sysukillvirus - 2006-4-6 16:16:00
发现HijackThis日志O23的提示最后两项:
O23 - Service: WintUPp - Unknown owner - C:\DOCUME~1\jbf\LOCALS~1\Temp\wt\wt.exe (file missing)
O23 - Service: Windows Installer Service (WIS) - Unknown owner - C:\WINNT\wis.exe
比较可能性比较大,有一项有(file missing),可能不是,不管了,一起干掉,先作了备份,
如果不是再干掉其它的.
找到病毒注册的系统服务名
注册表HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES
下的wintupp和wis
备份后删除,再把
c:\documents and settings\jbf\locals~1\temp
c:\documents and settings\jbf\locals~1\Temporary Internet Files
下的文件全部删除,这两个文件夹最令人讨厌,什么病毒都是进来到这里
下面是WIS的注册表内容,冒充微软的安装软件,日期却是最近的,我也不
知道是不是,反正干掉他后重启就不再发现病毒了.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WIS]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,00,77,00,\
69,00,73,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Windows Installer Service"
"ObjectName"="LocalSystem"
"Description"="软件安装服务,对符合微软软件安装规定*.msi的程序进行管理,中止可能会造成安装程序失败."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WIS\Security]
"Security"=hex:01,00,14,80,a0,00,00,00,ac,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,70,00,04,00,00,00,00,00,18,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,74,00,69,00,00,00,1c,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\
20,00,00,00,20,02,00,00,76,00,65,00,00,00,18,00,8d,01,02,00,01,01,00,00,00,\
00,00,05,0b,00,00,00,20,02,00,00,00,00,1c,00,fd,01,02,00,01,02,00,00,00,00,\
00,05,20,00,00,00,23,02,00,00,76,00,65,00,01,01,00,00,00,00,00,05,12,00,00,\
00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WIS\Enum]
"0"="Root\\LEGACY_WIS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
© 2000 - 2026 Rising Corp. Ltd.