RootkitReveal日志好大,挑重点放
刚才点save就直接重起了~晕
C:\Documents and Settings\**\Local Settings\Temp\UQZBERSH.DL1 2006-1-9 14:00 100.00 KB Hidden from Windows API.
C:\Documents and Settings\**\Local Settings\Temp\UQZBERSH.LOG 2006-1-10 21:13 30.06 KB Hidden from Windows API.
C:\Documents and Settings\**\Local Settings\Temporary Internet Files\Content.IE5\1IR712TI\list[6].htm 2006-1-10 21:44 42.61 KB Hidden from Windows API.
C:\Documents and Settings\**\Local Settings\Temporary Internet Files\Content.IE5\4PIFOHEJ\list[3].htm 2006-1-10 17:59 42.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\**\Local Settings\Temporary Internet Files\Content.IE5\CMST9NLA\scrollsms[1].htm 2006-1-10 21:43 6.52 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\**\Local Settings\Temporary Internet Files\Content.IE5\CMST9NLA\scrollsms[2].htm 2006-1-10 21:44 6.52 KB Hidden from Windows API.
C:\Documents and Settings\**\My Documents\My Pictures\UQZBERSH.JPG 2006-1-10 18:18 45.83 KB Hidden from Windows API.
C:\Documents and Settings\**\Recent\uqzbersh.JPG.lnk 2006-1-10 18:20 600 bytes Hidden from Windows API.
C:\Documents and Settings\**\Recent\uqzbersh.rar.lnk 2006-1-10 18:17 275 bytes Hidden from Windows API.
C:\WINDOWS\SYSTEM32\DRIVERS\UQZBERSH.SYS 2006-1-9 13:26 11.50 KB Hidden from Windows API.
C:\WINDOWS\SYSTEM32\UQZBERSH.D1L 2006-1-9 13:26 38.18 KB Hidden from Windows API.
C:\WINDOWS\SYSTEM32\UQZBERSH.DLL 2006-1-9 13:26 24.00 KB Hidden from Windows API.