Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'McAfeeUpdaterUI' = '"%ProgramFiles%\McAfee\Agent\x86\UpdaterUI.exe" /StartedFromRunKey'
- [<HKLM>\System\CurrentControlSet\Services\macmnsvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\mfeaack] 'ImagePath' = 'system32\drivers\mfeaack.sys'
- [<HKLM>\System\CurrentControlSet\Services\mfeaack] 'ImagePath' = 'mfeaack.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\mfehidk] 'ImagePath' = 'system32\drivers\mfehidk.sys'
- [<HKLM>\System\CurrentControlSet\Services\mfehidk] 'ImagePath' = 'mfehidk.sys'
- [<HKLM>\System\CurrentControlSet\Services\mfehidk] 'Start' = '00000000'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\mfevtp] 'ImagePath' = '"<SYSTEM32>\mfevtps.exe"'
- [<HKLM>\System\CurrentControlSet\Services\mfevtp] 'ImagePath' = 'mfevtps.exe'
- [<HKLM>\System\CurrentControlSet\Services\mfevtp] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\mfemms] 'ImagePath' = '"%CommonProgramFiles%\McAfee\SystemCore\\mfemms.exe"'
- [<HKLM>\System\CurrentControlSet\Services\mfemms] 'ImagePath' = 'mfemms.exe'
- [<HKLM>\System\CurrentControlSet\Services\mfemms] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\masvc] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\masvc.exe" /ServiceStart'
- [<HKLM>\System\CurrentControlSet\Services\masvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\McAfeeFramework] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\x86\macompatsvc.exe"'
- [<HKLM>\System\CurrentControlSet\Services\macmnsvc] 'ImagePath' = '"%ProgramFiles%\McAfee\Agent\macmnsvc.exe" /ServiceStart'
- [<HKLM>\System\CurrentControlSet\Services\mfeavfk] 'ImagePath' = 'mfeavfk.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\mfeavfk] 'ImagePath' = 'system32\drivers\mfeavfk.sys'
- %TEMP%\mcafeelogs\frminst_wdmrjykoj.log
- %ProgramFiles%\mcafee\agent\ma_variant.dll
- %ProgramFiles%\mcafee\agent\ma_utils.dll
- %ProgramFiles%\mcafee\agent\ma_service_manager_client.dll
- %ProgramFiles%\mcafee\agent\ma_serialization.dll
- %ProgramFiles%\mcafee\agent\ma_repository.dll
- %ProgramFiles%\mcafee\agent\ma_proxy.dll
- %ProgramFiles%\mcafee\agent\ma_network.dll
- %ProgramFiles%\mcafee\agent\ma_msgbus_auth.sig
- %ProgramFiles%\mcafee\agent\ma_msgbus.dll
- %ProgramFiles%\mcafee\agent\ma_logger.dll
- %ProgramFiles%\mcafee\agent\ma_datastore.dll
- %ProgramFiles%\mcafee\agent\ma_database.dll
- %ProgramFiles%\mcafee\agent\ma_configurator.dll
- %ProgramFiles%\mcafee\agent\maconfig.exe
- %ProgramFiles%\mcafee\agent\ma_client.dll
- %ProgramFiles%\mcafee\agent\libuv.dll
- %ProgramFiles%\mcafee\agent\libini.dll
- %ProgramFiles%\mcafee\agent\libcurl.dll
- %ProgramFiles%\mcafee\agent\genevtinf5_64.dll
- %ProgramFiles%\mcafee\agent\cmdagent.exe
- %ProgramFiles%\mcafee\agent\cryptocme.sig
- %ProgramFiles%\mcafee\agent\cryptocme.dll
- %ProgramFiles%\mcafee\agent\ccme_asym.dll
- %ProgramFiles%\mcafee\agent\ccme_base_non_fips.dll
- %ProgramFiles%\mcafee\agent\ccme_base.dll
- %ProgramFiles%\mcafee\agent\ma_crypto.dll
- %ProgramFiles%\mcafee\agent\x86\msvcr100.dll
- %ProgramFiles%\mcafee\agent\mfeagent64.cat
- %ProgramFiles%\mcafee\agent\x86\msvcp100.dll
- %ProgramFiles%\mcafee\agent\masvc.exe
- %ProgramFiles%\mcafee\agent\macmnsvc.exe
- %ProgramFiles%\mcafee\agent\ma_updater_service.dll
- %ProgramFiles%\mcafee\agent\ma_udp_server.dll
- %ProgramFiles%\mcafee\agent\ma_udp_client.dll
- %ProgramFiles%\mcafee\agent\ma_sensor_service.dll
- %ProgramFiles%\mcafee\agent\ma_scheduler.dll
- %ProgramFiles%\mcafee\agent\ma_repository_service.dll
- %ProgramFiles%\mcafee\agent\ma_property_service.dll
- %ProgramFiles%\mcafee\agent\ma_policy_service.dll
- %ProgramFiles%\mcafee\agent\ma_p2p.dll
- %ProgramFiles%\mcafee\agent\microsoft.vc100.crt.manifest
- %ProgramFiles%\mcafee\agent\ma_xml.dll
