Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'windows' = '%TEMP%\getpassword.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{84B0238E-FE3D-F634-DD73-68BF5BE0D402}] 'StubPath' = '%TEMP%\getpassword.exe'
- '%TEMP%\getpassword.exe'
- %WINDIR%\Explorer.EXE
- msnmsgr.exe
- %TEMP%\getpassword.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut1.tmp
- 'do######file.redirectme.net':3460
- DNS ASK do######file.redirectme.net