Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Siggen10.27815

Added to the Dr.Web virus database: 2020-09-24

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'McAfeeUpdaterUI' = '"%ProgramFiles%\McAfee\Agent\x86\UpdaterUI.exe" /StartedFromRunKey'
Sets the following service settings
  • [<HKLM>\System\CurrentControlSet\Services\macmnsvc] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\macmnsvc] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\macmnsvc.exe" /ServiceStart'
  • [<HKLM>\System\CurrentControlSet\Services\McAfeeFramework] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\x86\macompatsvc.exe"'
  • [<HKLM>\System\CurrentControlSet\Services\masvc] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\masvc] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\masvc.exe" /ServiceStart'
Creates the following services
  • 'macmnsvc' "%ProgramFiles%\McAfee\Agent\macmnsvc.exe" /ServiceStart
  • 'McAfeeFramework' "%ProgramFiles%\McAfee\Agent\x86\macompatsvc.exe"
  • 'McAfeeFramework' %ProgramFiles%\McAfee\Agent\x86\macompatsvc.exe
  • 'masvc' "%ProgramFiles%\McAfee\Agent\masvc.exe" /ServiceStart
Modifies file system
Creates the following files
  • %TEMP%\mcafeelogs\frminst_unwkphmyqsny.log
  • %ProgramFiles%\mcafee\agent\x86\0804\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\041d\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0419\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0416\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0415\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0414\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0413\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0412\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0411\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0410\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\mfemactl.exe
  • %ProgramFiles%\mcafee\agent\x86\040c\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\040b\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0407\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0406\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0405\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0404\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0409\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\updaterui.exe
  • %ALLUSERSPROFILE%\mcafee\agent\update\updatemain.mcs
  • %ProgramFiles%\mcafee\agent\x86\trex.dll
  • %ProgramFiles%\mcafee\agent\x86\sqlite.dll
  • %ProgramFiles%\mcafee\agent\x86\041f\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\0816\updres.dll
  • %ProgramFiles%\mcafee\agent\ma_service_manager_client.dll
  • %ProgramFiles%\mcafee\agent\x86\poevtinf.dll
  • %ProgramFiles%\mcafee\agent\x86\0c0a\updres.dll
  • %ProgramFiles%\mcafee\agent\ma_serialization.dll
  • %ProgramFiles%\mcafee\agent\ma_repository.dll
  • %ProgramFiles%\mcafee\agent\ma_proxy.dll
  • %ProgramFiles%\mcafee\agent\ma_network.dll
  • %ProgramFiles%\mcafee\agent\ma_msgbus_auth.sig
  • %ProgramFiles%\mcafee\agent\ma_msgbus.dll
  • %ProgramFiles%\mcafee\agent\ma_logger.dll
  • %ProgramFiles%\mcafee\agent\ma_datastore.dll
  • %ProgramFiles%\mcafee\agent\ma_database.dll
  • %ProgramFiles%\mcafee\agent\ma_crypto.dll
  • %ProgramFiles%\mcafee\agent\ma_configurator.dll
  • %ProgramFiles%\mcafee\agent\ma_client.dll
  • %ProgramFiles%\mcafee\agent\libuv.dll
  • %ProgramFiles%\mcafee\agent\ssleay32.dll
  • %ProgramFiles%\mcafee\agent\libeay32.dll
  • %ProgramFiles%\mcafee\agent\libcurl.dll
  • %ProgramFiles%\mcafee\agent\genevtinf5_64.dll
  • %ProgramFiles%\mcafee\agent\cmdagent.exe
  • %ProgramFiles%\mcafee\agent\microsoft.vc100.crt.manifest
  • %ProgramFiles%\mcafee\agent\x86\zlib.dll
  • %ProgramFiles%\mcafee\agent\x86\xmlwrap.dll
  • %ProgramFiles%\mcafee\agent\x86\userspace.dll
  • %ProgramFiles%\mcafee\agent\x86\policyupgrade.exe
  • %ProgramFiles%\mcafee\agent\x86\040a\updres.dll
  • %ProgramFiles%\mcafee\agent\x86\nagshr32.dll
  • %ProgramFiles%\mcafee\agent\x86\mxml.dll
  • %ProgramFiles%\mcafee\agent\ma_utils.dll
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_inc_sha1_2019_2022.cer
  • %ProgramFiles%\mcafee\agent\x86\mcscancheck.exe
  • %ProgramFiles%\mcafee\agent\x86\marepomirror.exe
  • %ProgramFiles%\mcafee\agent\x86\macompatsvc.exe
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_globalsign_root_ca_sha256.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_globalsign_root_ca_sha1.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_globalsign_codesigning_ca_sha256.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_globalsign_codesigning_ca_sha1.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_llc_sha256_2019_2022.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_llc_sha1_2019_2022.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_inc_sha256_2019_2022.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_sha256_2016_2019.cer