- %ProgramFiles%\mcafee\agent\ma_http_server.dll
- %ProgramFiles%\mcafee\agent\ma_event_service.dll
- %ProgramFiles%\mcafee\agent\ma_datachannel_service.dll
- %ProgramFiles%\mcafee\agent\ma_ahclient.dll
- %ProgramFiles%\mcafee\agent\ma_aac_service.dll
- %ProgramFiles%\mcafee\agent\zlib.dll
- %ProgramFiles%\mcafee\agent\trex.dll
- %ProgramFiles%\mcafee\agent\sqlite.dll
- %ProgramFiles%\mcafee\agent\mxml.dll
- %ProgramFiles%\mcafee\agent\msvcr100.bin
- %ProgramFiles%\mcafee\agent\msvcp100.bin
- %ProgramFiles%\mcafee\agent\mfelpc.dll
- %ProgramFiles%\mcafee\agent\ma_io_service.dll
- %ProgramFiles%\mcafee\agent\mfecryptc.dll
- %ProgramFiles%\mcafee\agent\ma_lockdown_service.dll
- %ProgramFiles%\mcafee\agent\msvcp100.dll
- %ProgramFiles%\mcafee\agent\x86\userspace.dll
- %ProgramFiles%\mcafee\agent\x86\mxml.dll
- %ProgramFiles%\mcafee\agent\x86\0804\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\041f\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\041d\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0419\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0416\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0415\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0414\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0413\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0412\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0411\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0410\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\040c\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\040b\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\040a\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0407\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0406\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0405\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0404\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\0409\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\mue.exe
- %ProgramFiles%\mcafee\agent\x86\msvcr100.bin
- %ProgramFiles%\mcafee\agent\x86\msvcp100.bin
- %PROGRAMDATA%\mcafee\agent\ml_cacerts.cer
- %ProgramFiles%\mcafee\agent\x86\mfelpc.dll
- %ProgramFiles%\mcafee\agent\x86\nagshr32.dll
- %ProgramFiles%\mcafee\agent\x86\poevtinf.dll
- %ProgramFiles%\mcafee\agent\x86\0c0a\updres.dll
- %ProgramFiles%\mcafee\agent\x86\040c\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0410\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0816\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0804\updres.dll
- %ProgramFiles%\mcafee\agent\x86\041f\updres.dll
- %ProgramFiles%\mcafee\agent\x86\041d\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0419\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0416\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0415\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0414\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0413\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0412\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0411\updres.dll
- %ProgramFiles%\mcafee\agent\x86\zlib.dll
- %ProgramFiles%\mcafee\agent\x86\xmlwrap.dll
- %ProgramFiles%\mcafee\agent\x86\0816\mueres.dll
- %ProgramFiles%\mcafee\agent\x86\040a\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0407\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0406\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0405\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0404\updres.dll
- %ProgramFiles%\mcafee\agent\x86\0409\updres.dll
- %ProgramFiles%\mcafee\agent\x86\updaterui.exe
- %PROGRAMDATA%\mcafee\agent\update\updatemain.mcs
- %ProgramFiles%\mcafee\agent\x86\trex.dll
- %ProgramFiles%\mcafee\agent\x86\sqlite.dll
- %ProgramFiles%\mcafee\agent\x86\policyupgrade.exe
- %ProgramFiles%\mcafee\agent\x86\040b\updres.dll
