|
 |
|
Remove Trojan.Hibik
Hibik trojan is typical spyware. It works in a background to collect sensitive information and later it sends the gathered data to a remote server. Hibik also causes system crashes and slow computer performance by creating corrupted files in Windows directories. It may download and install additional malwares on board compromised machine.
Hibik is detected as Infostealer.Hibik.A by some security tools. The main function of Hibik trojan is gathering various data and delivering it to a remote attacker. This makes Hibik a huge threat to person’s privacy. The trojan is difficult to remove manually because it hides under different randomly named files.
Hibik is Dangerous
Hibik is a Trojan parasite
Hibik may display fake security & messages
Hibik may display numerous annoying advertisements
Hibik may be remotely controlled by a malicious person
Hibik may spread additional spyware
Hibik may repair its files, spread or update by itself
Hibik may prove difficult or impossible to remove
Hibik violates your privacy and compromises your security
To Remove this trojan manually:
Remove these Hibik files:
System\HBQQXX.dll
HBmhly.dll
HB1000Y.dll
HBWOOOL.dll
HBXY2.dll
HBJXSJ.dll
HBSO2.dll
HBFS2.dll
HBXY3.dll
HBSHQ.dll
HBFY.dll
HBWULIN2.dll
HBW2I.dll
BKDXY.dll
HBWORLD2.dll
HBASKTAO.dll
HBZHUXIAN.dll
HBWOW.dll
HBZERO.dll
HBBO.dll
HBCONQUER.dll
HBSOUL.dll
HBCHIBI.dll
HBDNF.dll
HBWARLORDS.dll
HBTL.dll
HBPICKCHINA.dll
HBCT.dll
HBGC.dll
HBHM.dll
HBHX2.dll
HBQQHX.dll
HBTW2.dll
HBQQSG.dll
HBQQFFO.dll
HBZT.dll
HBMIR2.dll
HBRXJH.dll
HBYY.dll
HBMXD.dll
HBSQ.dll
HBTJ.dll
HBFHZL.dll
HBWLQX.dll
HBLYFX.dll
HBR2.dll
HBCHD.dll
HBTZ.dll
HBQQXX.dll
HBWD.dll
HBZG.dll
HBPPBL.dll
HBXMJ.dll
HBJTLQ.dll
HBQJSJ.dll
Remove these Hibik Registry Entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HBKERNEL32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HBKernel32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HBKernel32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HBKERNEL32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBKernel32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"HBService32" = "SYSTEM.EXE"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"AppInit_DLLs" = "48 42 6D 68 6C 79 2E 64 6C 6C 2C 48 42 31 30 30 30 59 2E 64 6C 6C 2C 48 42 57 4F 4F 4F 4C 2E 64 6C 6C 2C 48 42 58 59 32 2E 64 6C 6C 2C 48 42 4A 58 53 4A 2E 64 6C 6C 2C 48 42 53 4F 32 2E 64 6C 6C 2C 48 42 46 53 32 2E 64 6C 6C 2C 48 42 58 59 33 2E 64 6C 6C 2C 48 42 53 48 51 2E 64 6C 6C 2C 48 42 46 59 2E 64 6C 6C 2C 48 42 57 55 4C 49 4E 32 2E 64 6C 6C 2C 48 42 57 32 49 2E 64 6C 6C 2C 48 42 4B 44 58 59 2E 64 6C 6C 2C 48 42 57 4F 52 4C 44 32 2E 64 6C 6C 2C 48 42 41 53 4B 54 41 4F 2E 64 6C 6C 2C 48 42 5A 48 55 58 49 41 4E 2E 64 6C 6C 2C 48 42 57 4F 57 2E 64 6C 6C 2C 48 42 5A 45 52 4F 2E 64 6C 6C 2C 48 42 42 4F 2E 64 6C 6C 2C 48 42 43 4F 4E 51 55 45 52 2E 64 6C 6C 2C 48 42 53 4F 55 4C 2E 64 6C 6C 2C 48 42 43 48 49 42 49 2E 64 6C 6C 2C 48 42 44 4E 46 2E 64 6C 6C 2C 48 42 57 41 52 4C 4F 52 44 53 2E 64 6C 6C 2C 48 42 54 4C 2E 64 6C 6C 2C 48 42 50 49 43 4B 43 48 49 4E 41 2E 64 6C 6C 2C 48 42 43 54 2E 64 6C 6C 2C 48 42 47 43 2E 64 6C 6C 2C 48 42 48 4D 2E 64 6C 6C 2C 48 42 48 58 32 2E 64 6C 6C 2C 48 42 51 51 48 58 2E 64 6C 6C 2C 48 42 54 57 32 2E 64 6C 6C 2C 48 42 51 51 53 47 2E 64 6C 6C 2C 48 42 51 51 46 46 4F 2E 64 6C 6C 2C 48 42 5A 54 2E 64 6C 6C 2C 48 42 4D 49 52 32 2E 64 6C 6C 2C 48 42 52 58 4A 48 2E 64 6C 6C 2C 48 42 59 59 2E 64 6C 6C 2C 48 42 4D 58 44 2E 64 6C 6C 2C 48 42 53 51 2E 64 6C 6C 2C 48 42 54 4A 2E 64 6C 6C 2C 48 42 46 48 5A 4C 2E 64 6C 6C 2C 48 42 57 4C 51 58 2E 64 6C 6C 2C 48 42 4C 59 46 58 2E 64 6C 6C 2C 48 42 52 32 2E 64 6C 6C 2C 48 42 43 48 44 2E 64 6C 6C 2C 48 42 54 5A 2E 64 6C 6C 2C 48 42 51 51 58 58 2E 64 6C 6C 2C 48 42 57 44 2E 64 6C 6C 2C 48 42 5A 47 2E 64 6C 6C 2C 48 42 50 50 42 4C 2E 64 6C 6C 2C 48 42 58 4D 4A 2E 64 6C 6C 2C 48 42 4A 54 4C 51 2E 64 6C 6C 2C 48 42 51 4A 53 4A 2E 64 6C 6C"
|
| | |
 |
|
|