  • %ProgramFiles%\mcafee\agent\x86\mfecryptc.dll
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_sha1_2016_2019.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_iam_2020.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca_2014_2017.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfeca.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_sia_ca_signer.pem.cer
  • %ALLUSERSPROFILE%\mcafee\agent\certstore\mfe_sia_ca_root.pem.cer
  • %ProgramFiles%\mcafee\agent\x86\ma_xml.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_variant.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_utils.dll
  • %ProgramFiles%\mcafee\agent\x86\mfelpc.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_service_manager_client.dll
  • %ALLUSERSPROFILE%\mcafee\agent\ml_cacerts.cer
  • %ProgramFiles%\mcafee\agent\x86\msvcr100.bin
  • %ProgramFiles%\mcafee\agent\x86\0c0a\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\mctray.exe
  • %ProgramFiles%\mcafee\agent\x86\0816\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0804\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\041f\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\041d\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0419\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0416\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0415\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0414\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0413\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0412\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0411\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0410\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\040c\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\040b\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\040a\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0407\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0406\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0405\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0404\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\0409\mueres.dll
  • %ProgramFiles%\mcafee\agent\x86\mue.exe
  • %ProgramFiles%\mcafee\agent\x86\msvcp100.bin
  • %ProgramFiles%\mcafee\agent\x86\ma_udp_client.dll
  • %ProgramFiles%\mcafee\agent\ma_variant.dll
  • %ProgramFiles%\mcafee\agent\ma_udp_client.dll
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\logs\masvc_unwkphmyqsny.log
  • %ALLUSERSPROFILE%\mcafee\agent\logs\macmnsvc_unwkphmyqsny.log
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.config
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\cabundle.cer
  • %ALLUSERSPROFILE%\mcafee\agent\cabundle.cer.bak
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.back
  • %APPDATA%\mcafee\common framework\db\mctray\pluginhistory\mctraypluginstatehistory.txt
  • %TEMP%\mcafeelogs\mctray_unwkphmyqsny.log
  • %ALLUSERSPROFILE%\mcafee\agent\msgbus\config.ini
  • %TEMP%\mcafeelogs\updaterui_unwkphmyqsny.log
  • %ALLUSERSPROFILE%\mcafee\agent\logs\mfemactl.log
  • %ALLUSERSPROFILE%\mcafee\agent\logs\mfemactl_c.log
  • %ALLUSERSPROFILE%\mcafee\agent\agent.ini
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db-journal
  • %ProgramFiles%\mcafee\agent\0406\agentres.ini
  • %ProgramFiles%\mcafee\agent\ma_xml.dll
  • %ProgramFiles%\mcafee\agent\ma_scheduler.dll
  • %ProgramFiles%\mcafee\agent\ma_repository_service.dll
  • %ProgramFiles%\mcafee\agent\ma_property_service.dll
  • %ProgramFiles%\mcafee\agent\ma_policy_service.dll
  • %ProgramFiles%\mcafee\agent\ma_p2p.dll
  • %ProgramFiles%\mcafee\agent\ma_lockdown_service.dll
  • %ProgramFiles%\mcafee\agent\ma_io_service.dll
  • %ProgramFiles%\mcafee\agent\ma_http_server.dll
  • %ProgramFiles%\mcafee\agent\ma_event_service.dll
  • %ProgramFiles%\mcafee\agent\ma_datachannel_service.dll
  • %ProgramFiles%\mcafee\agent\ma_csclient.dll
  • %ProgramFiles%\mcafee\agent\ma_ahclient.dll
  • %ProgramFiles%\mcafee\agent\ma_aac_service.dll
  • %ProgramFiles%\mcafee\agent\zlib.dll
  • %ProgramFiles%\mcafee\agent\trex.dll
  • %ProgramFiles%\mcafee\agent\sqlite.dll
  • %ProgramFiles%\mcafee\agent\mxml.dll
  • %ProgramFiles%\mcafee\agent\msvcr100.bin
  • %ProgramFiles%\mcafee\agent\msvcp100.bin
  • %ProgramFiles%\mcafee\agent\mfelpc.dll
  • %ProgramFiles%\mcafee\agent\mfecryptc.dll
  • %ProgramFiles%\mcafee\agent\mcupdater.exe
  • %ProgramFiles%\mcafee\agent\ma_sensor_service.dll
  • %ProgramFiles%\mcafee\agent\maconfig.exe
  • %ProgramFiles%\mcafee\agent\ma_udp_server.dll
  • %ProgramFiles%\mcafee\agent\ma_updater_service.dll
  • %ProgramFiles%\mcafee\agent\macmnsvc.exe
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\keystore\serverreqseckey.bin
  • %ALLUSERSPROFILE%\mcafee\agent\keystore\serverpubkey.bin
  • %ALLUSERSPROFILE%\mcafee\agent\keystore\agentprvkey.bin