- %ProgramFiles%\mcafee\agent\x86\cryptocme.dll
- %ProgramFiles%\mcafee\agent\msvcr100.dll
- %TEMP%\ma472c.tmp\x86\mfehidin.exe
- %TEMP%\ma472c.tmp\x64\mfeapfa.dll
- %TEMP%\ma472c.tmp\x86\mfeapfa.dll
- %TEMP%\ma472c.tmp\x64\mfecanary.exe
- %TEMP%\ma472c.tmp\x86\mfecanary.exe
- %TEMP%\ma472c.tmp\x64\mfecana.dll
- %TEMP%\ma472c.tmp\x86\mfecana.dll
- %TEMP%\ma472c.tmp\x64\aacinfo.exe
- %TEMP%\ma472c.tmp\x86\aacinfo.exe
- %TEMP%\ma472c.tmp\x64\mfeaaca.dll
- %TEMP%\ma472c.tmp\x86\mfeaaca.dll
- %TEMP%\ma472c.tmp\x64\cacheinfo.exe
- %TEMP%\ma472c.tmp\x86\cacheinfo.exe
- %TEMP%\ma472c.tmp\x86\vtpinfo.exe
- %TEMP%\ma472c.tmp\x64\ma50.xml
- %TEMP%\ma472c.tmp\x64\mfeavfa.dll
- %TEMP%\ma472c.tmp\x86\mfeavfa.dll
- %TEMP%\ma472c.tmp\x64\mfevtpa.dll
- %TEMP%\ma472c.tmp\x86\mfevtpa.dll
- %TEMP%\ma472c.tmp\x64\mfehida.dll
- %TEMP%\ma472c.tmp\x86\mfehida.dll
- %TEMP%\ma472c.tmp\x64\mfeavfk.cat
- %TEMP%\ma472c.tmp\x86\mfeavfk.cat
- %TEMP%\ma472c.tmp\x64\mfeavfk.inf
- %TEMP%\ma472c.tmp\x86\mfeavfk.inf
- %TEMP%\ma472c.tmp\x64\mfehidin.exe
- %TEMP%\ma472c.tmp\x64\vtpinfo.exe
- %WINDIR%\installer\msi2117.tmp
- %TEMP%\mcafeelogs\ma_vscore_install_20190720t024305.log
- %CommonProgramFiles%\mcafee\systemcore\cacheinfo.exe
- %CommonProgramFiles%\mcafee\systemcore\vtpinfo.exe
- %CommonProgramFiles%\mcafee\systemcore\mfeavfa.dll
- %CommonProgramFiles%\mcafee\systemcore\mfevtpa.dll
- %CommonProgramFiles%\mcafee\systemcore\mfehida.dll
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\2.cat
- <DRIVERS>\seta664.tmp
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\1.cat
- <DRIVERS>\seta0a7.tmp
- %WINDIR%\temp\udd8977.tmp
- %WINDIR%\temp\tar864e.tmp
- %TEMP%\ma472c.tmp\x64\mfeavfk.sys
- %WINDIR%\temp\cab864d.tmp
- %TEMP%\ma472c.tmp\x86\ma50.xml
- %WINDIR%\temp\tar85ec.tmp
- %WINDIR%\temp\cab85eb.tmp
- %CommonProgramFiles%\mcafee\systemcore\mfehidk_messages.dll
- <DRIVERS>\mfehidk.sys
- <SYSTEM32>\mfevtps.exe
- %CommonProgramFiles%\mcafee\systemcore\mfemms.exe
- %CommonProgramFiles(x86)%\mcafee\systemcore\mfemmsa.dll
- %CommonProgramFiles%\mcafee\systemcore\mmsinfo.exe
- %CommonProgramFiles%\mcafee\systemcore\mfemms_messages.dll
- %CommonProgramFiles%\mcafee\systemcore\mfemmsa.dll
- %TEMP%\mcafeelogs\ma_vscore_install_20190720t024305.etl
- %WINDIR%\temp\tar862c.tmp
- %TEMP%\ma472c.tmp\x86\mfeavfk.sys
- %CommonProgramFiles%\mcafee\systemcore\mfeaaca.dll
- %TEMP%\ma472c.tmp\x64\mfeaack.cat
- %TEMP%\ma472c.tmp\x86\mfeaack.cat
- %PROGRAMDATA%\mcafee\agent\db\matask.db-journal
- %ProgramFiles%\mcafee\agent\x86\mfecryptc.dll
- %PROGRAMDATA%\mcafee\agent\db\mapolicy.db-journal
- %PROGRAMDATA%\mcafee\agent\db\ma.db
- %PROGRAMDATA%\mcafee\agent\db\ma.db-journal
- %PROGRAMDATA%\mcafee\agent\keystore\serverreqseckey.bin
- %PROGRAMDATA%\mcafee\agent\keystore\serverpubkey.bin
- %PROGRAMDATA%\mcafee\agent\keystore\agentprvkey.bin
- %PROGRAMDATA%\mcafee\agent\keystore\agentpubkey.bin
- %TEMP%\mcafeelogs\maconfig.log
- %WINDIR%\installer\msi336d.tmp
- %WINDIR%\installer\msi31f5.tmp
- %PROGRAMDATA%\mcafee\agent\db\matask.db
- %PROGRAMDATA%\mcafee\agent\db\macmnsvc.db-journal
- %PROGRAMDATA%\mcafee\agent\frameworkmanifest.xml_rollback
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\mfeagent64.cat
- %WINDIR%\installer\msi2ea7.tmp
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\mfeagent.cat
- %WINDIR%\installer\msi2e57.tmp
- %WINDIR%\installer\msi232b.tmp
- %WINDIR%\installer\{2caf387b-9488-4a32-b251-7850b718663f}\arpproducticon.exe
- %PROGRAMDATA%\mcafee\agent\svc_x86.cab
- %PROGRAMDATA%\mcafee\agent\svc_x64.cab
- %PROGRAMDATA%\mcafee\agent\shared64.cab
- %PROGRAMDATA%\mcafee\agent\shared.cab
- %PROGRAMDATA%\mcafee\agent\mfeagent_x64.msi
- %WINDIR%\installer\msi31c5.tmp
- %WINDIR%\installer\msi30f9.tmp
- %ProgramFiles%\mcafee\agent\x86\0c0a\mueres.dll
