1wcp6mzbgchz.exe

2007 Microsoft Office system

OOO IA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application 1wcp6mzbgchz.exe, “Microsoft Script Editor” by OOO IA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by OOO IA )

Product:
2007 Microsoft Office system

Description:
Microsoft Script Editor

Version:
12.0.6606.1000

MD5:
4064053ba2da2cc0288b316583b7d2a6

SHA-1:
25332eab48bcd9e5ed5736ce16721a92747b7358

SHA-256:
104972d85401c4026715712fa6fdb578d602c7cff311b194da0b82cf3fc5cae6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 4:51:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler.MS (M)
17.3.1.21

File size:
590.5 KB (604,704 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
mse.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\1wcp6mzbgchz.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2016 2:00:00 AM

Valid to:
7/9/2017 1:59:59 AM

Subject:
CN="OOO IA ""Lyuks""", O="OOO IA ""Lyuks""", STREET=8 ul. Partizana Zheleznyaka, L=Krasnoyarsk, S=Krasnoyarskaia, PostalCode=660022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5C165256CF6133E0C9777EBA9682BD31

File PE Metadata
Compilation timestamp:
8/2/2016 12:17:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, BC, 02, 00, 00, 53, 56, 57, C6, 85, 67, FF, FF, FF, 1D, EB, 02, CD, 4F, EB, 02, 87, F7, 68, 23, 10, 40, 00, C3, CD, 83, EB, 01, 55, 8B, C0, 68, 30, 10, 40, 00, C3, 33, DD, 68, 37, 10, 40, 00, C3, 56, EB, 02, 2B, E3, C1, E8, 00, 68, 80, 20, 49, 00, FF, 15, D8, A0, 48, 00, 68, 17, 17, 00, 00, A1, 94, 2E, 49, 00, 50, FF, 15, 44, A5, 48, 00, 85, C0, 74, 05, E8, 9D, FF, FF, FF, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 9C, 2E, 49, 00, 89, 2D, 7C, 2E, 49, 00, 68, 61, 1E, 00, 00, 8B, 0D, 94, 2E, 49...
 
[+]

Entropy:
6.8258

Developed / compiled with:
Microsoft Visual C++

Code size:
545 KB (558,080 bytes)

Remove 1wcp6mzbgchz.exe - Powered by Reason Core Security