  • %ALLUSERSPROFILE%\mcafee\agent\keystore\agentpubkey.bin
  • %TEMP%\mcafeelogs\maconfig.log
  • %ALLUSERSPROFILE%\mcafee\agent\frameworkmanifest.xml_rollback
  • %WINDIR%\installer\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\arpproducticon.exe
  • %ALLUSERSPROFILE%\mcafee\agent\svc_x86.cab
  • %ALLUSERSPROFILE%\mcafee\agent\svc_x64.cab
  • %ALLUSERSPROFILE%\mcafee\agent\shared64.cab
  • %ALLUSERSPROFILE%\mcafee\agent\shared.cab
  • %ALLUSERSPROFILE%\mcafee\agent\mfeagent_x64.msi
  • %ProgramFiles%\mcafee\agent\msvcr100.dll
  • %ProgramFiles%\mcafee\agent\x86\msvcr100.dll
  • %ProgramFiles%\mcafee\agent\msvcp100.dll
  • %ProgramFiles%\mcafee\agent\x86\msvcp100.dll
  • %ProgramFiles%\mcafee\agent\masvc.exe
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db
  • %ProgramFiles%\mcafee\agent\x86\ma_serialization.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_repository.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_proxy.dll
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\splashscreen.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\rule_folder_closed.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\plus_sign.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\outbound.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\no_symbol.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\minus_sign.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\mcafee_m_small.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\main_window.ini
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\inbound.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_ok_medium.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\trailer.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\group_folder_closed.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gradated_background_with_mcafee_logo.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gradated_background.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\folder_open.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\folder_closed.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\document.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\disallow.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_open_pressed.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_open_normal.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_close_pressed.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\grip.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gray_checked.png
  • %ProgramFiles%\mcafee\agent\x86\0816\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\tray_menu_issue.png
  • %ProgramFiles%\mcafee\agent\x86\041d\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0419\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0416\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0415\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0414\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0413\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0412\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0411\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0410\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\040c\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\040b\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\040a\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0407\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0406\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0405\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0404\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\0409\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\mctraylegacysupportplugin32.dll
  • %ProgramFiles%\mcafee\agent\x86\mctrayinterfacelib.dll
  • %ProgramFiles%\mcafee\agent\x86\mctrayinstsupp.dll
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\unchecked.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\tray_menu_okay.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_close_normal.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\checkmark.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_warning_medium.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\checked.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_up.png
  • %TEMP%\mcafeelogs\frminst_unwkphmyqsny_error.log
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\sitelist.xml
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\dxl.zip
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\hashes.xml
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\packageinfo.xml
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\bootstrapinfo.xml
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\sr2048pubkey.bin
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\req2048seckey.bin
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\agent.ini
