Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'taskmgs.exe' = '%ProgramFiles%\Internet Explorer\taskmgs.exe'
- %ProgramFiles%\Internet Explorer\taskmgs.exe
- %ProgramFiles%\Internet Explorer\taskmgs.exe
- <Full path to file>
- '15##.sogoui.com':1533
- 'any':0
- DNS ASK 15##.sogoui.com
- '%ProgramFiles%\Internet Explorer\taskmgs.exe'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> > nul