Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XXXXXX12546683' = '%WINDIR%\XXXXXX12546683\svchsot.exe'
- <SYSTEM32>\12546683
- %WINDIR%\XXXXXX12546683\svchsot.exe
- 'hk#####eng.gnway.net':80
- DNS ASK hk#####eng.gnway.net
- ClassName: '' WindowName: '??????????????'