- %PROGRAMDATA%\mcafee\agent\serversitelist.xml
- %TEMP%\ma472c.tmp\x86\mfemmsa.dll
- %TEMP%\ma472c.tmp\x64\mfemmsa.dll
- %TEMP%\ma472c.tmp\x86\mfeaack.inf
- %TEMP%\ma472c.tmp\x64\mfeaack.sys
- %TEMP%\ma472c.tmp\x86\mfeaack.sys
- %TEMP%\ma472c.tmp\x64\mfemms.exe
- %TEMP%\ma472c.tmp\x86\mfemms.exe
- %TEMP%\ma472c.tmp\x64\mmsinfo.exe
- %TEMP%\ma472c.tmp\x86\mmsinfo.exe
- %TEMP%\ma472c.tmp\x64\mfestwa.dll
- %TEMP%\ma472c.tmp\x86\mfestwa.dll
- %TEMP%\ma472c.tmp\x64\mfemms_messages.dll
- %TEMP%\ma472c.tmp\x86\mfemms_messages.dll
- %TEMP%\ma472c.tmp\x64\mfeaack.inf
- %PROGRAMDATA%\mcafee\agent\db\macmnsvc.db
- %PROGRAMDATA%\mcafee\agent\db\mapolicy.db
- %TEMP%\ma472c.tmp\x86\mfehidk_messages.dll
- %TEMP%\ma472c.tmp\x64\mfevtps.exe
- %TEMP%\ma472c.tmp\x86\mfevtps.exe
- %TEMP%\ma472c.tmp\x64\mfehidk.sys
- %TEMP%\ma472c.tmp\x86\mfehidk.sys
- %TEMP%\ma472c.tmp\ma50.cab
- %WINDIR%\installer\msi46d8.tmp
- %WINDIR%\installer\msi3ce4.tmp
- %PROGRAMDATA%\mcafee\agent\db\mascheduler.db
- %PROGRAMDATA%\mcafee\agent\db\mascheduler.db-journal
- %PROGRAMDATA%\mcafee\agent\cabundle.cer
- %TEMP%\ma472c.tmp\x64\mfehidk_messages.dll
- %ProgramFiles%\mcafee\agent\x86\mfeagent.cat
- %ProgramFiles%\mcafee\agent\x86\mctray.exe
- %ProgramFiles%\mcafee\agent\x86\mcscancheck.exe
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\tray_menu_okay.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_warning_medium.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_ok_medium.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\system_status_error_medium.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\splashscreen.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\rule_folder_closed.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\plus_sign.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\outbound.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\no_symbol.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\minus_sign.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\mcafee_m_small.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\main_window.ini
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\inbound.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\group_folder_closed.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\grip.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gray_checked.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gradated_background_with_mcafee_logo.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\gradated_background.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\folder_open.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\folder_closed.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\document.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\disallow.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_open_pressed.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_open_normal.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_close_pressed.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\unchecked.png
- %ProgramFiles%\mcafee\agent\x86\mctrayinstsupp.dll
- %ProgramFiles%\mcafee\agent\x86\0409\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0412\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0413\mctrayres.dll
- %PROGRAMDATA%\mcafee\agent\data\logging\agentlog.html
- %ProgramFiles%\mcafee\agent\x86\microsoft.vc100.crt.manifest
- %ProgramFiles%\mcafee\agent\x86\0c0a\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0816\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0804\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\041f\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\041d\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0419\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0416\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0415\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0414\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\tray_menu_issue.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\details_close_normal.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\checked.png
