Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\srservice] 'Start' = '00000002'
- '<SYSTEM32>\dwprssoz.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\delself0.bat
- %TEMP%\delself0.bat
- <SYSTEM32>\dwprssoz.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
- 'jj###6.3322.org':111
- DNS ASK jj###6.3322.org