Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Siggen34.19307

Added to the Dr.Web virus database: 2026-09-23

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %WINDIR%\tasks\dcagentupdater.job
  • <SYSTEM32>\tasks\dcagentupdater
Sets the following service settings
  • [HKLM\SYSTEM\CurrentControlSet\Services\ManageEngine UEMS - Agent] 'Start' = '00000002'
  • [HKLM\SYSTEM\CurrentControlSet\Services\ManageEngine UEMS - Agent] 'ImagePath' = '"%ProgramFiles(x86)%\ManageEngine\UEMS_Agent\bin\dcagentservice.exe"'
  • [HKLM\SYSTEM\CurrentControlSet\Services\ManageEngine UEMS - Remote Control] 'ImagePath' = '"%ProgramFiles(x86)%\ManageEngine\UEMS_Agent\bin\dcrdservice.exe"'
Creates the following services
  • 'ManageEngine UEMS - Agent' %ProgramFiles(x86)%\ManageEngine�MS_Agentin\dcagentservice.exe
  • 'ManageEngine UEMS - Agent' %ProgramFiles(x86)%\ManageEngine\UEMS_Agent\bin\dcagentservice.exe
  • 'ManageEngine UEMS - Remote Control' %ProgramFiles(x86)%\ManageEngine�MS_Agentin\dcrdservice.exe
Modifies file system
Creates the following files
  • C:\users\public\15dddcf3\<File name>.dll
  • C:\users\public\15dddcf3\regsvr32.exe
  • %TEMP%\generatorapp\runs\20260923-191513-5584-1\runtime.log
  • %TEMP%\generatorapp\runs\20260923-191513-5876-1\runtime.log
  • C:\users\public\documents\wu\mutex.owner
  • C:\users\public\documents\wu\runs\20260923-191513-5876-1\deploy.log
  • C:\users\public\documents\wu\c2b8.zip
  • C:\users\public\documents\wu\pkg\dcagentserverinfo.json
  • C:\users\public\documents\wu\pkg\uemsagent.mst
  • C:\users\public\documents\wu\pkg\dmrootca.crt
  • C:\users\public\documents\wu\pkg\dmrootca-server.crt
  • C:\users\public\documents\wu\pkg\setup.bat
  • C:\users\public\documents\wu\pkg\readme.html
  • C:\users\public\documents\wu\pkg\uemsagent.msi
  • C:\users\public\documents\wu\pkg\setup1.vbs
  • C:\users\public\documents\wu\pkg\msi_install.log
  • %WINDIR%\installer\e4497.mst
  • %WINDIR%\temp\~df74702ab2f420d2e4.tmp
  • %WINDIR%\installer\sourcehash{6ad2231f-ff48-4d59-ac26-405afae23db7}
  • %WINDIR%\temp\~dfe878d014b6c63977.tmp
  • %WINDIR%\temp\~df514a5233a2d58037.tmp
  • %WINDIR%\temp\~df2f935f573c6f694b.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\lato.woff2
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\lato.woff
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\chat.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\cold_send.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\ec_icon.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\minimize_button.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\announcement.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\configuration-settings-dc-win7.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-mc.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\clientauthhandler.dll
  • %WINDIR%\syswow64\dcagenthttp.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\logo_dark.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\hot_mover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-vul.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\computer.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dropdownarrow.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_rejected.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\dynamic-variables.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dropdown_hover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-onpremise.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dcannouncement.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\webrtcdll.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\approval_status.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\messagebox_info.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-edb.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagentregister.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\restart.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\participantlist.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dc_icon.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\configuration-settings-dc-win8.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-inv.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\refresh_inactive.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\console.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\restart.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\warning_icon.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\otp-lock.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\remind.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\refresh.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\addtcpipport.vbs
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\console1.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\waiting.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_request.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\proxy.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\chat.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\updates.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\loader.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\configuration-settings-dc-winxp.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\otp-lock-fail.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\alert.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\messagebox.vbs
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\close_top.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_requested.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagentupgrader.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\dcconfig.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dcicon16.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\pwd-show.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\remind_hover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\default.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\info.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\drop_down_icon.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\initcmd.bat
