beservice.exe

Bastian Suter

This is a setup program which is used to install the application. It runs as a separate (within the context of its own process) windows Service named “BattlEye Service”. The file has been seen being downloaded from www.battleye.com.
Publisher:
Bastian Suter  (signed and verified)

MD5:
50b6fce5325180ea217eae73202cb6db

SHA-1:
478ac5176de983ec0e2acdecd033d7677db93576

SHA-256:
5b31a8c389e3ca0f305eef11c8310cdf50f957348816710d5e4acd9a9a7b69be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/14/2025 11:42:33 AM UTC  (today)

File size:
907.5 KB (929,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\common files\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/19/2015 5:00:00 PM

Valid to:
6/13/2018 5:00:00 AM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0CEC25760619513A72214FB3C86C376D

File PE Metadata
Compilation timestamp:
6/2/2015 5:46:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:e3/dArBKQk6gz/uMApE2vZoehVzDpwtoS8Op1la:CMamES2ehBNw++1la

Entry address:
0xF841E

Entry point:
E9, 9E, AC, FF, FF, 88, C4, E8, 30, 60, 08, 00, 66, 81, FC, 84, 23, F9, 29, C0, E8, 56, E3, FF, FF, 8D, 64, 24, 54, 0F, 8B, 91, D5, FF, FF, FE, C8, 38, C9, F8, F5, 3A, 07, 8D, 81, 5B, A6, 8F, 9C, 9C, 66, F7, D0, E8, 73, E6, FB, FF, 25, 5F, 0C, 53, 04, F3, C0, 25, CA, 89, EE, F5, FA, B8, EE, 59, 89, C4, 91, 74, A5, 59, 89, DF, 89, 48, A1, 0F, 7B, 79, 23, 91, 74, 67, 5A, 68, 3E, 81, 92, 66, 6B, 78, 4B, 1C, AD, 95, A7, CA, 0D, 89, 39, 6E, 82, D4, B7, EB, 5B, 25, 48, 19, B8, 6B, F1, 74, 77, D2, D1, 37, CA, 1F...
 
[+]

Entropy:
7.8481

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
96 KB (98,304 bytes)

Service
Display name:
BattlEye Service

Service name:
BEService

Type:
Win32OwnProcess


The file beservice.exe has been discovered within the following program.

DayZ  by Bohemia Interactive
www.dayzgame.com
About 9% of users remove it
 
Powered by Should I Remove It?

The file beservice.exe has been seen being distributed by the following URL.

http://www.battleye.com/downloads/.../BEService.exe

Scan beservice.exe - Powered by Reason Core Security