/read.php/1.htm    的工具19或http://www.dodudou.com/down/index.php?dirpath=./01.原创软件&order=0)
使用说明:先勾选抑制再生删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除(不论文件是否存在,继续操作重启删除
)
,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。


c:\windows\system32\drivers\1wbm712t6r.sys
c:\4e2aca1c9a3707f3.dat
c:\documents and settings\all users\application data\microsoft\media player\obj\wmpobj.sys
c:\windows\system32\drivers\hbkernel32.sys
c:\windows\system32\drivers\fwlqgj.sys
c:\windows\system32\com\yndlolryhvlv.dll
c:\windows\system32\aaoifxpz.dll
c:\windows\system32\zlnzwxfx.dll
c:\windows\system32\iemwsyyq.dll
c:\windows\system32\sfohqeaz.dll
c:\windows\system32\bgpkxdch.dll
c:\windows\system32\orlagkxa.dll
c:\windows\system32\ouxnjoev.dll
c:\windows\system32\rxnmhrmy.dll
c:\windows\system32\kzraewrh.dll
C:\WINDOWS\system32\System.exe
c:\windows\system32\adsntzt.dll
c:\windows\system32\ksuserfy.dll
c:\windows\system32\imgutilhx2.dll
c:\windows\system32\tscfgwmijxsj.dll
c:\windows\system32\jdsaex.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\mpwdeapi.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\yzztimsn.dll
c:\windows\system32\comuidsg.dll
c:\windows\system32\mndhddwd.dll
c:\windows\system32\slbiopfs2.dll
c:\windows\system32\scrruncqsj.dll
c:\windows\system32\apsgdjba.dll
c:\windows\system32\avicapwm.dll
c:\windows\system32\wtsapi32yt2.dll
c:\windows\system32\mndsfsrv.dll
c:\windows\system32\dpvvoxmh.dll
c:\windows\system32\kbdswjr.dll
c:\windows\system32\bootvidgj.dll
c:\windows\system32\catsrvwl.dll
c:\windows\system32\zycbdime.dll
c:\windows\system32\zyzxjime.dll
c:\windows\system32\lofsdjbo.dll
c:\windows\system32\apfocdet.dll
c:\windows\system32\nhmxcjkl.dll
c:\windows\system32\skqncbib.dll
c:\windows\system32\ozfyebyt.dll
c:\windows\system32\tisqatyu.dll
c:\windows\system32\zywmfime.dll
c:\windows\system32\ietzbpaq.dll
c:\windows\system32\cdwsbkop.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\sgdewg.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\hbct.dll
c:\windows\system32\hbjxsj.dll
c:\windows\system32\hbkdxy.dll
c:\windows\system32\hbmhly.dll
c:\windows\system32\hbqqffo.dll
c:\windows\system32\hbsoul.dll
c:\windows\system32\hbtl.dll
c:\windows\system32\hbtw2.dll
c:\windows\system32\tphklock.dll
c:\windows\system32\aavtrtbe.dll
c:\windows\system32\amgyuyig.dll
c:\windows\system32\axrgpxck.dll
c:\windows\system32\fyzvlvcy.dll
c:\windows\system32\hbqqsg.dll
c:\windows\system32\qmdovhgy.dll
c:\windows\system32\wbpenild.dll
c:\windows\system32\wfpfebwq.dll
c:\windows\system32\wqashgvs.dll