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_uninstall.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\dcagent.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\arrow_pull_left.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\alert.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\toolbar.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\detected_sw.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\toolbar.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\waiting_aprvl.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\tools_reboot_alert.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\me-sign.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\stamp_used.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\icon_alert.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\invite.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\agenthook.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_install_all.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\proxy.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_download_all.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\user.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\refresh_inactive.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-framework.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\find.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\config_install_alert.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\btn_install.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\configuration-settings-dc.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\logger.conf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\close_top_hover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dropdown.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dc_icon.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\agent_binaries.7z
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\7z.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\wmi-classes.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\bit-locker.bat
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\find.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\alert.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\sspicon.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-br.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\minimize_icon.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\talkbackwidget.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\icon_software.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\apps_active.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\minimize.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\maximize_icon.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\filetransfer\dcfiletransfer.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\dc_rds.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\microsoftedge.admx
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\messagebox_warning.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\azurefs.ps1
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\ec_icon.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\restore_icon.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\detected.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\apps.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\logo_light.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\talkbackwidget.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\configuration-settings-dc-win10.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\style_cold.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\refresh.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\drop_down.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\console2.rgn
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\reboot_alert.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\uems_icon.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\chatframe.ico
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-rds.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\disableenableethernet.vbs
  • %ProgramFiles(x86)%\manageengine\uems_agent\licenses\license_libxml.txt
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\participantlist.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagentservice.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dumpcreator.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\history.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\osdetection.json
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\style_hot.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\updates_active.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\hot_send.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agentapplicationresources.properties
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\alert.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\minimize_hover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\agentqppmupgrader.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\cold_normal.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\x-icon.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\patch.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\tools.vbs
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\resource\invite.swf
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\hover.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\scripts\generalalerts.vbs
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\7z.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\7za.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\data-dictionary-pm.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\history_ico.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dcmsghandler.ico
  • %WINDIR%\syswow64\dclibxml2.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\dc_msp_image.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\user.svg
  • %ProgramFiles(x86)%\manageengine\uems_agent\rds\zchangenotifier.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentinstaller.log
  • %WINDIR%\installer\{6ad2231f-ff48-4d59-ac26-405afae23db7}\dcagentserverinfo.json
  • %ProgramFiles(x86)%\manageengine\uems_agent\certificates\csr.pem
  • %ProgramFiles(x86)%\manageengine\uems_agent\certificates\key.pem
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcdatatransferup.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\certificates\client.pem
  • %ProgramFiles(x86)%\manageengine\uems_agent\certificates\client.p12
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\imagefactor.json
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\imagefactoraccess.log
  • %TEMP%\certificates\client.p12_9389_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\ea131215d9cfd479de12ef629a4079a3_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\450f5a463de845b1531eef42454ee6ba_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %TEMP%\dc5956.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcdatatransferdown.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\client-data\server-certificates\dmrootca.crt
  • %ProgramFiles(x86)%\manageengine\uems_agent\client-data\1\server-certificates\dmrootca.crt
  • %TEMP%\certificates\client.p12_9405_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\bef8679720e1bfe57d5d5e0869fcbd49_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\osdetection.json.gz5956.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\osdetection.json.gz
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentinstallerunzip.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ca-certs.zip
