Technical Information
- [<HKLM>\System\CurrentControlSet\Services\hfnieyyv] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\hfnieyyv] 'ImagePath' = '%WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe /d"<Full path to file>"'
- [<HKLM>\SYSTEM\CurrentControlSet\services\hfnieyyv] 'ImagePath' = '%WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe'
- 'hfnieyyv' %WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe /d"<Full path to file>"
- 'hfnieyyv' %WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\SysWOW64\hfnieyyv' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\nxfsmwrf.exe
- from %TEMP%\nxfsmwrf.exe to %WINDIR%\syswow64\hfnieyyv\nxfsmwrf.exe
- 'mi##########m.mail.protection.outlook.com':25
- '10#.#48.137.133':465
- DNS ASK mi##########m.mail.protection.outlook.com
- '%WINDIR%\syswow64\hfnieyyv\nxfsmwrf.exe' /d"<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\hfnieyyv\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\nxfsmwrf.exe" %WINDIR%\SysWOW64\hfnieyyv\' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create hfnieyyv binPath= "%WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "P2P Support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' description hfnieyyv "Internet Mobile Support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start hfnieyyv' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\hfnieyyv\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\nxfsmwrf.exe" %WINDIR%\SysWOW64\hfnieyyv\
- '%WINDIR%\syswow64\sc.exe' create hfnieyyv binPath= "%WINDIR%\SysWOW64\hfnieyyv\nxfsmwrf.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "P2P Support"
- '%WINDIR%\syswow64\sc.exe' description hfnieyyv "Internet Mobile Support"
- '%WINDIR%\syswow64\sc.exe' start hfnieyyv
- '%WINDIR%\syswow64\svchost.exe'