Technical Information
- '%TEMP%\310714_o.exe' (downloaded from the Internet)
- '%TEMP%\310714_o.exe'
- %TEMP%\nss2.tmp\nsWeb.dll
- %TEMP%\310714_o.exe
- %TEMP%\nss2.tmp\inetc.dll
- 'go#.gl':80
- 'localhost':1038
- 'www.ha####portal.net':80
- http://go#.gl/rL7TPc
- http://www.ha####portal.net/310714d/310714_o.exe
- DNS ASK go#.gl
- DNS ASK www.ha####portal.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''