- %ProgramFiles%\mcafee\agent\x86\0410\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\040c\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\040b\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\040a\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0407\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0406\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0405\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0404\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\0409\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\mctraylegacysupportplugin32.dll
- %ProgramFiles%\mcafee\agent\x86\mctrayinterfacelib.dll
- %ProgramFiles%\mcafee\agent\x86\0411\mctrayres.dll
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\checkmark.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_up.png
- %WINDIR%\installer\msie033.tmp
- %TEMP%\mfe6d57.tmp\agentfipsmode
- %WINDIR%\installer\msic5f9.tmp
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\main.txt
- %WINDIR%\installer\msic53d.tmp
- %WINDIR%\installer\f792e.msi
- %TEMP%\mcafeelogs\mfeagent.msi.2019.07.20.02.42.12.log
- %TEMP%\mcafeelogs\frminst_wdmrjykoj_error.log
- %TEMP%\mfe6d57.tmp\hashes.xml
- %TEMP%\mfe6d57.tmp\packageinfo.xml
- %TEMP%\mfe6d57.tmp\bootstrapinfo.xml
- %TEMP%\mfe6d57.tmp\sr2048pubkey.bin
- %TEMP%\mfe6d57.tmp\req2048seckey.bin
- %ProgramFiles%\mcafee\agent\x86\0404\agentres.dll
- %WINDIR%\installer\f7931.ipi
- %TEMP%\mfe6d57.tmp\srpubkey.bin
- %TEMP%\mfe6d57.tmp\sitelist.xml
- %TEMP%\mfe6d57.tmp\reqseckey.bin
- %TEMP%\mfe6d57.tmp\svc_x86.cab
- %TEMP%\mfe6d57.tmp\svc_x64.cab
- %TEMP%\mfe6d57.tmp\shared64.cab
- %TEMP%\mfe6d57.tmp\shared.cab
- %TEMP%\mfe6d57.tmp\mfeagent_x64.msi
- %TEMP%\mfe6d57.tmp\mfeagent.msi
- %TEMP%\mfe6d57.tmp\frminst.exe
- %TEMP%\mfe6d57.tmp\cleanup.exe
- %TEMP%\mfe6d57.tmp\__temp.zip
- %TEMP%\mfe6d57.tmp\repokeys.ini
- %WINDIR%\temp\udda772.tmp
- %WINDIR%\installer\msic763.tmp
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\req2048seckey.bin
- %WINDIR%\installer\msicb9a.tmp
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_hover.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_down.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\button_disabled.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\bidirectional.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\allow.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\advisory_dlg.png
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\advisory_dlg.ini
- %ProgramFiles%\mcafee\agent\x86\mctrayeventlog.dll
- %ProgramFiles%\mcafee\agent\x86\mctrayerrorloggingplugin.dll
- %ProgramFiles%\mcafee\agent\x86\mcafeewin32guisupportdll.dll
- %ProgramFiles%\mcafee\agent\x86\mcafeecommonupdaterplugin.dll
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\reqseckey.bin
- %ProgramFiles%\mcafee\agent\x86\componentpointproduct.dll
- %WINDIR%\installer\msic704.tmp
- %WINDIR%\installer\msidfc5.tmp
- %WINDIR%\installer\msiddc0.tmp
- %WINDIR%\installer\msidd91.tmp
- %WINDIR%\installer\msidb2e.tmp
- %WINDIR%\installer\msid793.tmp
- C:\config.msi\f7932.rbs
- %WINDIR%\installer\msicc27.tmp
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\repokeys.ini
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\agentfipsmode
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\sr2048pubkey.bin
- %TEMP%\{2caf387b-9488-4a32-b251-7850b718663f}\srpubkey.bin
- %WINDIR%\installer\msi185b.tmp
- %WINDIR%\temp\cab862b.tmp
