Техническая информация
- [<HKLM>\SYSTEM\CONTROLSET003\Services\gbkrqq] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\gbkrqq] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\gbkrqq] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k gbkrqq
- <SYSTEM32>\ijezda.com
- <SYSTEM32>\00049a9c.sys
- 'ta###.3322.org':8001
- DNS ASK ta###.3322.org