services.exe

Microsoft VM

Wave Corporate Sistemas LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘win’.
Publisher:
Microsoft Corporation  (signed by Wave Corporate Sistemas LTDA)

Product:
Microsoft VM

Description:
Microsoft Corporation

Version:
4.00.0046

MD5:
5c1ca6a3cbf87ec5b2227f0db80dca39

SHA-1:
6cdd9f8bff485f2ac955cffae2e501dd057cf446

SHA-256:
fcd424a0a232d6ecbe6a364a19240cffa369c6ac2db2645bb11a33ad54ca7e35

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/15/2024 11:57:11 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

F-Secure
Trojan.Heur.ko1@szsRtiiiC
5.15.154

File size:
2.2 MB (2,267,328 bytes)

Product version:
4.00.0046

Copyright:
Microsoft Copyright 2011

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2013 9:00:00 PM

Valid to:
3/30/2014 8:59:59 PM

Subject:
CN=Wave Corporate Sistemas LTDA, OU=Register, O=Wave Corporate Sistemas LTDA, STREET="Rua Waltrudes Correa, 297", L=São Paulo, S=São Paulo/Pq. São Domingos, PostalCode=05122-070, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3E5EB6C1AF61814663D09161FDAE8291

File PE Metadata
Compilation timestamp:
10/29/2013 5:22:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:96hQO2srjrcsJ9s9k9fdqUpTGYRA9XpCKUSwqb8K/qN:4hQO2srUsJqWPqUpSYRKZCKUSwqPS

Entry address:
0x629C

Entry point:
68, 00, 6B, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, CF, 03, 04, EE, 79, 41, B2, 4F, A7, 9F, 88, 80, 79, 4A, 60, 91, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, C8, 79, CE, 0C, 56, 69, 72, 74, 75, 61, 6C, 43, 6C, 69, 65, 6E, 74, 00, 40, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 46, 72, 61, 6D, 65, 77, 6F, 72, 6B, 00, 01, 00, 00, 00, 00, 00, 00, 00, 01, 00, 05, 00, 0C, 04, 41, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
2.1 MB (2,248,704 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
win

Command:
C:\windows\services.exe


Scan services.exe - Powered by Reason Core Security