1:路径 C:\System Volume Information\_restore{EC0869E0-C517-4216-ACD3-C6EBF38CD94B}\rp388\a0079087.exe>>$TEMP\$TEMP\196.exe>>$TEMP 文件名 DoSSSetub.dll
2: 路径 C:\System Volume Information\_restore{EC0869E0-C517-4216-ACD3-C6EBF38CD94B}\rp388\a0079087.exe>>$TEMP\$TEMP\196.exe>>$TEMP 文件名 acpidisk.sys