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\repokeys.ini
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\agentfipsmode
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\srpubkey.bin
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\reqseckey.bin
  • %ProgramFiles%\mcafee\agent\x86\0804\mctrayres.dll
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\svc_x86.cab
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\svc_x64.cab
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\shared64.cab
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\shared.cab
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\mfeagent_x64.msi
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\mfeagent.msi
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\frminst.exe
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\cleanup.exe
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\__temp.zip
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\dxl\dxdet.mcs
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\dxl\dxinst.mcs
  • %ProgramFiles%\mcafee\agent\x86\041f\mctrayres.dll
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\dxl\pkgcatalog.z
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\dxl\dxlsetup-ma.exe
  • %TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\contrib.ini
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_down.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_disabled.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\bidirectional.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\allow.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\advisory_dlg.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\advisory_dlg.ini
  • %ProgramFiles%\mcafee\agent\x86\mctrayeventlog.dll
  • %ProgramFiles%\mcafee\agent\x86\mctrayerrorloggingplugin.dll
  • %ProgramFiles%\mcafee\agent\x86\mcafeewin32guisupportdll.dll
  • %ProgramFiles%\mcafee\agent\x86\mcafeecommonupdaterplugin.dll
  • %ProgramFiles%\mcafee\agent\x86\componentpointproduct.dll
  • %TEMP%\mcafeelogs\mfemactl.log
  • %TEMP%\mcafeelogs\mfemactl_c.log
  • %TEMP%\ab0b3035-cffb-4bc0-89cd-e73f727a93a3\mfemactl.exe
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\repokeys.ini
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\agentfipsmode
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\sr2048pubkey.bin
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\srpubkey.bin
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\req2048seckey.bin
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\reqseckey.bin
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\main.txt
  • %TEMP%\mcafeelogs\mfeagent.msi.2020.10.01.19.28.45.log
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_hover.png
  • %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_error_medium.png
  • %ProgramFiles%\mcafee\agent\x86\0c0a\mctrayres.dll
  • %ProgramFiles%\mcafee\agent\x86\libuv.dll
  • %ProgramFiles%\mcafee\agent\x86\040c\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\ssleay32.dll
  • %ProgramFiles%\mcafee\agent\x86\libeay32.dll
  • %ProgramFiles%\mcafee\agent\x86\libcurl.dll
  • %ALLUSERSPROFILE%\mcafee\agent\update\installmain.mcs
  • %ProgramFiles%\mcafee\agent\x86\mctray\gui_redirect.ini
  • %ProgramFiles%\mcafee\agent\x86\genevtinf5.dll
  • %ProgramFiles%\mcafee\agent\x86\frminst.exe
  • %ALLUSERSPROFILE%\mcafee\agent\frameworkmanifest.xml
  • %ProgramFiles%\mcafee\agent\x86\componentuserinterface.dll
  • %ProgramFiles%\mcafee\agent\x86\0c0a\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0816\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0804\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\041f\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\041d\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0419\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0416\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0415\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0414\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0413\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0412\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0411\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0410\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\microsoft.vc100.crt.manifest
  • %ProgramFiles%\mcafee\agent\license.txt
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\css\agentlog.css
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\css\asc.gif
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\css\bg.gif
  • %ProgramFiles%\mcafee\agent\x86\ma_network.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_msgbus_auth.sig
