services.exe

Services and Controller app

Microsoft

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable services.exe, “Services and Controller app” has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DDXPPXCE’.
Publisher:
Microsoft Corporation  (signed by Microsoft)

Product:
Microsoft® Windows® Operating System

Description:
Services and Controller app

Version:
5.1.2600.5512 (xpsp.080413-2111)

MD5:
8215697bfeef78a929f47f93bbd1b8ae

SHA-1:
3246b073cfb0bfa7926fc59f2d9d9205d73fe4fd

SHA-256:
95af7d2ff865e039236515c121897bc3880b930c3d8a21b7e6484fca551ae793

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 6:51:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Generic
17.3.13.17

File size:
393 KB (402,448 bytes)

Product version:
5.1.2600.5512

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\amir\userdata\services.exe

Digital Signature
Signed by:

Authority:
Microsoft

Valid from:
12/31/1999 11:00:00 PM

Valid to:
12/31/2098 11:00:00 PM

Subject:
CN=Microsoft

Issuer:
CN=Microsoft

Serial number:
3C7D826D713CFF9646BDA02B7E542C7B

File PE Metadata
Compilation timestamp:
8/10/2010 5:02:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x26C2B

Entry point:
E8, 73, 6A, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, A0, 37, 45, 00, 75, 02, F3, C3, E9, F3, 6A, 00, 00, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 91, 24, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 4B, 13, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 6C, 24, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, AA, 6B, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, 8B, 44, 24, 04, 85, C0, 74, 12, 83, E8, 08, 81...
 
[+]

Entropy:
6.3201

Code size:
256 KB (262,144 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DDXPPXCE

Command:
C:\users\amir\userdata\services.exe


Remove services.exe - Powered by Reason Core Security