ozt3vmfzm1cw.exe

2007 Microsoft Office system

Inergen

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable ozt3vmfzm1cw.exe, “2007 Microsoft Office component” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Inergen)

Product:
2007 Microsoft Office system

Description:
2007 Microsoft Office component

Version:
12.0.6606.1000

MD5:
47d7286796590c5ccee28ce5a935c02d

SHA-1:
2a5b5f628f45df093a3fd5b4018ac23d6d47a4c8

SHA-256:
d2fe5b7cdb23ae6874c351e9cae37a1fea9ce082dea84ef834a99f6ff7f9b50c

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
8/6/2025 10:13:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.16.10

File size:
593.5 KB (607,744 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
SetLang.Exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\ozt3vmfzm1cw.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/25/2016 3:00:00 AM

Valid to:
5/26/2017 2:59:59 AM

Subject:
CN=Inergen, O=Inergen, STREET="AVENUE VOLGOGRAD, House 93, Building 2, ROOM II ROOM 12,", L=Moscow, S=Moscow, PostalCode=109117, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C9BE03B759B3C958ED3BBFB001506309

File PE Metadata
Compilation timestamp:
6/18/2016 6:18:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, B0, 03, 00, 00, C6, 85, 44, FF, FF, FF, EA, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 1C, 19, 49, 00, 89, 2D, FC, 18, 49, 00, C6, 85, 05, FE, FF, FF, ED, A1, 2C, C0, 48, 00, A3, 44, 19, 49, 00, 8B, 0D, 44, 19, 49, 00, 89, 8D, 40, FE, FF, FF, C7, 85, 3C, FE, FF, FF, 00, 00, 00, 00, 68, 48, 19, 49, 00, 8B, 15, 48, 10, 49, 00, 52, 68, 00, 00, 00, 80, FF, 95, 40, FE, FF, FF, 89, 85, 44, FE, FF, FF, 83, BD, 44, FE, FF, FF, 00, 74, 02, CD, 05, C6, 85, 10, FD, FF, FF, 48, E8, 82, 03, 00, 00, A3, 24...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
554.5 KB (567,808 bytes)

Remove ozt3vmfzm1cw.exe - Powered by Reason Core Security