  • %ProgramFiles%\mcafee\agent\x86\ma_msgbus.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_logger.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_datastore.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_database.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_crypto.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_configurator.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compatplugin.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compatlpc.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compatdata.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compatbase.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_updater.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_subsystem.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_scheduler.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_logger.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_framework_factory.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_compat_agent.dll
  • %ProgramFiles%\mcafee\agent\x86\ma_client.dll
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\js\json2.js
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\js\agentlog.js
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\css\desc.gif
  • %ProgramFiles%\mcafee\agent\x86\ma_package_manager.dll
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\data\contrib\contrib.ini
  • %ProgramFiles%\mcafee\agent\x86\0407\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0412\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0c0a\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0816\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0804\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\041f\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\041d\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0419\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0416\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0415\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0414\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0413\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0411\agentres.dll
  • %ProgramFiles%\mcafee\agent\0404\agentres.ini
  • %ProgramFiles%\mcafee\agent\x86\0410\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\040c\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\040b\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\040a\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0407\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0406\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0405\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0404\agentres.dll
  • %ProgramFiles%\mcafee\agent\x86\0409\agentres.dll
  • %ALLUSERSPROFILE%\mcafee\agent\data\logging\agentlog.html
  • %ProgramFiles%\mcafee\agent\x86\040a\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\040b\cmauires.dll
  • %ProgramFiles%\mcafee\agent\0405\agentres.ini
  • %ProgramFiles%\mcafee\agent\040a\agentres.ini
  • %ProgramFiles%\mcafee\agent\0409\agentres.ini
  • %ProgramFiles%\mcafee\agent\x86\0406\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0405\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0404\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\0409\cmauires.dll
  • %ProgramFiles%\mcafee\agent\x86\clientui.dll
  • %ProgramFiles%\mcafee\agent\x86\boost_thread-vc100-mt-1_39.dll
  • %ProgramFiles%\mcafee\agent\x86\boost_system-vc100-mt-1_39.dll
  • %ProgramFiles%\mcafee\agent\0c0a\agentres.ini
  • %ProgramFiles%\mcafee\agent\0816\agentres.ini
  • %ProgramFiles%\mcafee\agent\0804\agentres.ini
  • %ProgramFiles%\mcafee\agent\041f\agentres.ini
  • %ProgramFiles%\mcafee\agent\041d\agentres.ini
  • %ProgramFiles%\mcafee\agent\0419\agentres.ini
  • %ProgramFiles%\mcafee\agent\0416\agentres.ini
  • %ProgramFiles%\mcafee\agent\0415\agentres.ini
  • %ProgramFiles%\mcafee\agent\0414\agentres.ini
  • %ProgramFiles%\mcafee\agent\0413\agentres.ini
  • %ProgramFiles%\mcafee\agent\0412\agentres.ini
  • %ProgramFiles%\mcafee\agent\0411\agentres.ini
  • %ProgramFiles%\mcafee\agent\0410\agentres.ini
  • %ProgramFiles%\mcafee\agent\040c\agentres.ini
  • %ProgramFiles%\mcafee\agent\040b\agentres.ini
  • %ProgramFiles%\mcafee\agent\0407\agentres.ini
  • %ALLUSERSPROFILE%\mcafee\agent\data\contrib\dxl.zip
Deletes the following files
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\frameworkmanifest.xml_rollback
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\agentfipsmode
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\main.txt
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\repokeys.ini
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\req2048seckey.bin
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\reqseckey.bin
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt.dump
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\sr2048pubkey.bin
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.repair-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt.dump
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.back