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\cold_normal_msghldr.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcrdsagentwindow.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcscreenrec.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dctoolshardware.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dc_msp_image.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\devexe32.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\devexe64.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\driverfiles.7z
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\hot_mover_msghldr.gif
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\lato-bold.eot
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\lato-medium.eot
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ohotfix.ini
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\rdsrunasuser.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\topmiddle.bmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_444444_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_555555_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_777620_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_777777_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_cc0000_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_ffffff_256x240.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\wakeonlan.exe.config
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\agent_troubleshooting_tool.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\cfgupdate.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\checkvolume.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\clientauthhandler64.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\clientsocket.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcaddonsevaluator.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagenttrayicon.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcannouncement.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcappcontrol.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcchat.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dccomponentregister.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcconfigexec.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcfaservice.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcfaservice64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcfauser.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcfilescan.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcinventory.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcmsghandler.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcondemand.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcondemandtasks.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcpatchscan.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcprocessmonitor.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcproxyfinder.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcrdsagentwindow.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcrdservice.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcscreenrec.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcstatusutil.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcswmeter.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dctask64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dctoolshardware.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcuninstallsw.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcupload.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcusb32.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcusb64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcusbsummary.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcwol.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dcwolsettings.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dc_cad.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\detoureddll32.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\detoureddll64.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\devexe32.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\devexe64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dpinst64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\dpinst86.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\file_system_watcher.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\folder_backup.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\mdmregistrationhandler.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\mdmregistrationhandler_64.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\meaap.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\meaaphelper.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\metroapps.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\msvcp110.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\msvcr110.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\nativeuihandler.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\rapchat.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\rdsrunasuser.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\remcomm.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\resources.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\sas.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\secaddoncrashanalyser.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\securedcprocess.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\selfservicedll.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\selfserviceexe.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\selfserviceportal.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\sysmanager.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\toolsiq.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\uemsnotifications.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\uicontrols.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\usbedevicelist.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\vccorlib110.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\wakeonlan.exe
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\wsclientsocket.dll
  • %ProgramFiles(x86)%\manageengine\uems_agent\manageengine self service portal.lnk
  • %TEMP%\certificates\client.p12_9425_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\db61a4a351a846c9b8fc8bc6e16df3c0_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agentapplicationresources.properties5956.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\systeminfo.log
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %TEMP%\certificates\client.p12_9461_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\4f0c2a0616cb404ea4a3a163e1f06e3b_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-settings.xml
  • %TEMP%\certificates\client.p12_9464_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\77d5a4e0593a26f9f823fc5b0b809f9e_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-security-setting.json5956.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-security-setting.json
