Technical Information
- [<HKLM>\System\CurrentControlSet\Services\mtsvgyla] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mtsvgyla] 'ImagePath' = '%WINDIR%\SysWOW64\mtsvgyla\gcuurgft.exe /d"<Full path to file>"'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %TEMP%\gcuurgft.exe
- from %TEMP%\gcuurgft.exe to %WINDIR%\syswow64\mtsvgyla\gcuurgft.exe
- '%WINDIR%\syswow64\mtsvgyla\gcuurgft.exe' /d"<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\mtsvgyla\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\gcuurgft.exe" %WINDIR%\SysWOW64\mtsvgyla\' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create mtsvgyla binPath= "%WINDIR%\SysWOW64\mtsvgyla\gcuurgft.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' description mtsvgyla "wifi internet conection"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start mtsvgyla' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\mtsvgyla\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\gcuurgft.exe" %WINDIR%\SysWOW64\mtsvgyla\
- '%WINDIR%\syswow64\sc.exe' create mtsvgyla binPath= "%WINDIR%\SysWOW64\mtsvgyla\gcuurgft.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"
- '%WINDIR%\syswow64\sc.exe' description mtsvgyla "wifi internet conection"
- '%WINDIR%\syswow64\sc.exe' start mtsvgyla