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.repair
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt-journal
  • %TEMP%\{7e7d0018-f9e8-4f6e-a9d8-28e0aa492222}\srpubkey.bin
Substitutes the following files
  • %ALLUSERSPROFILE%\mcafee\agent\db\ma.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mapolicy.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\matask.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\mascheduler.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\macmnsvc.db.decrypt-journal
  • %ALLUSERSPROFILE%\mcafee\agent\db\msgbus.db.decrypt-journal
Network activity
TCP
HTTP GET requests
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
  • 'ti###o03.tii.ie':443
  • UDP
    • DNS ASK microsoft.com
    • DNS ASK ti###o03.tii.ie
    Miscellaneous
    Searches for the following windows
    • ClassName: 'McAfeeFramework_NotifyIcon' WindowName: ''
    • ClassName: 'McAfeeCommonUpdaterUIMainWindow' WindowName: ''
    Creates and executes the following
    • '%TEMP%\mfe0bfed0a5-bc42-4570-b0ab-aadbd58e4e36.tmp\frminst.exe' /FramePkg /OriginalFramePkg="<Full path to file>" /Cleanup="%TEMP%\mfe0BFED0A5-BC42-4570-B0AB-AADBD58E4E36.tmp" /LOGDIR="%TEMP%\McAfeeLogs" /EmbeddedUsername="" /EmbeddedDomain="" /EmbeddedPass...
    • '%TEMP%\ab0b3035-cffb-4bc0-89cd-e73f727a93a3\mfemactl.exe' --log "%TEMP%\McAfeeLogs" --ppid 1068 --interface 4D454F57010000000000000000000000C0000000000000460000000005000000B0D675AD55A6D992BDEBABCCD5D6D5D3049C00002C04140910680905C0B6149A00000000
    • '%TEMP%\ab0b3035-cffb-4bc0-89cd-e73f727a93a3\mfemactl.exe' --log "%TEMP%\McAfeeLogs" --ppid 1068 --interface 4D454F57010000000000000000000000C0000000000000460000000005000000DB419E95E84FAEB5DAD935C9FD1BE22708DC00002C04100B0E2B570F2254A08E00000000
    • '%ProgramFiles%\mcafee\agent\x86\mctray.exe'
    • '%ProgramFiles%\mcafee\agent\maconfig.exe' -provision -managed -dir "%TEMP%\mfe0BFED0A5-BC42-4570-B0AB-AADBD58E4E36.tmp" -logdir "%TEMP%\McAfeeLogs" -nostart -check
    • '%ProgramFiles%\mcafee\agent\x86\mfemactl.exe' --log "%ALLUSERSPROFILE%\McAfee\Agent\logs" --ppid 1008 --interface 4D454F57010000000000000000000000C00000000000004600000000050000008971446C3B554CFBEF28BA3096785BE605E80000F003BC06EEA465FA40169...
    • '%ProgramFiles%\mcafee\agent\masvc.exe' /ServiceStart
    • '%ProgramFiles%\mcafee\agent\macmnsvc.exe' /ServiceStart
    • '%ProgramFiles%\mcafee\agent\maconfig.exe' -writenotifyregistrykey
    • '%ProgramFiles%\mcafee\agent\x86\updaterui.exe' /StartedFromRunKey
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq Mue_InUse.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macompatsvc.exe" /FO CSV /NH' (with hidden window)
    • '%ProgramFiles%\mcafee\agent\maconfig.exe' -provision -managed -dir "%TEMP%\mfe0BFED0A5-BC42-4570-B0AB-AADBD58E4E36.tmp" -logdir "%TEMP%\McAfeeLogs" -nostart -check' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macmnsvc.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq masvc.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UdaterUI.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UpdaterUI.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq McScript_InUse.exe" /FO CSV /NH' (with hidden window)
    • '%WINDIR%\syswow64\tasklist.exe' /FO CSV /NH' (with hidden window)
    • '%ProgramFiles%\mcafee\agent\maconfig.exe' -writenotifyregistrykey' (with hidden window)
    Executes the following
    • '%WINDIR%\syswow64\msiexec.exe' /i "%TEMP%\mfe0BFED0A5-BC42-4570-B0AB-AADBD58E4E36.tmp\MFEagent_x64.msi" ADDLOCAL=Main,Agent,Svc_x64 TRANSFORMS=:1033.mst /qb+ /l+*v "%TEMP%\McAfeeLogs\MFEagent.msi.2020.10.01.19.28.45.log" SIT...
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq Mue_InUse.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq McScript_InUse.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UpdaterUI.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UdaterUI.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq masvc.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macmnsvc.exe" /FO CSV /NH
    • '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macompatsvc.exe" /FO CSV /NH

    Curing recommendations

    1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
    2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
    Download Dr.Web

    Download by serial number

    Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

    After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

    Download Dr.Web

    Download by serial number

    1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
    2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
      • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
      • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
      • Switch off your device and turn it on as normal.

    Find out more about Dr.Web for Android