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\prevatemptdata.json
  • %TEMP%\certificates\client.p12_9480_5512
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\0e5d4312b0076c28a19d3f587b796ce7_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\somagentaccess.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentservice.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\updates\oldinstaller.msi
  • %WINDIR%\installer\{6ad2231f-ff48-4d59-ac26-405afae23db7}\uemsagent.mst
  • %WINDIR%\temp\~dfdb0ea08d86106628.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentserviceaccess.log
  • %WINDIR%\temp\~df30b56e6c3ae9ce75.tmp
  • %WINDIR%\temp\~dfb88512dd88ce2476.tmp
  • %WINDIR%\temp\~dfdcca98a633440986.tmp
  • %WINDIR%\temp\~dfca4ea9844c96c31e.tmp
  • %WINDIR%\temp\~df24a8ec5bb5180081.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcusbsummary.log
  • %WINDIR%\temp\~dff7285144347de35a.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcrotatelog.log
  • %WINDIR%\temp\~dfb4082a3c190656d3.tmp
  • %WINDIR%\temp\~df71b60e9ad6cd04e1.tmp
  • %WINDIR%\temp\~df004a6fa6080c3c7b.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentaccess.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcpowerreports.log
  • %WINDIR%\temp\certificates\client.p12_9500_5312
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\usbconfig_user.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\temp\temp.txt
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\1919518274ae5874f09247c3e44e958f_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcagentslotrequest.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\hostondemandrequest.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\invnotifylogger.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcswmetercollector.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcondemandrequest.log
  • %WINDIR%\temp\certificates\client.p12_9510_5312
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c663c0bf69e2a94a777e1bcc89e242f1_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9513_3308
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\34afa08b16c4edf32518fd2a6afb06c4_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9513_1444
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\f9ad48948205c028016981f41427f32c_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9513_4404
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\decf699f894740effd1d2870b8dfdcc5_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\meta-data.xml5312.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\meta-data.xml
  • %WINDIR%\temp\dc3308.tmp
  • %WINDIR%\temp\certificates\client.p12_9516_5312
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c1735cbf51705f99229c52d9f0cc031a_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\ns-status-details.xml1444.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\ns-status-details.xml
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\hostondemandaccess.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\computer.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\vmware-names.conf4404.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\vmware-names.conf
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\devicescanaccess.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\devicescanlogger.log
  • %WINDIR%\temp\certificates\client.p12_9539_5272
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\a65a77458c8e00cb1001600fc036eac7_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9546_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\106b61b6ccfd93c17c35bdb4c81f79e9_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\e195fe17480455eb3045751d01dde3bf_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9552_2988
  • %ProgramFiles(x86)%\manageengine\uems_agent\logs\dcprocessmoniter.log
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\processlist.conf
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\0b055ba7d06c5bb616d137a8ae0ad8da_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9555_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\614b7a3b85cbadd727c2fded65dda771_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-settings.xml2988.tmp
  • %WINDIR%\temp\certificates\client.p12_9562_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\79620bd7485a673603cc225c4be7fce3_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\userassignmentrules.json2988.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\userassignmentrules.json
  • %WINDIR%\temp\certificates\client.p12_9568_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c165ab583351536e9ee16d82a2cebea2_8cf7b530-613e-439b-a8c5-ccfc0e745400
Deletes following files that it created itself
  • C:\users\public\documents\wu\c2b8.zip
  • %TEMP%\certificates\client.p12_9389_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\ea131215d9cfd479de12ef629a4079a3_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\450f5a463de845b1531eef42454ee6ba_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %TEMP%\dc5956.tmp
  • %TEMP%\certificates\client.p12_9405_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\bef8679720e1bfe57d5d5e0869fcbd49_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\osdetection.json.gz5956.tmp
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\ca-certs.zip
  • %ProgramFiles(x86)%\manageengine\uems_agent\bin\agent_binaries.7z
  • %TEMP%\certificates\client.p12_9425_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\db61a4a351a846c9b8fc8bc6e16df3c0_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agentapplicationresources.properties5956.tmp
  • %TEMP%\certificates\client.p12_9461_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\4f0c2a0616cb404ea4a3a163e1f06e3b_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %TEMP%\certificates\client.p12_9464_5956
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\77d5a4e0593a26f9f823fc5b0b809f9e_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-security-setting.json5956.tmp
  • %TEMP%\certificates\client.p12_9480_5512
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\0e5d4312b0076c28a19d3f587b796ce7_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\installer\e4497.mst
  • C:\users\public\documents\wu\mutex.owner
  • %WINDIR%\temp\certificates\client.p12_9500_5312
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\1919518274ae5874f09247c3e44e958f_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9510_5312
  • %WINDIR%\temp\certificates\client.p12_9513_3308
  • %WINDIR%\temp\certificates\client.p12_9513_1444
  • %WINDIR%\temp\certificates\client.p12_9513_4404
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c663c0bf69e2a94a777e1bcc89e242f1_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\meta-data.xml5312.tmp
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\34afa08b16c4edf32518fd2a6afb06c4_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\dc3308.tmp