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[aaoifxpz.dll]    <C:\WINDOWS\system32\aaoifxpz.dll>
[zlnzwxfx.dll]    <C:\WINDOWS\system32\zlnzwxfx.dll>
[iemwsyyq.dll]    <C:\WINDOWS\system32\iemwsyyq.dll>
[sfohqeaz.dll]    <C:\WINDOWS\system32\sfohqeaz.dll>
[bgpkxdch.dll]    <C:\WINDOWS\system32\bgpkxdch.dll>
[orlagkxa.dll]    <C:\WINDOWS\system32\orlagkxa.dll>
[ouxnjoev.dll]    <C:\WINDOWS\system32\ouxnjoev.dll>
[rxnmhrmy.dll]    <C:\WINDOWS\system32\rxnmhrmy.dll>
[kzraewrh.dll]    <C:\WINDOWS\system32\kzraewrh.dll>
[qmdovhgy.dll]    <C:\WINDOWS\system32\aaoifxpz.dll>
[axrgpxck.dll]    <C:\WINDOWS\system32\iemwsyyq.dll>
[aavtrtbe.dll]    <C:\WINDOWS\system32\sfohqeaz.dll>
[amgyuyig.dll]    <C:\WINDOWS\system32\bgpkxdch.dll>
[wfpfebwq.dll]    <C:\WINDOWS\system32\orlagkxa.dll>
[wqashgvs.dll]    <C:\WINDOWS\system32\ouxnjoev.dll>
[wbpenild.dll]    <C:\WINDOWS\system32\rxnmhrmy.dll>
[fyzvlvcy.dll]    <C:\WINDOWS\system32\kzraewrh.dll>
[ptgtfwqg.dll]    <C:\WINDOWS\system32\aaoifxpz.dll>
[aagnkxsa.dll]    <C:\WINDOWS\system32\iemwsyyq.dll>
[qweiuxfe.dll]    <C:\WINDOWS\system32\sfohqeaz.dll>
[kuxroyks.dll]    <C:\WINDOWS\system32\bgpkxdch.dll>
[apvnqgxw.dll]    <C:\WINDOWS\system32\orlagkxa.dll>
[mazdhfsq.dll]    <C:\WINDOWS\system32\ouxnjoev.dll>
[wiemikeo.dll]    <C:\WINDOWS\system32\rxnmhrmy.dll>
[twainyy.dll]    <C:\WINDOWS\system32\aaoifxpz.dll>
[xolehlpjh.dll]    <C:\WINDOWS\system32\iemwsyyq.dll>
[nwapi32dj.dll]    <C:\WINDOWS\system32\bgpkxdch.dll>
[dispexcb.dll]    <C:\WINDOWS\system32\rxnmhrmy.dll>
[lweurqhx.dll]    <C:\WINDOWS\system32\kzraewrh.dll>
[{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}]    <C:\WINDOWS\system32\aaoifxpz.dll>
[{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}]    <C:\WINDOWS\system32\orlagkxa.dll>
[{20A0D061-7950-4B34-8E47-38D835DD9E6B}]    <20A0D061.dll>
[{F0930A2F-D971-4828-8209-B7DFD266ED44}]    <C:\WINDOWS\system32\iemwsyyq.dll>
[{DA56B183-A731-402b-9235-2CB8803E212D}]    <C:\WINDOWS\system32\zlnzwxfx.dll>
[{D3112B69-A745-4805-874E-ABD480EA1299}]    <C:\WINDOWS\system32\sfohqeaz.dll>
[{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}]    <C:\WINDOWS\system32\bgpkxdch.dll>
[{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}]    <C:\WINDOWS\system32\ouxnjoev.dll>
[{76D44356-B494-443a-BEDC-AA68DE4255E6}]    <C:\WINDOWS\system32\rxnmhrmy.dll>
[{71A78CD4-E470-4a18-8457-E0E0283DD507}]    <C:\WINDOWS\system32\kzraewrh.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}]    <>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]    <>
[{14698742-2059-3025-9058-954023874141}]    <>
[{70AF1289-F140-A140-D012-C1458759FC07}]    <>
[{91698482-6555-3666-1222-954784129019}]    <>
[{35671234-7890-ABCD-CDEF-567801237653}]    <>
[{83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38}]    <>
[{50940F85-F015-14F1-A05F-F69858AC6D05}]    <>
[{2D698451-2015-6358-9871-2015987452D2}]    <>
[{22596546-2036-9451-6058-658402589722}]    <>
[{528DF602-9541-A985-210A-984A698C6F25}]    <>
[{81954FAC-1023-154F-895A-1458258AD818}]    <>
[{6A041F13-A111-12A3-B0CF-F99818AA68A6}]    <>
[{4629FF4F-ACDB-5C90-A098-FACB3456A264}]    <>
[{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}]    <>
[HBService32]    <System.exe>
[{00010001-0001-0001-0001-00010001BB15}]    <C:\WINDOWS\system32\adsntzt.dll>
[{00130013-0013-0013-0013-00130013BB15}]    <C:\WINDOWS\system32\ksuserfy.dll>
[{00300030-0030-0030-0030-00300030BB15}]    <C:\WINDOWS\system32\imgutilhx2.dll>
[{00330033-0033-0033-0033-00330033BB15}]    <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[{B29583D8-033A-4B9F-8553-7C5458F3FB8E}]    <C:\WINDOWS\system32\jdsaex.dll>
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}]    <C:\WINDOWS\system32\tdffdl.dll>
