Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SQL Server Sock] 'Start' = '00000002'
- '<SYSTEM32>\sc.exe' delete "Remote Procedure Capter"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\1.tmp.bat"
- %WINDIR%\SQLServer.exe
- %TEMP%\1.tmp.bat
- '61.##2.227.15':6666