services.exe

Microsoft Library

WAVE CORPORATE SISTEMAS LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Intel’.
Publisher:
Microsoft Corporation  (signed by WAVE CORPORATE SISTEMAS LTDA)

Product:
Microsoft Library

Description:
Microsoft Corporation

Version:
12.00.0029

MD5:
d9e71ec3ef0812f24b7a8873e7fa5aae

SHA-1:
b7cc9ddd335ede4e8b79e2b7cc9fbed72714a3bb

SHA-256:
2b0e2b60ab3ea488abd9ea4c8b75f2f6daad4f74771a14277f6b8fc22615270e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/30/2024 10:19:21 PM UTC  (today)

File size:
941.9 KB (964,544 bytes)

Product version:
12.00.0029

Copyright:
Microsoft Copyright 2015

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2015 11:25:27 AM

Valid to:
6/23/2016 11:25:27 AM

Subject:
E=wavecorporate@gmail.com, CN="Open Source Developer, Vagner Araujo Costa", OU=Registration Wave Corporate, O=WAVE CORPORATE SISTEMAS LTDA, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
763F08A85E63DDE82B1CCC80817B4EFB

File PE Metadata
Compilation timestamp:
4/13/2016 10:46:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:oQ84wBZSF84wBZSaa2FwyeJUSwGIn33HTzHTwxoxac7FXuCVWVtcuavpgKEmWOp0:oJ4wBZS24wBZSaa2uySUSw1ZGNZ

Entry address:
0x5AD8

Entry point:
68, A4, 64, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, 3B, 0A, 44, 27, F6, 12, A3, 41, BA, 35, 77, 33, CE, 98, 16, 7C, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 6C, 69, 65, 6E, 54, 72, 61, 63, 6B, 65, 72, 74, 00, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 4C, 69, 62, 72, 61, 72, 79, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 23, 00, E0, 04, 41, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Entropy:
6.5395

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
924 KB (946,176 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Intel

Command:
C:\windows\services.exe


Scan services.exe - Powered by Reason Core Security