- %ProgramFiles%\mcafee\agent\x86\0405\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\040a\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\libcurl.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compat_framework_factory.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compat_agent.dll
- %ProgramFiles%\mcafee\agent\x86\ma_client.dll
- %PROGRAMDATA%\mcafee\agent\data\logging\js\json2.js
- %PROGRAMDATA%\mcafee\agent\data\logging\js\agentlog.js
- %PROGRAMDATA%\mcafee\agent\data\logging\css\desc.gif
- %PROGRAMDATA%\mcafee\agent\data\logging\css\bg.gif
- %PROGRAMDATA%\mcafee\agent\data\logging\css\asc.gif
- %PROGRAMDATA%\mcafee\agent\data\logging\css\agentlog.css
- %ProgramFiles%\mcafee\agent\license.txt
- %ProgramFiles%\mcafee\agent\x86\libuv.dll
- %ProgramFiles%\mcafee\agent\x86\libini.dll
- %PROGRAMDATA%\mcafee\agent\update\installmain.mcs
- %ProgramFiles%\mcafee\agent\x86\ma_compat_scheduler.dll
- %ProgramFiles%\mcafee\agent\x86\mctray\gui_redirect.ini
- %ProgramFiles%\mcafee\agent\x86\genevtinf5.dll
- %ProgramFiles%\mcafee\agent\x86\frminst.exe
- %PROGRAMDATA%\mcafee\agent\frameworkmanifest.xml
- %ProgramFiles%\mcafee\agent\x86\componentuserinterface.dll
- %ProgramFiles%\mcafee\agent\x86\0c0a\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0816\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0804\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\041f\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\041d\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\mctray\images\mcafee\trailer.png
- %ProgramFiles%\mcafee\agent\x86\ma_compat_subsystem.dll
- %ProgramFiles%\mcafee\agent\x86\marepomirror.exe
- %ProgramFiles%\mcafee\agent\x86\ma_proxy.dll
- %ProgramFiles%\mcafee\agent\x86\ma_repository.dll
- %ProgramFiles%\mcafee\agent\x86\macompatsvc.exe
- %PROGRAMDATA%\mcafee\agent\certstore\mfeca_2014_2017.cer
- %PROGRAMDATA%\mcafee\agent\certstore\mfeca.cer
- %PROGRAMDATA%\mcafee\agent\certstore\mfe_sia_ca_signer.pem.cer
- %PROGRAMDATA%\mcafee\agent\certstore\mfe_sia_ca_root.pem.cer
- %ProgramFiles%\mcafee\agent\x86\ma_xml.dll
- %ProgramFiles%\mcafee\agent\x86\ma_variant.dll
- %ProgramFiles%\mcafee\agent\x86\ma_utils.dll
- %ProgramFiles%\mcafee\agent\x86\ma_udp_client.dll
- %ProgramFiles%\mcafee\agent\x86\ma_service_manager_client.dll
- %ProgramFiles%\mcafee\agent\x86\ma_serialization.dll
- %ProgramFiles%\mcafee\agent\x86\0419\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0416\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compat_updater.dll
- %ProgramFiles%\mcafee\agent\x86\ma_msgbus_auth.sig
- %ProgramFiles%\mcafee\agent\x86\ma_msgbus.dll
- %ProgramFiles%\mcafee\agent\x86\ma_logger.dll
- %ProgramFiles%\mcafee\agent\x86\ma_datastore.dll
- %ProgramFiles%\mcafee\agent\x86\ma_database.dll
- %ProgramFiles%\mcafee\agent\x86\ma_crypto.dll
- %ProgramFiles%\mcafee\agent\x86\ma_configurator.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compatplugin.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compatlpc.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compatdata.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compatbase.dll
- %ProgramFiles%\mcafee\agent\x86\ma_network.dll
- %ProgramFiles%\mcafee\agent\x86\ma_compat_logger.dll
- %ProgramFiles%\mcafee\agent\x86\0415\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0414\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0406\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\041f\agentres.dll
- %ProgramFiles%\mcafee\agent\0410\agentres.ini
- %ProgramFiles%\mcafee\agent\040c\agentres.ini
- %ProgramFiles%\mcafee\agent\040b\agentres.ini
- %ProgramFiles%\mcafee\agent\040a\agentres.ini
- %ProgramFiles%\mcafee\agent\0407\agentres.ini
- %ProgramFiles%\mcafee\agent\0406\agentres.ini
- %ProgramFiles%\mcafee\agent\0405\agentres.ini
