Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'cmdd' = '%CommonProgramFiles%\system32\cmdd.exe'
- ClassName: 'FileMonClass' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- %CommonProgramFiles%\safemode
- 'www.ju####ende.gov.ar':80
- '10#.#5.170.246':80
- www.ju####ende.gov.ar/images/2009/02/exincor-copy2.jpg
- 10#.#5.170.246/clientes.php
- DNS ASK www.ju####ende.gov.ar
- '<IP-адрес в локальной сети>':1036