又是HBservice32!
参考
http://bbs.ikaka.com/search.aspx?type=&searchid=36021 http://bbs.ikaka.com/showtopic-8562924.aspx操作前断网1、用
xdelbox删除文件:
C:\Autorun.inf
D:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
C:\WINDOWS\system32\HBW2I.dll
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\HBSO2.dll
C:\WINDOWS\system32\HBSHQ.dll
C:\WINDOWS\system32\HBKDXY.dll
C:\WINDOWS\system32\HBASKTAO.dll
C:\WINDOWS\system32\HBZHUXIAN.dll
C:\WINDOWS\system32\HBWOW.dll
C:\WINDOWS\system32\HBSOUL.dll
C:\WINDOWS\system32\HBDNF.dll
C:\WINDOWS\system32\HBTL.dll
C:\WINDOWS\system32\HBQQSG.dll
C:\WINDOWS\system32\HBYY.dll
C:\WINDOWS\system32\HBQQXX.dll
C:\WINDOWS\system32\appwinproc.dll
C:\Program Files\Internet Explorer\VitnNt64.987
C:\WINDOWS\system32\xsiscok.exe
C:\WINDOWS\system32\appwinproc.dll
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\drivers\NPF.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys
C:\WINDOWS\system32\Nskhelper2.sys
C:\WINDOWS\system32\NsPass4.sys
C:\WINDOWS\system32\NsPass3.sys
C:\WINDOWS\system32\NsPass1.sys
C:\WINDOWS\system32\NsPass2.sys
C:\WINDOWS\System32\drivers\kapaodn.sys
C:\WINDOWS\system32\drivers\HBKernel32.sys
2、重启后,用
XdelBox (http://www.kztechs.com/sreng/download.html)删除以下:
启动项目 -- 注册表之如下项删除
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HBService32><System.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{202AEF39-2BFA-4A5F-B526-390FDE0BC675}><C:\Program Files\Internet Explorer\VitnNt64.987>
启动项目 -- 服务-- 驱动程序之如下项删除
[HBKernel32 Driver / HBKernel32][Stopped/Boot Start]
<\SystemRoot\system32\drivers\HBKernel32.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass1.sys><N/A>
[NsPsDk02 / NsPsDk02][Running/Manual Start]
<\??\C:\WINDOWS\system32\NsPass2.sys><N/A>
[NsPsDk03 / NsPsDk03][Running/Manual Start]
<\??\C:\WINDOWS\system32\NsPass3.sys><N/A>
[NsPsDk04 / NsPsDk04][Running/Manual Start]
<\??\C:\WINDOWS\system32\NsPass4.sys><N/A>
[NsRk1 / NsRk1][Running/Manual Start]
<\??\C:\WINDOWS\system32\Nskhelper2.sys><N/A>
[wmpobj / wmpobj][Running/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys><N/A>
[WinPcap Packet Driver (NPF) / NPF][Stopped/Manual Start]
<system32\drivers\NPF.sys><N/A>
系统修复-- 浏览器加载项之如下项删除:
{202AEF39-2BFA-4A5F-B526-390FDE0BC675} <C:\Program Files\Internet Explorer\VitnNt64.987, N/A>
3、
映像劫持修复4、最后尝试使用杀毒软件全盘杀毒!