7ehygvespmrg.exe

2007 Microsoft Office system

OOO IA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application 7ehygvespmrg.exe, “Microsoft Script Editor” by OOO IA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by OOO IA )

Product:
2007 Microsoft Office system

Description:
Microsoft Script Editor

Version:
12.0.6606.1000

MD5:
57095c3e6973820bb4ba66ea11d3a5f7

SHA-1:
c85a27172a74df8a6066c0c4d6431e7421cca265

SHA-256:
1b42b60d66b6bb4e3c7cb2ae176c87f64efd8838206eede4b86eb9ede3731f43

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 4:29:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler.MS (M)
17.2.4.10

File size:
590.5 KB (604,704 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
mse.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\7ehygvespmrg.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2016 3:00:00 AM

Valid to:
7/9/2017 2:59:59 AM

Subject:
CN="OOO IA ""Lyuks""", O="OOO IA ""Lyuks""", STREET=8 ul. Partizana Zheleznyaka, L=Krasnoyarsk, S=Krasnoyarskaia, PostalCode=660022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5C165256CF6133E0C9777EBA9682BD31

File PE Metadata
Compilation timestamp:
8/2/2016 1:17:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, BC, 02, 00, 00, 53, 56, 57, C6, 85, 67, FF, FF, FF, 1D, EB, 02, CD, 4F, EB, 02, 87, F7, 68, 23, 10, 40, 00, C3, CD, 83, EB, 01, 55, 8B, C0, 68, 30, 10, 40, 00, C3, 33, DD, 68, 37, 10, 40, 00, C3, 56, EB, 02, 2B, E3, C1, E8, 00, 68, 80, 20, 49, 00, FF, 15, D8, A0, 48, 00, 68, 17, 17, 00, 00, A1, 94, 2E, 49, 00, 50, FF, 15, 44, A5, 48, 00, 85, C0, 74, 05, E8, 9D, FF, FF, FF, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 9C, 2E, 49, 00, 89, 2D, 7C, 2E, 49, 00, 68, 61, 1E, 00, 00, 8B, 0D, 94, 2E, 49...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
545 KB (558,080 bytes)

Remove 7ehygvespmrg.exe - Powered by Reason Core Security