近一段时间以来,论坛上扫/贴SREng日志求助的朋友较多。
说实在的,读SREng、autoruns的日志——我比较怵(内容太多),这双本已高度近视的眼睛倍受摧残啊!
今天,得到一个“灰鸽子”样本,正好拿来举个例子。
将灰鸽子(setup.exe)种植到系统中,然后,分别用SREng、HijackThis1.99.1、autoruns三个常用日志工具扫系统日志。结果如下:
————————————————————
SREng日志:
2006-07-29,15:04:51
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
服务
[kavsvc / kavsvc]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
[TuneUp WinStyler Theme Service / TUWinStylerThemeSvc]
<"C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe"><TuneUp Software GmbH>
[FW Event Manager / UmxAgent]
<"C:\Program Files\Tiny Firewall Pro\UmxAgent.exe"><Computer Associates International, Inc.>
[FW Configuration Interpreter / UmxCfg]
<"C:\Program Files\Common Files\PFShared\UmxCfg.exe"><Computer Associates International, Inc.>
[FW User-Mode Helper / UmxFwHlp]
<"C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe"><Computer Associates International, Inc.>
[FW Live Update / UmxLU]
<"C:\Program Files\Common Files\PFShared\umxlu.exe"><Tiny Software, Inc.>
[FW Policy Manager / UmxPol]
<"C:\Program Files\Common Files\PFShared\UmxPol.exe"><Computer Associates International, Inc.>
________________________________
HijackThis v1.99.1日志:
Scan saved at 15:08:26, on 2006-7-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\Program Files\Internet Explorer\IEXPLORE.EXE
O23 - Service: Lan_manage - Unknown owner - C:\WINDOWS\Lan_manage.exe
_________________________________
autoruns日志:
HKLM\System\CurrentControlSet\Services
+ Lan_manage 内网管理服务,不可删 c:\windows\lan_manage.exe
——————————————————
三份日志中,只有SREng日志丢掉了“灰鸽子”的服务项。
这个例子再次说明:扫日志时,不要过度依赖某个工具。日志工具——需要灵活使用。
这只鸽子的样本来自:http://majun1988.netcx.net/hgz/setup.exe
如果不信,可以自己试试。