Technical Information
- svchost.exe
- %TEMP%\svchost.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\72nooqqm\service[1].htm
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\9yuishes\service[1].htm
- 'drive.usercontent.google.com':443
- '15#.#4.209.95':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6a##############
- http://15#.#4.209.95/success?su#############################
- 'drive.usercontent.google.com':443
- DNS ASK drive.usercontent.google.com
- '%TEMP%\svchost.exe'