- %ProgramFiles%\mcafee\agent\0404\agentres.ini
- %ProgramFiles%\mcafee\agent\0409\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0c0a\agentres.dll
- %ProgramFiles%\mcafee\agent\0413\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0816\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0804\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\041d\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0419\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0416\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0415\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0414\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0413\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0412\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0411\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\0410\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\040c\agentres.dll
- %ProgramFiles%\mcafee\agent\x86\040b\agentres.dll
- %ProgramFiles%\mcafee\agent\0412\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0407\agentres.dll
- %ProgramFiles%\mcafee\agent\0415\agentres.ini
- %ProgramFiles%\mcafee\agent\0419\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0413\cmauires.dll
- %ProgramFiles%\mcafee\agent\0414\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0412\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0411\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0410\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\040c\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\040b\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\040a\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0407\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0406\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0405\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\0404\cmauires.dll
- %ProgramFiles%\mcafee\agent\0416\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\0409\cmauires.dll
- %ProgramFiles%\mcafee\agent\x86\cryptocme.sig
- %ProgramFiles%\mcafee\agent\0411\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\ccme_asym.dll
- %ProgramFiles%\mcafee\agent\x86\ccme_base_non_fips.dll
- %ProgramFiles%\mcafee\agent\x86\ccme_base.dll
- %ProgramFiles%\mcafee\agent\x86\boost_thread-vc100-mt-1_39.dll
- %ProgramFiles%\mcafee\agent\x86\boost_system-vc100-mt-1_39.dll
- %ProgramFiles%\mcafee\agent\0c0a\agentres.ini
- %ProgramFiles%\mcafee\agent\0816\agentres.ini
- %ProgramFiles%\mcafee\agent\0804\agentres.ini
- %ProgramFiles%\mcafee\agent\041f\agentres.ini
- %ProgramFiles%\mcafee\agent\041d\agentres.ini
- %ProgramFiles%\mcafee\agent\x86\clientui.dll
- %WINDIR%\temp\uddacf1.tmp
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\mfeagent.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\mfeagent64.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\1.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\2.cat
- %WINDIR%\installer\msic53d.tmp
- %PROGRAMDATA%\mcafee\agent\db\ma.db-journal
- %PROGRAMDATA%\mcafee\agent\db\mapolicy.db-journal
- %PROGRAMDATA%\mcafee\agent\db\matask.db-journal
- %PROGRAMDATA%\mcafee\agent\db\macmnsvc.db-journal
- %PROGRAMDATA%\mcafee\agent\db\mascheduler.db-journal
- %WINDIR%\installer\msi336d.tmp
- %WINDIR%\temp\cab85eb.tmp
- %WINDIR%\temp\udda772.tmp
- %WINDIR%\temp\tar85ec.tmp
- %WINDIR%\temp\cab862b.tmp
- %WINDIR%\temp\tar862c.tmp
- %WINDIR%\temp\cab864d.tmp
- %WINDIR%\temp\tar864e.tmp
- %WINDIR%\temp\udd8977.tmp
- %WINDIR%\installer\msi31f5.tmp
- %WINDIR%\installer\msi3ce4.tmp
- %WINDIR%\installer\msi31c5.tmp
- %WINDIR%\installer\msidd91.tmp
- %WINDIR%\installer\msic5f9.tmp
- %WINDIR%\installer\msic704.tmp
- %WINDIR%\installer\msicb9a.tmp
- %WINDIR%\installer\msicc27.tmp
- %WINDIR%\installer\msid793.tmp
- %WINDIR%\installer\msidb2e.tmp
- %WINDIR%\installer\msiddc0.tmp
- %WINDIR%\installer\msi2ea7.tmp
- %WINDIR%\installer\msidfc5.tmp
- %WINDIR%\installer\msie033.tmp
- %WINDIR%\installer\msi185b.tmp
- %WINDIR%\installer\msi2117.tmp
- %WINDIR%\installer\msi232b.tmp
- %WINDIR%\installer\msi2e57.tmp
- %WINDIR%\installer\msi30f9.tmp
- %WINDIR%\temp\uddacf1.tmp
- from <DRIVERS>\seta0a7.tmp to <DRIVERS>\mfeaack.sys
- from <DRIVERS>\seta664.tmp to <DRIVERS>\mfeavfk.sys
- %PROGRAMDATA%\mcafee\agent\db\ma.db-journal
- %PROGRAMDATA%\mcafee\agent\db\mapolicy.db-journal
- %PROGRAMDATA%\mcafee\agent\db\mascheduler.db-journal
- '%TEMP%\mfe6d57.tmp\frminst.exe' /FramePkg /OriginalFramePkg="<Full path to file>" /Cleanup="%TEMP%\mfe6D57.tmp" /LOGDIR="%TEMP%\McAfeeLogs" /EmbeddedUsername="" /EmbeddedDomain="" /EmbeddedPassword=""
- '%ProgramFiles%\mcafee\agent\x86\macompatsvc.exe' /Service
- '%ProgramFiles%\mcafee\agent\maconfig.exe' -provision -managed -dir "%TEMP%\mfe6D57.tmp" -logdir "%TEMP%\McAfeeLogs" -nostart -check
- '%TEMP%\ma472c.tmp\x64\mfehidin.exe' -i ma50 -x ma50.xml -mfetrust_off -l "%TEMP%\McAfeeLogs\ma_vscore_install_20190720T024305.log" -etl "%TEMP%\McAfeeLogs\ma_vscore_install_20190720T024305.etl"
- '%CommonProgramFiles%\mcafee\systemcore\mfemms.exe'
- '<SYSTEM32>\mfevtps.exe' -mms
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq Mue_InUse.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq McScript_InUse.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UpdaterUI.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UdaterUI.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq masvc.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macmnsvc.exe" /FO CSV /NH' (with hidden window)
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macompatsvc.exe" /FO CSV /NH' (with hidden window)
- '%ProgramFiles%\mcafee\agent\maconfig.exe' -provision -managed -dir "%TEMP%\mfe6D57.tmp" -logdir "%TEMP%\McAfeeLogs" -nostart -check' (with hidden window)
- '%WINDIR%\syswow64\msiexec.exe' /i "%TEMP%\mfe6D57.tmp\MFEagent_x64.msi" ADDLOCAL=Main,Agent,Svc_x64 TRANSFORMS=:1033.mst /qb+ /l+*v "%TEMP%\McAfeeLogs\MFEagent.msi.2019.07.20.02.42.12.log" SITELISTINFO="%TEMP%\mfe6D57.tmp" P...
- '<SYSTEM32>\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\genevtinf5_64.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\genevtinf5.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\UserSpace.Dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_updater.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_subsystem.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_scheduler.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_logger.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_framework_factory.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ma_compat_agent.dll"
- '%WINDIR%\syswow64\msiexec.exe' /Y "%ProgramFiles%\McAfee\Agent\x86\ComponentUserInterface.dll"
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macompatsvc.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq macmnsvc.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq masvc.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UdaterUI.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq UpdaterUI.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq McScript_InUse.exe" /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FO CSV /NH
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq Mue_InUse.exe" /FO CSV /NH
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\Installer\MSIDB2E.tmp",rundll_invoke release_from_ap
- '%WINDIR%\syswow64\msiexec.exe' -Embedding 71F4B2E91B86BBDE15A5C98E47B28129 M Global\MSI0000
- '%WINDIR%\syswow64\msiexec.exe' -Embedding 0E6E22CF8959ADC08CEBE1DC3103DCD0
- '<SYSTEM32>\wevtutil.exe' um aacetw.man
- '<SYSTEM32>\wevtutil.exe' im aacetw.man