Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost.exe' = '%ProgramFiles%\Internet Explorer\svchost.exe'
- '%ProgramFiles%\Internet Explorer\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> > nul
- %ProgramFiles%\Internet Explorer\svchost.exe
- %ProgramFiles%\Internet Explorer\svchost.exe
- '35##.sogoui.com':3500
- DNS ASK 35##.sogoui.com