Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Collecting the User-Mode Hooking (UMH) module's service and driver logs

    • Updated:
    • 13 Mar 2020
    • Product/Version:
    • Apex One 2019
    • Apex One All.All
    • OfficeScan 10.6
    • OfficeScan 11.0
    • OfficeScan 11.0
    • OfficeScan XG
    • OfficeScan XG.All
    • Platform:
    • Windows 10
    • Windows 2008 32-Bit
    • Windows 2008 64-Bit
    • Windows 2012
    • Windows 7 32-Bit
    • Windows 7 64-Bit
    • Windows 8 32-Bit
    • Windows 8 64-Bit
    • Windows 8.1 32-Bit
    • Windows 8.1 64-Bit

This article introduces how to collect the UMH service and driver logs if required.

UMH is an engine in OSCE and Apex One that supports the enhanced ransomware solution. It is installed in the Common Client Solution Framework (CCSF) service as a module. It provides API events for other modules, such as Behavior Monitoring, Predictive Machine Learning, etc. Those modules will make decisions according to the provided API events from UMH.

Below is the installation path for UMH:

<Agent Installation Path>\CCSF\MODULE\20019\

UMH has been involved since OfficeScan 11.0 Service Pack 1 Critical Patch 6054 (Ransomware CP) and OfficeScan XG.


To collect the logs:

  1. Depending on your version:
    • For OfficeScan:
      1. Copy\PCCSRV\Private\LogServer\ofcdebugEx.ini from the OSCE server to C:\ in the OSCE agent.
      2. Rename ofcdebugEx.ini to ofcdebug.ini.
    • For Apex One:
      1. Copy the ofcdebug.ini of the \Program Files (x86)\Trend Micro\OfficeScan Client\Temp\LogServer\ folder (excluding the Log folder) to the root of C:.
      2. Edit the ofcdebug.ini file now located in the root of C::
        1. Change DebugLog=.\Log\ofcdebug.log to "DebugLog=.\ofcdebug.log".
        2. Change debugLevel_new=E to "debugLevel_new=D".
        3. Change ForceStopOtherLogserver=0 to "ForceStopOtherLogserver=1".

          If larger logs are desired, you can edit the debugSplitSize line. Default is 10 MB before splitting and zipping the old file.

          By default DebugMaxSplit=100, this limits the total number of split logs to 100 files.

        4. Save the file.
  2. Unload the agent.
  3. Open a command line. Run as administrator.
  4. Run the following prompt: net stop tmumh (Stop UMH driver).
  5. Download DebugView from the following link: DebugView v4.81.
  6. Open Dbgview.exe (Run as administrator), and check Capture Win32, Capture Global Win32, Caputer Kernel, Enable Verbose Kernel Output, Pass-Through, and Capture Events from the Caputer dropdown list.

    Caputer dropdown list

  7. Reload the agent, and make sure that the tmccsf.exe, tmbmsrv.exe, ntrtscan.exe and tmlisten.exe processes are running. Also make sure that tmumh is running (sc query tmumh).
  8. Reproduce the problem.
  9. Collect the following logs:
    • C:\CCSF_DebugLog.log
    • C:\osceDB.log
    • Driver log from Dbgview.exe

    Collect logs for UMH

  10. Get the following UMH-related binary files:
    • \CCSF\module\20019
    • %windir%\system32\tmumh
    • %windir%\syswow64\tmumh
    • %windir%\system32\drivers\tmumh.sys
  11. Get the following UMH-related registry keys:
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmumh
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\GlobalFlag
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
    • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Solution Id:
Did this article help you?

Thank you for your feedback!

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.