iusb3mon.exe

The executable iusb3mon.exe has been detected as malware by 22 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘USB3MON’.
MD5:
114bee8aaf3b06464c43e8c232badb8e

SHA-1:
7d3bb554ead3d398d181b4b922f3ce63e343777f

SHA-256:
6854185a4a56b10ece6a98f88d371c9d0fb958b440111f1bf027e654df677bf6

Scanner detections:
22 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/28/2024 3:54:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Jeefo.B
-40

AegisLab AV Signature
W32.W.Runouce.liJO
2.1.4+

AhnLab V3 Security
Trojan/Win32.HDC.C87681
3.8.1.15

Avira AntiVirus
W32/Jeefo.A
8.3.3.4

Arcabit
Win32.Jeefo.B
1.0.0.788

avast!
Win32:Crypt-SJB [Trj]
2014.9-170315

AVG
Win32/Hidrag.A
2018.0.2438

Baidu Antivirus
Win32.Trojan.Jeefo
4.0.3.17315

Bitdefender
Win32.Jeefo.B
1.0.20.370

Clam AntiVirus
Win.Trojan.Jeefo-1
0.98/21511

Fortinet FortiGate
W32/Generic.AC.9FB1!tr
3/15/2017

F-Prot
W32/SuspPack.AA.gen
v6.4.7.1.166

F-Secure
Win32.Jeefo.B
11.2017-15-03_4

G Data
Win32.Jeefo
17.3.25

IKARUS anti.virus
Virus.Win32.Hidrag
t3scan.2.1.16.0

Malwarebytes
Virus.Jeefo
v2017.03.15.10

MicroWorld eScan
Win32.Jeefo.B
18.0.0.222

NANO AntiVirus
Virus.Win32.Hidrag.clfcen
1.0.46.12879

Qihoo 360 Security
HEUR/QVM00.1.0000.Malware.Gen
1.0.0.1120

Quick Heal
W32.Jeefo.A
3.17.14.00

Rising Antivirus
Trojan.DL.Adload!1.66A0 (classic)
23.00.65.17313

VIPRE Antivirus
Virus.Win32.Jeefo.a
53582

File size:
321.5 KB (329,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\intel\intel(r) usb 3.0 extensible host controller driver\application\iusb3mon.exe

File PE Metadata
Compilation timestamp:
1/1/2008 4:55:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.0

Entry address:
0x1C0

Entry point:
33, C0, C2, 08, 00, 00, 00, 00, 0D, 0A, 0D, 0A, 54, 68, 69, 73, 20, 66, 69, 6C, 65, 20, 77, 61, 73, 20, 73, 61, 6E, 69, 74, 69, 7A, 65, 64, 20, 62, 79, 20, 61, 76, 61, 73, 74, 21, 20, 41, 6E, 74, 69, 76, 69, 72, 75, 73, 2E, 0D, 0A, 0D, 0A, 00, 00, 8F, 48, 00, 0A, 00, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, C0, 2E, 72, 73, 72, 63, 00, 00, 00, FC, 50, 03, 00, 00, C0, 00, 00, 00, 52, 03, 00, 00, 8A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 50...
 
[+]

Entropy:
5.8396

Code size:
128 Bytes (128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
USB3MON

Command:
"C:\Program Files\intel\intel(r) usb 3.0 extensible host controller driver\application\iusb3mon.exe"


Remove iusb3mon.exe - Powered by Reason Core Security