Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Ias] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Ias] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\Ias\Parameters] 'ServiceDll' = '%WINDIR%\SysWOW64\IsAgent\IsaSvc.dll'
- [<HKLM>\System\CurrentControlSet\Services\IsaSvcProtectServer] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\IsaSvcProtectServer] 'ImagePath' = '%WINDIR%\SysWOW64\IsAgent\IsaSvcProtectServer.exe'
- 'Ias' <SYSTEM32>\svchost.exe -k netsvcs
- 'IsaSvcProtectServer' %WINDIR%\SysWOW64\IsAgent\IsaSvcProtectServer.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes\] 'IsaHelp.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes\] 'svchost.exe' = '00000000'
- '%WINDIR%\syswow64\taskkill.exe' /im AsmAssistant.exe /f
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="NATCheck" dir=in program="<SYSTEM32>\isagent\NATCheck.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="NATCheck" dir=out program="<SYSTEM32>\isagent\NATCheck.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="NATCheck" dir=in program="%WINDIR%\syswow64\isagent\NATCheck.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="NATCheck" dir=out program="%WINDIR%\syswow64\isagent\NATCheck.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram %WINDIR%\syswow64\isagent\LcfP2PSeedTask.exe "LcfP2PSeedTask" enable
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram <SYSTEM32>\isagent\LcfP2PSeedTask.exe "LcfP2PSeedTask" enable
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="LcfP2PSeedTask" dir=in program="<SYSTEM32>\isagent\LcfP2PSeedTask.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="LcfP2PSeedTask" dir=out program="<SYSTEM32>\isagent\LcfP2PSeedTask.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="LcfP2PSeedTask" dir=in program="%WINDIR%\syswow64\isagent\LcfP2PSeedTask.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="LcfP2PSeedTask" dir=out program="%WINDIR%\syswow64\isagent\LcfP2PSeedTask.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram %WINDIR%\syswow64\isagent\AsmPatchAutoRepair.exe "AsmPatchAutoRepair" enable
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram <SYSTEM32>\isagent\NATCheck.exe "NATCheck" enable
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram <SYSTEM32>\isagent\AsmPatchAutoRepair.exe "AsmPatchAutoRepair" enable
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="AsmPatchAutoRepair" dir=out program="<SYSTEM32>\isagent\AsmPatchAutoRepair.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="AsmPatchAutoRepair" dir=in program="%WINDIR%\syswow64\isagent\AsmPatchAutoRepair.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="AsmPatchAutoRepair" dir=out program="%WINDIR%\syswow64\isagent\AsmPatchAutoRepair.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass Server" protocol=TCP dir=in localport=36600 action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass Server" protocol=TCP dir=out localport=36600 action=allow
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram %WINDIR%\syswow64\isagent\isahelp.exe "ASM 6000 Ass" enable
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram <SYSTEM32>\isagent\isahelp.exe "ASM 6000 Ass" enable
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass" dir=in program="<SYSTEM32>\isagent\isahelp.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass" dir=out program="<SYSTEM32>\isagent\isahelp.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass" dir=in program="%WINDIR%\syswow64\isagent\isahelp.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="ASM 6000 Ass" dir=out program="%WINDIR%\syswow64\isagent\isahelp.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="AsmPatchAutoRepair" dir=in program="<SYSTEM32>\isagent\AsmPatchAutoRepair.exe" action=allow
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram %WINDIR%\syswow64\isagent\NATCheck.exe "NATCheck" enable
- C:\asm\run.exe
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\access.b7d68d02.svg
