services.exe

Microsoft Library

WAVE CORPORATE SISTEMAS LTDA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Intel’.
Publisher:
Microsoft Corporation  (signed by WAVE CORPORATE SISTEMAS LTDA)

Product:
Microsoft Library

Description:
Microsoft Corporation

Version:
12.00.0030

MD5:
98bfea5166d07ae65e5ba3c9f1389249

SHA-1:
ce541112b6483234c38a519310cec0b734f6a947

SHA-256:
9c855bc407207819eb076e93f0ab98ef25f8ff80a42478d9b712e67b01d0cda9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 8:30:58 PM UTC  (today)

File size:
933.9 KB (956,344 bytes)

Product version:
12.00.0030

Copyright:
Microsoft Copyright 2015

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2015 11:25:27 AM

Valid to:
6/23/2016 11:25:27 AM

Subject:
E=wavecorporate@gmail.com, CN="Open Source Developer, Vagner Araujo Costa", OU=Registration Wave Corporate, O=WAVE CORPORATE SISTEMAS LTDA, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
763F08A85E63DDE82B1CCC80817B4EFB

File PE Metadata
Compilation timestamp:
5/12/2016 12:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:Zf84wBZSN84wBZSxa2FTyeiUSwmJwibsG:Zk4wBZSu4wBZSxa2hy5USwmJwibsG

Entry address:
0x5AD8

Entry point:
68, A4, 64, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, B3, 38, A3, D9, E5, F1, DD, 4C, 93, 4D, 56, 83, 3E, E3, 3C, 28, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 6C, 69, 65, 6E, 54, 72, 61, 63, 6B, 65, 72, 74, 00, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 4C, 69, 62, 72, 61, 72, 79, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 23, 00, C4, F3, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00...
 
[+]

Entropy:
6.5464

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
916 KB (937,984 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Intel

Command:
C:\windows\services.exe


Scan services.exe - Powered by Reason Core Security