[{7C8D1401-A58D-A81C-CD24-A5915C4517C7}]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[{55694105-5108-9405-3695-954187462155}]    <C:\WINDOWS\system32\mpwdeapi.dll>
[{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}]    <C:\WINDOWS\system32\cliconfgzx.dll>
[{9490415F-65F8-B5C5-D8BA-9405FB120549}]    <C:\WINDOWS\system32\yzztimsn.dll>
[{898E02AB-9372-4a2c-9C4A-FFE1AF61097F}]    <C:\WINDOWS\system32\comuidsg.dll>
[{4C648541-1025-9650-9057-6541258720C4}]    <C:\WINDOWS\system32\mndhddwd.dll>
[{EB9660D8-E1CD-4ff0-B4A9-00CD907F928A}]    <C:\WINDOWS\system32\slbiopfs2.dll>
[{00240024-0024-0024-0024-00240024BB15}]    <C:\WINDOWS\system32\scrruncqsj.dll>
[{4FD45A54-9875-698F-E56E-65102358FDF4}]    <C:\WINDOWS\system32\apsgdjba.dll>
[{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}]    <C:\WINDOWS\system32\avicapwm.dll>
[{BA4B5EBD-AB43-4c2b-84F5-F1AD85E79E4A}]    <C:\WINDOWS\system32\wtsapi32yt2.dll>
[{67FD640A-158F-48AC-FD14-1597F14A9776}]    <C:\WINDOWS\system32\mndsfsrv.dll>
[cliconfgzx.dll]    <C:\WINDOWS\system32\cliconfgzx.dll>
[dpvvoxmh.dll]    <C:\WINDOWS\system32\dpvvoxmh.dll>
[kbdswjr.dll]    <C:\WINDOWS\system32\kbdswjr.dll>
[bootvidgj.dll]    <C:\WINDOWS\system32\bootvidgj.dll>
[catsrvwl.dll]    <C:\WINDOWS\system32\catsrvwl.dll>
[adsntzt.dll]    <C:\WINDOWS\system32\adsntzt.dll>
[ksuserfy.dll]    <C:\WINDOWS\system32\ksuserfy.dll>
[imgutilhx2.dll]    <C:\WINDOWS\system32\imgutilhx2.dll>
[tscfgwmijxsj.dll]    <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[comuidsg.dll]    <C:\WINDOWS\system32\comuidsg.dll>
[slbiopfs2.dll]    <C:\WINDOWS\system32\slbiopfs2.dll>
[{4A698102-5904-AFD0-20DF-CD1A65829CA4}]    <C:\WINDOWS\system32\zycbdime.dll>
[scrruncqsj.dll]    <C:\WINDOWS\system32\scrruncqsj.dll>
[avicapwm.dll]    <C:\WINDOWS\system32\avicapwm.dll>
[wtsapi32yt2.dll]    <C:\WINDOWS\system32\wtsapi32yt2.dll>
[{AA59145F-315D-BC23-AC1F-145DF81A34AA}]    <C:\WINDOWS\system32\zyzxjime.dll>
[{470165F1-9F65-569F-F895-F14F58F41074}]    <C:\WINDOWS\system32\lofsdjbo.dll>
[{3E035987-F585-68D1-AC28-98FA58E459E3}]    <C:\WINDOWS\system32\apfocdet.dll>
[{37AC9076-C898-B098-D098-A18319080973}]    <C:\WINDOWS\system32\nhmxcjkl.dll>
[{32023698-6984-8541-9654-698745012523}]    <C:\WINDOWS\system32\skqncbib.dll>
[{5A069845-2036-6084-9054-6087502480A5}]    <C:\WINDOWS\system32\ozfyebyt.dll>
[{18093456-9012-4568-9076-908765467181}]    <C:\WINDOWS\system32\tisqatyu.dll>
[{6319A1F1-9410-9654-3201-345FFA349136}]    <C:\WINDOWS\system32\zywmfime.dll>
[{29109876-7619-9101-7012-901938475192}]    <C:\WINDOWS\system32\ietzbpaq.dll>
[{2A095412-A568-B258-C587-D148E148F0A2}]    <C:\WINDOWS\system32\cdwsbkop.dll>
[{00050005-0005-0005-0005-00050005BB15}]    <C:\WINDOWS\system32\cliconfgzx.dll>
[{00070007-0007-0007-0007-00070007BB15}]    <C:\WINDOWS\system32\dpvvoxmh.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}]    <C:\WINDOWS\system32\jfrwdh.dll>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}]    <C:\WINDOWS\system32\sgdewg.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}]    <C:\WINDOWS\system32\ddserh.dll>

注意该项[AppInit_DLLs]修改:把<HBCT.dll,HBQQSG.dll,kmon.dll>修改为<komn.dll>

    启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[Secondary Logon / seclogon]    <C:\WINDOWS\System32\svchost.exe -k netsvcs-->c:\windows\system32\com\yndlolryhvlv.dll>

    启动项目 -- 服务-- 驱动程序之如下项删除:
(选中有问题的驱动/服务后,点"删除服务",点"设置"按钮即可。注意弹出的窗口中要点"否NO"才是确认删除服务)


[1wbm712t6r / 1wbm712t6r]    <\??\C:\WINDOWS\system32\drivers\1wbm712t6r.sys>
[4e2aca1c9a3707f3 / 4e2aca1c9a3707f3]    <\??\C:\4e2aca1c9a3707f3.dat>
[wmpobj / wmpobj]    <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys>
[HBKernel32 Driver / HBKernel32]    <\SystemRoot\system32\DRIVERS\HBKernel32.sys>
[fwlqg / fwlqgj]    <\SystemRoot\System32\DRIVERS\fwlqgj.sys>
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT