Agent.exe

AgentUI

Iron Mountain Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AgentUiRunKey’. This is installed with multiple programs including Connected Backup/PC Agent and EY Personal Backup Agent.
Publisher:
Iron Mountain Incorporated  (signed by Iron Mountain Inc)

Product:
AgentUI

Description:
Agent User Interface

Version:
8,2,2,6002

MD5:
7567bbc3803dda5a5abdac4842263655

SHA-1:
f8272a814dafe67cf6e01f86c65480ef2287d46b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/7/2025 3:32:50 PM UTC  (today)

File size:
238.8 KB (244,536 bytes)

Product version:
8,2,2,1

Copyright:
Copyright (c) 1996-2008 Iron Mountain Incorporated. All rights reserved.

Original file name:
Agent.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\remote data backups\agent.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2006 8:00:00 PM

Valid to:
6/21/2009 7:59:59 PM

Subject:
CN=Iron Mountain Inc, OU=Iron Mountain Digital, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Iron Mountain Inc, L=Framingham, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6364166F550FCA5B07B0A55E4F185BF1

File PE Metadata
Compilation timestamp:
11/22/2005 3:24:26 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:Y4Eg40zE7NP0MOc6HkY3wT66vlm5svn0F4xWyHHj2Dh9:V940ABv/u4ZO

Entry address:
0x11D8

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.1087

Code size:
118 KB (120,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AgentUiRunKey

Command:
"C:\Program Files\remote data backups\agent.exe" -ni -sss -e httC:\localhosC:16386\


The file Agent.exe has been discovered within the following programs.

Cadbury Backup Agent  by Iron Mountain
About 9% of users remove it
Connected Backup/PC Agent  by Iron Mountain
About 8% of users remove it
EY Personal Backup Agent  by Iron Mountain
About 4% of users remove it
 
Powered by Should I Remove It?

Scan Agent.exe - Powered by Reason Core Security