Technical Information
- '%TEMP%\nso3.tmp\SecurityScan_release_small.exe'
- '%TEMP%\nso3.tmp\checker.exe'
- '%TEMP%\nso3.tmp\SecurityScan_release_small.exe' (downloaded from the Internet)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\SecurityScan_release_small[1].exe
- %TEMP%\nso3.tmp\SecurityScan_release_small.exe
- %TEMP%\nso3.tmp\inetc.dll
- %TEMP%\nso2.tmp
- %TEMP%\nso3.tmp\checker.exe
- %TEMP%\nso3.tmp\SecurityScan_release_small.exe
- %TEMP%\nso3.tmp\inetc.dll
- %TEMP%\nso3.tmp\checker.exe
- 'dc###.4shared.com':80
- 'www.up###esrv.com':80
- dc###.4shared.com/download/Tfu7lKJV/SecurityScan_release_small.exe
- www.up###esrv.com/c/r/0/347778/
- DNS ASK dc###.4shared.com
- DNS ASK www.up###esrv.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'