Technical Information
- '%TEMP%\310714_o.exe'
- '%TEMP%\310714_o.exe' (downloaded from the Internet)
- %TEMP%\nsx2.tmp\nsWeb.dll
- %TEMP%\310714_o.exe
- %TEMP%\nsx2.tmp\inetc.dll
- 'go#.gl':80
- 'localhost':1039
- 'www.ha####portal.net':80
- go#.gl/rL7TPc
- www.ha####portal.net/310714d/310714_o.exe
- DNS ASK go#.gl
- DNS ASK www.ha####portal.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''