Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'cmdd' = '%CommonProgramFiles%\system32\cmdd.exe'
- ClassName: 'FileMonClass' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- %CommonProgramFiles%\safemode
- 'www.ju####ende.gov.ar':80
- '10#.##.#70.246clientes.php':80
- www.ju####ende.gov.ar/images/2009/02/11.jpg
- 10#.##.#70.246clientes.php/
- DNS ASK www.ju####ende.gov.ar
- DNS ASK 10#.##.#70.246clientes.php