services.exe

Microsoft Library

WAVE CORPORATE SISTEMAS LTDA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable services.exe, “Microsoft Corporation” has been detected as malware by 9 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windows Library’.
Publisher:
Microsoft Corporation  (signed by WAVE CORPORATE SISTEMAS LTDA)

Product:
Microsoft Library

Description:
Microsoft Corporation

Version:
12.00

MD5:
e7e1a68bbc93751d7cb66c04b7ca38d7

SHA-1:
62c671993633570e49ba92c48420aed3794cf7ac

SHA-256:
59ab251be641026e86c408c27d63d01a3a763da1ff1887379bedab26f21b1131

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
12/30/2024 9:47:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.Zm1@s5kAY6piC
365

Arcabit
Trojan.Heur.E0E417
1.0.0.582

AVG
Generic_vb
2017.0.2843

Bitdefender
Gen:Trojan.Heur.Zm1@s5kAY6piC
1.0.20.175

Dr.Web
BACKDOOR.Trojan
9.0.1.035

Emsisoft Anti-Malware
Gen:Trojan.Heur.Zm1@s5kAY6piC
8.16.02.04.05

ESET NOD32
Win32/VB.OFK (variant)
10.12388

G Data
Gen:Trojan.Heur.Zm1@s5kAY6piC
16.2.25

MicroWorld eScan
Gen:Trojan.Heur.Zm1@s5kAY6piC
17.0.0.105

File size:
825.9 KB (845,744 bytes)

Product version:
12.00

Copyright:
Microsoft Copyright 2015

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2015 11:25:27 AM

Valid to:
6/23/2016 11:25:27 AM

Subject:
E=wavecorporate@gmail.com, CN="Open Source Developer, Vagner Araujo Costa", OU=Registration Wave Corporate, O=WAVE CORPORATE SISTEMAS LTDA, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
763F08A85E63DDE82B1CCC80817B4EFB

File PE Metadata
Compilation timestamp:
9/7/2015 5:16:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:+e084wBw2Sh84wBw2ScXHQ7KFuZAwljIZ1rNCH1Na2jz:f084wBZSh84wBZScZUSwk3YNa2jz

Entry address:
0x4ED8

Entry point:
68, 24, 57, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 38, 00, 00, 00, A3, 86, 46, 1E, B7, 7F, 56, 4E, A6, B1, C7, 70, 17, 59, 60, 45, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 6C, 69, 65, 6E, 74, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 4C, 69, 62, 72, 61, 72, 79, 00, 01, 00, 08, 00, 00, 00, 00, 00, 00, 00, 01, 00, 25, 00, 4C, CD, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 90, D4, 40, 00, C0, B8, 4C, 00...
 
[+]

Entropy:
6.5090

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
808 KB (827,392 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windows Library

Command:
"C:\windows\services.exe"


Remove services.exe - Powered by Reason Core Security