services.exe

Microsoft VM

WAVE CORPORATE SISTEMAS LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘win’.
Publisher:
Microsoft Corporation  (signed by WAVE CORPORATE SISTEMAS LTDA)

Product:
Microsoft VM

Description:
Microsoft Corporation

Version:
5.00.0003

MD5:
953bbc55e373ab511a4ec9449bf43bd2

SHA-1:
b0da7ecd86593b8bed0609e2ee1d773181f8e485

SHA-256:
8924ba658a1abc4fc1d2cbddba9f527b1a47e267a210c53f8b8e371bfe5e3632

Scanner detections:
7 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/30/2024 10:32:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.@p1@s1kJJ1jiC
353

Arcabit
Trojan.Heur.E26B34
1.0.0.581

Bitdefender
Gen:Trojan.Heur.@p1@s1kJJ1jiC
1.0.20.235

Emsisoft Anti-Malware
Gen:Trojan.Heur.@p1@s1kJJ1jiC
8.16.02.16.01

F-Secure
Gen:Trojan.Heur.@p1@s1kJJ1jiC
11.2016-16-02_3

G Data
Gen:Trojan.Heur.@p1@s1kJJ1jiC
16.2.25

MicroWorld eScan
Gen:Trojan.Heur.@p1@s1kJJ1jiC
17.0.0.141

File size:
8.8 MB (9,222,064 bytes)

Product version:
5.00.0003

Copyright:
Microsoft Copyright 2011

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2015 11:25:27 AM

Valid to:
6/23/2016 11:25:27 AM

Subject:
E=wavecorporate@gmail.com, CN="Open Source Developer, Vagner Araujo Costa", OU=Registration Wave Corporate, O=WAVE CORPORATE SISTEMAS LTDA, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
763F08A85E63DDE82B1CCC80817B4EFB

File PE Metadata
Compilation timestamp:
7/13/2015 9:35:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:pw45N/p5FuPFxFuPFc+i0rsfab0hFuPFIUSwK45x5c2oJE2a45Kzg7CPMM+rh5cX:pj/p5F0FkUaohF9USwaMM7CPMM+OzEO

Entry address:
0x69D8

Entry point:
68, B0, 72, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, 92, 3D, CF, D5, 44, 93, 1F, 41, BC, A2, 57, C0, 5A, D7, D8, CD, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 57, 61, 76, 65, 69, 42, 6C, 6F, 63, 6B, 65, 72, 00, 00, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 46, 72, 61, 6D, 65, 77, 6F, 72, 6B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 0F, 00, 9C, 39, 41, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
8.8 MB (9,203,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
win

Command:
C:\windows\services.exe


Scan services.exe - Powered by Reason Core Security