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\f9ad48948205c028016981f41427f32c_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9516_5312
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\ns-status-details.xml1444.tmp
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\decf699f894740effd1d2870b8dfdcc5_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\vmware-names.conf4404.tmp
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c1735cbf51705f99229c52d9f0cc031a_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9539_5272
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\a65a77458c8e00cb1001600fc036eac7_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9546_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\106b61b6ccfd93c17c35bdb4c81f79e9_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\e195fe17480455eb3045751d01dde3bf_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9552_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\0b055ba7d06c5bb616d137a8ae0ad8da_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %WINDIR%\temp\certificates\client.p12_9555_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\614b7a3b85cbadd727c2fded65dda771_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\agent-settings.xml2988.tmp
  • %WINDIR%\temp\certificates\client.p12_9562_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\79620bd7485a673603cc225c4be7fce3_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\manageengine\uems_agent\data\userassignmentrules.json2988.tmp
  • %WINDIR%\temp\certificates\client.p12_9568_2988
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\c165ab583351536e9ee16d82a2cebea2_8cf7b530-613e-439b-a8c5-ccfc0e745400
Moves the following files
  • from %ProgramFiles(x86)%\manageengine\uems_agent\images\lato.woff to C:\config.msi\e449b.rbf
  • from %ProgramFiles(x86)%\manageengine\uems_agent\images\info.png to C:\config.msi\e449c.rbf
  • from %ProgramFiles(x86)%\manageengine\uems_agent\images\drop_down_icon.png to C:\config.msi\e449d.rbf
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\lato-bold.eot to %ProgramFiles(x86)%\manageengine\uems_agent\images\lato-bold.eot
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\lato-medium.eot to %ProgramFiles(x86)%\manageengine\uems_agent\images\lato-medium.eot
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\resources.exe to %ProgramFiles(x86)%\manageengine\uems_agent\images\resources.exe
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\topmiddle.bmp to %ProgramFiles(x86)%\manageengine\uems_agent\images\topmiddle.bmp
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\cold_normal_msghldr.gif to %ProgramFiles(x86)%\manageengine\uems_agent\images\cold_normal_msghldr.gif
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\hot_mover_msghldr.gif to %ProgramFiles(x86)%\manageengine\uems_agent\images\hot_mover_msghldr.gif
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_444444_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_444444_256x240.png
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_555555_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_555555_256x240.png
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_777620_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_777620_256x240.png
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_777777_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_777777_256x240.png
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_cc0000_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_cc0000_256x240.png
  • from %ProgramFiles(x86)%\manageengine\uems_agent\bin\ui-icons_ffffff_256x240.png to %ProgramFiles(x86)%\manageengine\uems_agent\images\images\ui-icons_ffffff_256x240.png
Substitutes the following files
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\lato.woff
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\info.png
  • %ProgramFiles(x86)%\manageengine\uems_agent\images\drop_down_icon.png
  • %TEMP%\certificates\client.p12_9389_5956
  • %TEMP%\dc5956.tmp
  • %WINDIR%\temp\certificates\client.p12_9546_2988
Network activity
Connects to
  • 'pu####.#iantianxiazai88.com':443
  • 'x1.#.lencr.org':80
  • '27.##4.47.74':8151
TCP
HTTP GET requests
  • http://x1.#.lencr.org/
Other
  • 'pu####.#iantianxiazai88.com':443
  • '27.##4.47.74':8151
UDP
  • DNS ASK pu####.#iantianxiazai88.com
  • DNS ASK x1.#.lencr.org
  • DNS ASK mo#####.map.fastly.net
Miscellaneous
Adds a root certificate
Creates and executes the following
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagentregister.exe' -i dc
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\7za.exe' e -mx9 "%ProgramFiles(x86)%\ManageEngine\UEMS_Agent\bin\agent_binaries.7z" -o"%ProgramFiles(x86)%\ManageEngine\UEMS_Agent\bin\" -y
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcstatusutil.exe' -install 22
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcagentservice.exe'
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcusbsummary.exe' -s ET_ENUM 9 2 "Unknown"
  • '%ProgramFiles(x86)%\manageengine\uems_agent\dcconfig.exe' 0 0
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcusb64.exe' -s 9
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcstatusutil.exe' RequestAgentSlotFromServer
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcondemand.exe'
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcswmeter.exe' -s ET_COL
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcinventory.exe' -s prenotify
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcinventory.exe' -p processor compatibility
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\dcprocessmonitor.exe'
  • '%ProgramFiles(x86)%\manageengine\uems_agent\bin\mdmregistrationhandler_64.exe' -u "Admin" "https://27.##4.47.74:8443/mdm/client/v1/enroll?encapiKey=451e10aa&templateToken=faef665fd7b40d00a7f7a663577d918d&action=discover" "1513" "d3c1b3e7"
Executes the following
  • '<SYSTEM32>\rundll32.exe' "C:\Users\Public\15DDDCF3\<File name>.dll",MpayWebviewSupportMain
  • '<SYSTEM32>\msiexec.exe' /i "C:\Users\Public\Documents\WU\pkg\UEMSAgent.msi" TRANSFORMS="C:\Users\Public\Documents\WU\pkg\UEMSAgent.mst" ENABLESILENT=yes REBOOT=ReallySuppress INSTALLSOURCE=Manual SERVER_ROOT_CRT="C:\U...
  • '%WINDIR%\syswow64\cmd.exe' /C systeminfo.exe > "%ProgramFiles(x86)%\ManageEngine\UEMS_Agent\\logs\systeminfo.log"
  • '%WINDIR%\syswow64\systeminfo.exe'
  • '<SYSTEM32>\wbem\wmiapsrv.exe'
  • '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s NgcSvc
  • '<SYSTEM32>\rundll32.exe' "C:\Users\Public\15DDDCF3\<File name>.dll",MpayWebviewSupportMain' (with hidden window)
  • '<SYSTEM32>\msiexec.exe' /i "C:\Users\Public\Documents\WU\pkg\UEMSAgent.msi" TRANSFORMS="C:\Users\Public\Documents\WU\pkg\UEMSAgent.mst" ENABLESILENT=yes REBOOT=ReallySuppress INSTALLSOURCE=Manual SERVER_ROOT_CRT="C:\U...' (with hidden window)
  • '%ProgramFiles(x86)%\manageengine\uems_agent\dcconfig.exe' 0 0' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android