services.exe

Microsoft VM

Wave Corporate Sistemas LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windows Library’.
Publisher:
Microsoft Corporation  (signed by Wave Corporate Sistemas LTDA)

Product:
Microsoft VM

Description:
Microsoft Corporation

Version:
6.00.0016

MD5:
7e1e61a1eefca69dac0278c632fad583

SHA-1:
48b8d93134fed7e462ac2fd665096935645bccbd

SHA-256:
c4db581f49656f84649cffabc7b6aa4638143d407781a515998e53abff2d05e3

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/15/2024 10:53:00 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/VB.OFK trojan
6.3.12010.0

File size:
915.2 KB (937,200 bytes)

Product version:
6.00.0016

Copyright:
Microsoft Copyright 2014

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/15/2014 9:00:00 PM

Valid to:
5/16/2015 8:59:59 PM

Subject:
CN=Wave Corporate Sistemas LTDA, O=Wave Corporate Sistemas LTDA, STREET="Rua Waltrudes Correa, 297", L=São Paulo, S=São Paulo, PostalCode=05122070, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5CF9AD4E9073852DEFA5388B9A06D3DD

File PE Metadata
Compilation timestamp:
12/15/2014 6:27:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x4DB0

Entry point:
68, 18, 56, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, 28, 85, E9, EA, 2B, 8F, D9, 43, B5, CC, 3F, 4E, 00, 4B, AE, 29, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 41, 00, 82, 50, 82, 01, 56, 69, 72, 74, 75, 61, 6C, 43, 6C, 69, 65, 6E, 74, 00, 09, 0A, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 46, 72, 61, 6D, 65, 77, 6F, 72, 6B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 07, 00, 78, CB, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
896 KB (917,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windows Library

Command:
"C:\windows\services.exe"


Scan services.exe - Powered by Reason Core Security