cgma4nma7706.exe

2007 Microsoft Office system

OOO IA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application cgma4nma7706.exe, “Microsoft Script Editor” by OOO IA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by OOO IA )

Product:
2007 Microsoft Office system

Description:
Microsoft Script Editor

Version:
12.0.6606.1000

MD5:
16add8b8e2daaa5cb703fedaa31afc3c

SHA-1:
ff158948323ceac13f472d0cc8f1bdc43ad29997

SHA-256:
c5040bdff44e2c602e04771e5868ea2fb74e21f4d7251dca9b31ee738c6445ee

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 4:58:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler.MS (M)
17.1.10.16

File size:
590.5 KB (604,704 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
mse.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\cgma4nma7706.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2016 3:00:00 AM

Valid to:
7/9/2017 2:59:59 AM

Subject:
CN="OOO IA ""Lyuks""", O="OOO IA ""Lyuks""", STREET=8 ul. Partizana Zheleznyaka, L=Krasnoyarsk, S=Krasnoyarskaia, PostalCode=660022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5C165256CF6133E0C9777EBA9682BD31

File PE Metadata
Compilation timestamp:
8/2/2016 1:17:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, BC, 02, 00, 00, 53, 56, 57, C6, 85, 67, FF, FF, FF, 1D, EB, 02, CD, 4F, EB, 02, 87, F7, 68, 23, 10, 40, 00, C3, CD, 83, EB, 01, 55, 8B, C0, 68, 30, 10, 40, 00, C3, 33, DD, 68, 37, 10, 40, 00, C3, 56, EB, 02, 2B, E3, C1, E8, 00, 68, 80, 20, 49, 00, FF, 15, D8, A0, 48, 00, 68, 17, 17, 00, 00, A1, 94, 2E, 49, 00, 50, FF, 15, 44, A5, 48, 00, 85, C0, 74, 05, E8, 9D, FF, FF, FF, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 9C, 2E, 49, 00, 89, 2D, 7C, 2E, 49, 00, 68, 61, 1E, 00, 00, 8B, 0D, 94, 2E, 49...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
545 KB (558,080 bytes)

Remove cgma4nma7706.exe - Powered by Reason Core Security