services.exe

Microsoft VM

WAVE CORPORATE SISTEMAS LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Intel’.
Publisher:
Microsoft Corporation  (signed by WAVE CORPORATE SISTEMAS LTDA)

Product:
Microsoft VM

Description:
Microsoft Corporation

Version:
6.00

MD5:
31800aa15072e0c1dddbed7bd5d07681

SHA-1:
b44ca6c5accdeee1f5c36e3348024a525086c676

SHA-256:
76a9e37cfbc4ef89e5242b1f789b29e95592c06bb08ea1ae63d3f0cbd4facac6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/30/2024 10:14:37 PM UTC  (today)

File size:
8.8 MB (9,250,736 bytes)

Product version:
6.00

Copyright:
Microsoft Copyright 2011

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2015 11:25:27 AM

Valid to:
6/23/2016 11:25:27 AM

Subject:
E=wavecorporate@gmail.com, CN="Open Source Developer, Vagner Araujo Costa", OU=Registration Wave Corporate, O=WAVE CORPORATE SISTEMAS LTDA, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
763F08A85E63DDE82B1CCC80817B4EFB

File PE Metadata
Compilation timestamp:
3/17/2016 3:16:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:a/1Cp8FIFsUaobF9USwHFuRCPMMTDzr8eK:Y1waCyF7zr8eK

Entry address:
0x6A60

Entry point:
68, 38, 73, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, 93, 1E, 34, 88, 44, 53, 0D, 4C, A7, 7D, E1, 3A, A6, 50, A6, F4, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 57, 61, 76, 65, 69, 42, 6C, 6F, 63, 6B, 65, 72, 00, 00, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 46, 72, 61, 6D, 65, 77, 6F, 72, 6B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 20, 00, 4C, 3B, 41, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Entropy:
6.0501

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
8.8 MB (9,232,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Intel

Command:
C:\windows\services.exe


Scan services.exe - Powered by Reason Core Security