Technical Information
- [HKLM\System\CurrentControlSet\Services\qyoftgio] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\qyoftgio] 'ImagePath' = '%WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe /d"<Full path to file>"'
- [HKLM\SYSTEM\CurrentControlSet\services\qyoftgio] 'ImagePath' = '%WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe'
- 'qyoftgio' %WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe /d"<Full path to file>"
- 'qyoftgio' %WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\SysWOW64\qyoftgio' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\wtmbfdfl.exe
- from %TEMP%\wtmbfdfl.exe to %WINDIR%\syswow64\qyoftgio\wtmbfdfl.exe
- 'mi##########m.mail.protection.outlook.com':25
- '14#.0.68.13':465
- DNS ASK mi##########m.mail.protection.outlook.com
- '%WINDIR%\syswow64\qyoftgio\wtmbfdfl.exe' /d"<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\qyoftgio\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\wtmbfdfl.exe" %WINDIR%\SysWOW64\qyoftgio\
- '%WINDIR%\syswow64\sc.exe' create qyoftgio binPath= "%WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "P2P Support"
- '%WINDIR%\syswow64\sc.exe' description qyoftgio "Internet Mobile Support"
- '%WINDIR%\syswow64\sc.exe' start qyoftgio
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\qyoftgio\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\wtmbfdfl.exe" %WINDIR%\SysWOW64\qyoftgio\' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create qyoftgio binPath= "%WINDIR%\SysWOW64\qyoftgio\wtmbfdfl.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "P2P Support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' description qyoftgio "Internet Mobile Support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start qyoftgio' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (with hidden window)