Technical Information
- [HKCU\Environment] 'UserInitMprLogonScript' = '%LOCALAPPDATA%\iusb3mon.exe'
- <SYSTEM32>\tasks\mytaskname
- User Account Control (UAC)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\iusb3mon.exe' -Force"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionProcess '<File name>.exe' -Force"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Local\ziliao.jpg'"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\iusb3mon.exe'"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionProcess 'iusb3mon.exe'"
- %WINDIR%\syswow64\prevhost.exe
- %WINDIR%\syswow64\dllhost.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.3.dll
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irimg1.bmp
- %TEMP%\_ir_sf_temp_0\irimg1.jpg
- nul
- %LOCALAPPDATA%\iusb3mon.exe
- %LOCALAPPDATA%\local\ziliao.jpg
- %ProgramFiles%\your product\mumu_ä£äâæ÷.exe
- %TEMP%\7zf63f40f8\config.ini
- %TEMP%\7zf63f40f8\skin.zip
- %TEMP%\7zf63f40f8\nemu-downloader.exe
- %TEMP%\7zf63f40f8\mumudownloader.exe
- %TEMP%\7zf63f40f8\msvcp_win.dll
- %TEMP%\7zf63f40f8\msvcrt.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-private-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\7zf63f40f8\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\7zf63f40f8\crashpad_handler.exe
- %TEMP%\7zf63f40f8\msvcp140.dll
- %TEMP%\7zf63f40f8\sentry.dll
- %TEMP%\7zf63f40f8\ucrtbase.dll
- %TEMP%\7zf63f40f8\vcruntime140.dll
- %TEMP%\7zf63f40f8\7z.exe
- %TEMP%\7zf63f40f8\7z.dll
- %TEMP%\7zf63f40f8\colaboxchecker.exe
- %TEMP%\7zf63f40f8\hypervchecker.exe
- %LOCALAPPDATA%\cx002_group_remarks.dat.tmp
- %TEMP%\nemux-downloader-fbd96a53-b854-43a4-869a-1e5e9ff3f2ef.log
- %LOCALAPPDATA%\nemuserver\.sentry-native\e25f4cc9-552a-4b12-5e3e-a85cfab1d13a.run\__sentry-event
- %LOCALAPPDATA%\nemuserver\.sentry-native\settings.dat
- %LOCALAPPDATA%\nemuserver\.sentry-native\e25f4cc9-552a-4b12-5e3e-a85cfab1d13a.run\session.json
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- %TEMP%\sedebugprivilege.inf
- %TEMP%\sedebugprivilege.log
- %TEMP%\sedebugprivilege.jfm
- %TEMP%\sedebugprivilege.sdb
- %LOCALAPPDATA%\bba080ebee3f33e1585fcf4948f47839.data
- %TEMP%\winring0.cat
- %TEMP%\winring0.inf
- %TEMP%\winring0.sys
- %TEMP%\winring0x64.cat
- %TEMP%\winring0x64.inf
- %TEMP%\winring0x64.sys
- %TEMP%\7zf63f40f8\run-checker-log\baseboard-140058441231673720.log.log
- %TEMP%\7zf63f40f8\baseboard
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irimg1.bmp
- %TEMP%\_ir_sf_temp_0\irimg1.jpg
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.3.dll
- %TEMP%\sedebugprivilege.inf
- from %WINDIR%\security\database\edb.log to %WINDIR%\security\database\edb00001.log
- from %LOCALAPPDATA%\cx002_group_remarks.dat.tmp to %LOCALAPPDATA%\cx002_group_remarks.dat
- 're####.#umu.nie.netease.com':443
- 'yy###suyt.net':25450
- 'x1.#.lencr.org':80
- 'ap#.####.nie.netease.com':443
- http://x1.#.lencr.org/
- 're####.#umu.nie.netease.com':443
- 'yy###suyt.net':25450
- 'ap#.####.nie.netease.com':443
- DNS ASK re####.#umu.nie.netease.com
- DNS ASK yy###suyt.net
- DNS ASK x1.#.lencr.org
- DNS ASK ap#.####.nie.netease.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Q360SafeMonClass' WindowName: ''
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:5226434 "__IRAFN:<Full path to file>" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-4226853953-3309226944-3078887307-1000"
- '%LOCALAPPDATA%\iusb3mon.exe'
- '%ProgramFiles%\your product\mumu_ä£äâæ÷.exe'
- '%TEMP%\7zf63f40f8\nemu-downloader.exe'
- '%TEMP%\7zf63f40f8\crashpad_handler.exe' --no-rate-limit --database=%LOCALAPPDATA%\NemuServer\.sentry-native --metrics-dir=%LOCALAPPDATA%\NemuServer\.sentry-native --url=https://sentry.netease.com:443/api/324/minidump/?sentry_client=s...
- '%TEMP%\7zf63f40f8\colaboxchecker.exe' checker /baseboard
- '%TEMP%\7zf63f40f8\hypervchecker.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\iusb3mon.exe' -Force" >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionProcess '<File name>.exe' -Force" >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c timeout /t 2 /nobreak >nul
- '<SYSTEM32>\timeout.exe' /t 2 /nobreak
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "$temp = $env:TEMP;$inf = Join-Path $temp 'SeDebugPrivilege.inf';$sdb = Join-Path $temp 'SeDebugPrivilege.sdb';$log = Join-Path $temp 'SeDebugPrivilege.log';$b64 = '//5bAFUA...
- '%WINDIR%\syswow64\prevhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks.exe /delete /tn "WinSvcMon_3E5A0232" /f >nul 2>&1
- '%WINDIR%\syswow64\schtasks.exe' /delete /tn "WinSvcMon_3E5A0232" /f
- '%WINDIR%\syswow64\secedit.exe' /configure /db %TEMP%\SeDebugPrivilege.sdb /cfg %TEMP%\SeDebugPrivilege.inf /overwrite /log %TEMP%\SeDebugPrivilege.log /quiet
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\iusb3mon.exe' -Force" >nul 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionProcess '<File name>.exe' -Force" >nul 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c timeout /t 2 /nobreak >nul' (with hidden window)
- '%LOCALAPPDATA%\iusb3mon.exe' ' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "$temp = $env:TEMP;$inf = Join-Path $temp 'SeDebugPrivilege.inf';$sdb = Join-Path $temp 'SeDebugPrivilege.sdb';$log = Join-Path $temp 'SeDebugPrivilege.log';$b64 = '//5bAFUA...' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Local\ziliao.jpg'"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks.exe /delete /tn "WinSvcMon_3E5A0232" /f >nul 2>&1' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\iusb3mon.exe'"' (with hidden window)
- '%TEMP%\7zf63f40f8\colaboxchecker.exe' checker /baseboard' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionProcess 'iusb3mon.exe'"' (with hidden window)
- '%TEMP%\7zf63f40f8\hypervchecker.exe' ' (with hidden window)