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\softwareshop.47dabf20.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\selftestacuityinfo.ed220538.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\privilegemode.bb22a349.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\patchsuccess.86d26b05.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\patchdown.365bc63f.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\ipconfig.eed6559e.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\authorisedcheck.99f546a3.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\acuityinfocheck.7be52d24.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\iconfont.b87eec94.woff2
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\119.6341caf0.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\iconfont.b3324f8f.ttf
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\iconfont.504cf79a.eot
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\element-icons.ff18efd1.woff
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\element-icons.f1a45d74.ttf
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\app.55f3cd6f.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\9835.700ae387.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\9821.69b81d38.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\8858.9ef0dcfb.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\8009.208e6858.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\7943.e4834951.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\7918.60d385a1.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\fonts\iconfont.95c01202.woff
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\725.afe24869.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\6527.f2539f3d.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\checkloading.ebd4126d.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\auditing.87de1711.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\thirdlinkagemenu.79de9397.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\servernotworking.942a6428.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\repairing.bb9fd048.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\remoteassistancesuccess.f74eb2d9.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\refuse.91d93680.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\noaccess.b33dd5f9.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\networkaccess.93dfdcad.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\msepbg.b54fdf93.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\loading.2b3d2edd.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\avator.c07cd875.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\iconfont.8057799a.svg
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\applyok.f2de04dc.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\faultdiagnosis.0ca8b4a5.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\examineing.027a91a9.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\examinesuccess.67cd7b15.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\examineerror.8d85f376.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\examinedanger.a490537f.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\empty.e5035a0d.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\empty.8d8d8eb1.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\cutoff.d2d95fe1.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\checkukey.446bab7f.gif
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\iillegal.f7db1579.png
- %WINDIR%\syswow64\isagent\skin\img\wifi_enable.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\img\finger.0e8d4441.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\3006.e4834951.css
- %WINDIR%\syswow64\isagent\skin\netisolatewnd.xml
- %WINDIR%\syswow64\isagent\skin\addnetwork.xml
- %WINDIR%\syswow64\isagent\skin\changepassword.xml
- %WINDIR%\syswow64\isagent\skin\authorizedaccesswnd.xml
- %WINDIR%\syswow64\isagent\skin\devicelistitemcontainer.xml
- %WINDIR%\syswow64\isagent\skin\img\refreshqr.png
- %WINDIR%\syswow64\isagent\skin\img\refresh_qr.png
- %WINDIR%\syswow64\isagent\skin\uninstall.xml
- %WINDIR%\syswow64\isagent\skin\twofactorauth.xml
- %WINDIR%\syswow64\isagent\qrc\dist\loading.gif
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\6071.e4834951.css
- %WINDIR%\syswow64\isagent\skin\tooltipui.xml
- %WINDIR%\syswow64\isagent\skin\sub_menu.xml
- %WINDIR%\syswow64\isagent\qrc\dist\favicon.ico
- %WINDIR%\syswow64\isagent\skin\scrollbar.xml
- %WINDIR%\syswow64\isagent\skin\restart.xml
- %WINDIR%\syswow64\isagent\skin\requestremotescreenwnd.xml
- %WINDIR%\syswow64\isagent\qrc\image\app.ico
- %WINDIR%\syswow64\isagent\skin\promptui.xml
- %WINDIR%\syswow64\isagent\skin\msgbox.xml
- %WINDIR%\syswow64\isagent\skin\mainwndtest.xml
- %WINDIR%\syswow64\isagent\skin\isamainmenu.xml
- %WINDIR%\syswow64\isagent\qrc\dist\index.html
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\6487.4c1d2612.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\6116.d5f1c933.css
- %WINDIR%\syswow64\isagent\skin\img\isolate_net_normal.png
- %WINDIR%\syswow64\isagent\skin\img\isolate_net_hot.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\5917.b0edbab6.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\5879.e4834951.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\5870.23d0f532.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\5710.e4834951.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\5379.91623ec4.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\4711.61e588a2.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\4700.29be09ea.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\4398.bc4fc7dc.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\3991.8e7dc765.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\1319.64578f5e.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\3906.6790f8a9.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\1283.7ac546cb.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2965.74c48aa7.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2823.161c851b.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2694.b9768cfe.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2624.1200e2a9.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2388.e4834951.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\237.543024ec.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2189.e4834951.css
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\2072.7f2f9c8c.css
- %WINDIR%\syswow64\isagent\skin\img\isolate_net_disable.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\css\3886.468fa80d.css
- %WINDIR%\syswow64\isagent\skin\img\wifi_unable.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\119.6341caf0.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2240.089f5f80.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6585.0d3637f7.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6527.633b09f3.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6527.633b09f3.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6506.cac1dfc4.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6506.cac1dfc4.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6487.97e52ade.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6487.97e52ade.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6116.ac95ec5a.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6116.ac95ec5a.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6071.7648aeba.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5379.0435c036.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6071.7648aeba.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5917.47a23625.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\59.960b7158.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\59.960b7158.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5879.efecf067.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5879.efecf067.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5870.19555965.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5870.19555965.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5825.d9c49220.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5825.d9c49220.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5710.7b525d0d.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5917.47a23625.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5710.7b525d0d.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\6585.0d3637f7.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8396.206f99b5.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\app.d39e4f9c.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\app.d39e4f9c.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9835.b80ec53a.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9835.b80ec53a.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9727.1b1471e1.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9727.1b1471e1.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9651.51c7698a.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\9651.51c7698a.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8858.e1a5d7d7.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8858.e1a5d7d7.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7065.8e13f60f.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7065.8e13f60f.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8009.87753fd1.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8009.87753fd1.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7943.18f8f0a9.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7943.18f8f0a9.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7918.822e1902.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7918.822e1902.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\725.43288543.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\725.43288543.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7150.ff602483.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\7150.ff602483.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\8396.206f99b5.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1283.344a520b.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1283.344a520b.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5166.36d128b6.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2240.089f5f80.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2694.dffafa9f.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2624.7f57f94f.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2624.7f57f94f.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2489.85d744f6.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2489.85d744f6.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2388.51383e1d.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2388.51383e1d.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\237.50b0567b.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\237.50b0567b.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2694.dffafa9f.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2823.e91ae374.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5166.36d128b6.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2189.28415df7.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2072.f316bed2.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2072.f316bed2.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1755.6120e4e1.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1755.6120e4e1.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1701.d6e9ec7d.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1701.d6e9ec7d.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1319.4d62d489.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\1319.4d62d489.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2189.28415df7.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\5379.0435c036.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2823.e91ae374.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3906.ff78c18c.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3906.ff78c18c.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4711.4a924840.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4700.a4624cae.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4700.a4624cae.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4501.848cac17.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4501.848cac17.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4398.32013a2d.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4398.32013a2d.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3991.1bd4dfd4.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3991.1bd4dfd4.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\4711.4a924840.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2965.407cbd49.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2965.407cbd49.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3886.8c31c053.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3605.8edabcfe.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3605.8edabcfe.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3243.2fa963d0.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3243.2fa963d0.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3006.428c43f9.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3006.428c43f9.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2985.ec09985a.js.map
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\2985.ec09985a.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\3886.8c31c053.js.map
- %WINDIR%\syswow64\isagent\skin\img\waitting.gif
- %WINDIR%\syswow64\isagent\skin\img\vscrollbar.png
- %WINDIR%\syswow64\isagent\skin\img\vline.png
- %WINDIR%\syswow64\isagent\msaccustomcheck_extmodule.db
- %WINDIR%\syswow64\isagent\msachttpclient.dll
- %WINDIR%\syswow64\isagent\findmoduleinprocess.exe
- %WINDIR%\syswow64\isagent\rulelib.xml
- %WINDIR%\syswow64\isagent\msaccustomcheck.dll
- %WINDIR%\syswow64\isagent\virusdatabaseex.xml
- %WINDIR%\syswow64\isagent\virusdatabase.xml
- %WINDIR%\syswow64\isagent\qrc.zip
- %WINDIR%\syswow64\isagent\baseconfig.xml
- %WINDIR%\syswow64\isagent\asmgpedit.exe
- %WINDIR%\syswow64\isagent\spolicy_identityauthpolicy.xml
- %WINDIR%\syswow64\isagent\isacreateuserprocess.exe
- %WINDIR%\syswow64\isagent\wpcap.dll
- %WINDIR%\syswow64\isagent\pthreadvc.dll
- %WINDIR%\syswow64\isagent\packet.dll
- %WINDIR%\syswow64\isagent\npptools.dll
- %WINDIR%\syswow64\isagent\npf_x86.sys
- %WINDIR%\syswow64\isagent\npf_x64.sys
- %WINDIR%\syswow64\isagent\lcfhostfirewall.dll
- %WINDIR%\syswow64\isagent\lcfforcevlan.dll
- C:\asm\dbghelp.dll
- %WINDIR%\syswow64\isagent\movefile.exe
- %WINDIR%\syswow64\isagent\zh.langue
- <SYSTEM32>\isaview.lnk
- %WINDIR%\syswow64\isagent\uam_uas.dll
- <SYSTEM32>\isalog.lnk
- %WINDIR%\syswow64\isagent\isaagent.bin
- %WINDIR%\syswow64\isagent\preauthchecknonsupportconfig.xml
- %WINDIR%\syswow64\isagent\msaccheckantivirussoft.dll
- %WINDIR%\syswow64\isagent\msacp2pdownload.dll
- %WINDIR%\syswow64\isagent\asmprocmon.dll
- %WINDIR%\syswow64\isagent\asmconsole.exe
- %WINDIR%\syswow64\isagent\softinfo.inf
- %WINDIR%\syswow64\isagent\msacchecksoftinfo.dll
- %WINDIR%\syswow64\isagent\asmpatchautorepair.dll
- %WINDIR%\syswow64\isagent\msacchecksecurityset.dll
- %WINDIR%\syswow64\isagent\msaccheckweakpasswds.dll
- %WINDIR%\syswow64\isagent\msaccheckpatchnew.dll
- %WINDIR%\syswow64\isagent\msaccheckpatch.dll
- %WINDIR%\syswow64\isagent\msaccheckipmanage.dll
- %WINDIR%\syswow64\isagent\msaccheckdomain.dll
- %WINDIR%\syswow64\isagent\msaccheckisfirewallenable.dll
- %WINDIR%\syswow64\isagent\scrnsave.scr
- %WINDIR%\syswow64\isagent\msacactivex.dll
- %WINDIR%\syswow64\isagent\comparestringbyregular.exe
- %WINDIR%\syswow64\isagent\comparestringbyregular.vbs
- %WINDIR%\syswow64\isagent\secedit.exe
- %WINDIR%\syswow64\isagent\leakcheck1.dat
- %WINDIR%\syswow64\isagent\password.dll
- %WINDIR%\syswow64\isagent\balckupdate.xml
- %WINDIR%\syswow64\isagent\success.png
- %WINDIR%\syswow64\isagent\isawebsocketserver.dll
- %WINDIR%\syswow64\isagent\false.ico
- %WINDIR%\syswow64\isagent\en.unicode.langue
- %WINDIR%\syswow64\isagent\en.langue
- %WINDIR%\syswow64\isagent\duilib.dll
- %WINDIR%\syswow64\isagent\dbghelp.dll
- %WINDIR%\syswow64\isagent\curl.exe
- %WINDIR%\syswow64\isagent\config.xml
- %WINDIR%\syswow64\isagent\authunpass.png
- %WINDIR%\syswow64\isagent\authpass.png
- %WINDIR%\syswow64\isagent\fault.ico
- %WINDIR%\syswow64\isagent\asmunzip.exe
- %WINDIR%\syswow64\isagent\asmauthclient.dll
- %WINDIR%\syswow64\isagent\asmassistant.ico
- %WINDIR%\syswow64\isagent\addexcept.bat
- %WINDIR%\syswow64\isagent\aboutdlg.exe
- %TEMP%\uz9be1.tmp
- C:\asm\isaagent.bin
- C:\asm\isadomainins.exe
- C:\asm\extend.zip
- C:\asm\config.xml
- C:\asm\172.19.77.118_80_http_issetup_agent.exe
- %WINDIR%\syswow64\isagent\asmfunctionmgr.dll
- %WINDIR%\syswow64\isagent\thirdlinkagemodule.dll
- <SYSTEM32>\isaremove.lnk
- %WINDIR%\syswow64\isagent\false.png
- %WINDIR%\syswow64\isagent\success.ico
- %WINDIR%\syswow64\isagent\setup.bat
- %WINDIR%\syswow64\isagent\offline.ico
- %WINDIR%\syswow64\isagent\noauth.ico
- %WINDIR%\syswow64\isagent\msacassinterface.dll
- %WINDIR%\syswow64\isagent\libssl-1_1.dll
- %WINDIR%\syswow64\isagent\libcrypto-1_1.dll
- %WINDIR%\syswow64\isagent\lcfupdatedot1xmodule.dll
- %WINDIR%\syswow64\isagent\lcfprobeagent.dll
- %WINDIR%\syswow64\isagent\lcfgrayupdate.dll
- %WINDIR%\syswow64\isagent\firewalladdapp.bat
- %WINDIR%\syswow64\isagent\fault.png
- %WINDIR%\syswow64\isagent\isatraymenu.zip
- %WINDIR%\syswow64\isagent\isatraymenu.dll
- %WINDIR%\syswow64\isagent\isasvcprotectserver.exe
- %WINDIR%\syswow64\isagent\isasvc.dll
- %WINDIR%\syswow64\isagent\isasetup.exe
- %WINDIR%\syswow64\isagent\isamanage.dll
- %WINDIR%\syswow64\isagent\isahelp.exe
- %WINDIR%\syswow64\isagent\isadriver.dll
- %WINDIR%\syswow64\isagent\isactrl.dll
- %WINDIR%\syswow64\isagent\ipsec.dll
- %WINDIR%\syswow64\isagent\isauninstalldlg.dll
- %WINDIR%\syswow64\isagent\internal_config.xml
- %WINDIR%\syswow64\isagent\asmfiledownload.exe
- %WINDIR%\syswow64\isagent\setasmagentmodeflagfile.txt
- %WINDIR%\syswow64\isagent\skin\img\patch_repair_hot.png
- %WINDIR%\syswow64\isagent\skin\img\guest.png
- %WINDIR%\syswow64\isagent\skin\img\no_autoauth_normal.png
- %WINDIR%\syswow64\isagent\skin\img\no_autoauth_hot.png
- %WINDIR%\syswow64\isagent\skin\img\menu_expand.png
- %WINDIR%\syswow64\isagent\skin\img\lock.png
- %WINDIR%\syswow64\isagent\skin\img\loading.gif
- %WINDIR%\syswow64\isagent\skin\img\infogo.png
- %WINDIR%\syswow64\isagent\skin\img\hscrollbar.png
- %WINDIR%\syswow64\isagent\skin\img\hline.png
- %WINDIR%\syswow64\isagent\skin\img\help.png
- %WINDIR%\syswow64\isagent\skin\img\check_result_normal.png
- %WINDIR%\syswow64\isagent\skin\img\patch_repair_normal.png
- %WINDIR%\syswow64\isagent\skin\img\combo_normal.png
- %WINDIR%\syswow64\isagent\skin\img\ethernet.png
- %WINDIR%\syswow64\isagent\skin\img\device_info_normal.png
- %WINDIR%\syswow64\isagent\skin\img\device_info_hot.png
- %WINDIR%\syswow64\isagent\skin\img\device_info_disable.png
- %WINDIR%\syswow64\isagent\skin\img\deviceinfo.png
- %WINDIR%\syswow64\isagent\skin\img\default_menu_normal.png
- %WINDIR%\syswow64\isagent\skin\img\default_menu_hot.png
- %WINDIR%\syswow64\isagent\skin\img\default.png
- %WINDIR%\syswow64\isagent\skin\img\computer.png
- %WINDIR%\syswow64\isagent\skin\img\false.png
- %WINDIR%\syswow64\isagent\skin\img\fault.png
- %WINDIR%\syswow64\isagent\skin\img\qr_code.png
- %WINDIR%\syswow64\isagent\skin\img\switch_user_disable.png
- %WINDIR%\syswow64\isagent\skin\img\switch_user_hot.png
- %WINDIR%\syswow64\isagent\skin\img\visitor_code_hot.png
- %WINDIR%\syswow64\isagent\skin\img\user.png
- %WINDIR%\syswow64\isagent\skin\img\uninstall_ass_normal.png
- %WINDIR%\syswow64\isagent\skin\img\uninstall_ass_hot.png
- %WINDIR%\syswow64\isagent\skin\img\uninstall.png
- %WINDIR%\syswow64\isagent\skin\img\treeview_b.png
- %WINDIR%\syswow64\isagent\skin\img\treeview_a.png
- %WINDIR%\syswow64\isagent\skin\img\tool.png
- %WINDIR%\syswow64\isagent\skin\img\switch_user_normal.png
- %WINDIR%\syswow64\isagent\skin\img\visitor_code_normal.png
- %WINDIR%\syswow64\isagent\skin\img\reboot.png
- %WINDIR%\syswow64\isagent\skin\img\refresh.png
- %WINDIR%\syswow64\isagent\skin\img\sub_department.png
- %WINDIR%\syswow64\isagent\skin\img\small_282.png
- %WINDIR%\syswow64\isagent\skin\img\shadow.png
- %WINDIR%\syswow64\isagent\skin\img\sd.png
- %WINDIR%\syswow64\isagent\skin\img\scrollbar.bmp
- %WINDIR%\syswow64\isagent\skin\img\root_department.png
- %WINDIR%\syswow64\isagent\skin\img\remotescreen.png
- %WINDIR%\syswow64\isagent\skin\img\remote.png
- %WINDIR%\syswow64\isagent\skin\img\refresh_32.png
- %WINDIR%\syswow64\isagent\skin\img\success.png
- %WINDIR%\syswow64\isagent\skin\img\clock.png
- %WINDIR%\syswow64\isagent\skin\img\check_result_hot.png
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- %WINDIR%\syswow64\isagent\skin\img\btn_blue_round_rect.png
- %WINDIR%\syswow64\isagent\skin\img\btn_blank_round_rect.png
- %WINDIR%\syswow64\isagent\skin\img\book.png
- %WINDIR%\syswow64\isagent\skin\img\auth_check_normal.png
- %WINDIR%\syswow64\isagent\skin\img\auth_check_hot.png
- %WINDIR%\syswow64\isagent\skin\img\auth_check_disable.png
- %WINDIR%\syswow64\isagent\skin\img\apply_remote_normal.png
- %WINDIR%\syswow64\isagent\skin\img\apply_remote_hot.png
- %WINDIR%\syswow64\isagent\skin\img\analyze_tool_normal.png
- %WINDIR%\syswow64\isagent\skin\img\btn_close_down.png
- %WINDIR%\syswow64\isagent\firewalloption.xml
- %WINDIR%\syswow64\isagent\skin\img\analyze_tool_hot.png
- %WINDIR%\syswow64\isagent\skin\img\analyze_tool_disable.png
- %WINDIR%\syswow64\isagent\skin\departmenthierarchy.xml
- %WINDIR%\syswow64\isagent\skin\autouninstallprompt.xml
- %WINDIR%\syswow64\isagent\skin\authandcheck.xml
- %WINDIR%\syswow64\isagent\skin\accountloginexceedui.xml
- %WINDIR%\syswow64\isagent\skin\aboutwnd.xml
- %WINDIR%\syswow64\infogofunmgr\asm6000\ö÷»ú·à »ðç½\event.txt
- %WINDIR%\syswow64\infogofunmgr\asm6000\ö÷»ú·à »ðç½\event.txt.ini
- %WINDIR%\syswow64\isagent\hflogonflagfile.txt
- %WINDIR%\syswow64\isagent\breaknetworkflagfile.txt
- %WINDIR%\syswow64\isagent\skin\img\btn_close_highlight.png
- %WINDIR%\syswow64\isagent\skin\img\btn_close.png
- %WINDIR%\syswow64\isagent\skin\img\btn_close_normal.png
- %WINDIR%\syswow64\isagent\skin\img\check_result_disable.png
- %WINDIR%\syswow64\isagent\skin\img\btn_pc_hot.png
- %WINDIR%\syswow64\isagent\skin\img\checkbox_un_focus.png
- %WINDIR%\syswow64\isagent\skin\img\checkbox_un.png
- %WINDIR%\syswow64\isagent\skin\img\checkbox_sel_focus.png
- %WINDIR%\syswow64\isagent\skin\img\checkbox_sel.png
- %WINDIR%\syswow64\isagent\skin\img\change_passwd_normal.png
- %WINDIR%\syswow64\isagent\skin\img\change_passwd_hot.png
- %WINDIR%\syswow64\isagent\skin\img\btn_qr_code_push.png
- %WINDIR%\syswow64\isagent\skin\img\btn_qr_code_hot.png
- %WINDIR%\syswow64\isagent\skin\img\btn_qr_code.png
- %WINDIR%\syswow64\isagent\skin\img\btn_pc_push.png
- %WINDIR%\syswow64\isagent\skin\img\btn_pc.png
- %WINDIR%\syswow64\isagent\skin\img\btn_darkblue_round_rect.png
- %WINDIR%\syswow64\isagent\skin\img\btn_min.png
- %WINDIR%\syswow64\isagent\skin\img\btn_login_push.png
- %WINDIR%\syswow64\isagent\skin\img\btn_login_nor.png
- %WINDIR%\syswow64\isagent\skin\img\btn_login_hot.png
- %WINDIR%\syswow64\isagent\skin\img\btn_lightblue_round_rect.png
- %WINDIR%\syswow64\isagent\skin\img\btn_guest_switch_push.png
- %WINDIR%\syswow64\isagent\skin\img\btn_guest_switch_nor.png
- %WINDIR%\syswow64\isagent\skin\img\btn_guest_switch_hot.png
- %WINDIR%\syswow64\isagent\skin\img\btn_green_round_rect.png
- %WINDIR%\syswow64\isagent\skin\img\btn_gray_round_rect.png
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\chunk-vendors.50de8ddd.js
- %WINDIR%\syswow64\isagent\qrc\dist\static\js\chunk-vendors.50de8ddd.js.map
- C:\asm\dbghelp.dll
- C:\asm\isaagent.bin
- C:\asm\config.xml
- from %TEMP%\uz9be1.tmp to %WINDIR%\syswow64\isagent\setup.zip
- %ALLUSERSPROFILE%\ntuser.pol
- '17#.#9.77.118':80
- DNS ASK ba##u.com
- '17#.#9.77.118':36533
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- 'C:\asm\isadomainins.exe'
- 'C:\asm\172.19.77.118_80_http_issetup_agent.exe'
- '%WINDIR%\syswow64\isagent\isahelp.exe'
- '%WINDIR%\syswow64\isagent\isasvcprotectserver.exe'
- '%WINDIR%\syswow64\isagent\asmgpedit.exe' Set HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat DisablePCA 1
- '%WINDIR%\syswow64\isagent\asmunzip.exe' -Unzip %WINDIR%\syswow64\isagent\Qrc.zip %WINDIR%\syswow64\isagent\
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe < %WINDIR%\SysWOW64\IsAgent\\Setup.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c Ewfmgr C: -commit' (with hidden window)
- '%WINDIR%\syswow64\isagent\asmunzip.exe' -Unzip %WINDIR%\syswow64\isagent\Qrc.zip %WINDIR%\syswow64\isagent\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe < %WINDIR%\SysWOW64\IsAgent\\Setup.bat
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c Ewfmgr C: -commit
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\cmd.exe' /K AddExcept.bat
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" ver "
- '%WINDIR%\syswow64\find.exe' "6.3."
- '%WINDIR%\syswow64\find.exe' "10."