services.exe

Microsoft Library

Wave Corporate Sistemas LTDA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable services.exe, “Microsoft Corporation” has been detected as malware by 3 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘win’.
Publisher:
Microsoft Corporation  (signed by Wave Corporate Sistemas LTDA)

Product:
Microsoft Library

Description:
Microsoft Corporation

Version:
8.00.0014

MD5:
dc4251bc107820549df675d06796b60f

SHA-1:
d35bb2268c7cea22bd363ead30bf7d80da3d6b7d

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/15/2024 10:48:34 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

ESET NOD32
Win32/VB.OFK trojan
6.3.12010.0

F-Secure
Trojan.Heur.0m1@sfdd97diC
5.15.154

File size:
839.3 KB (859,400 bytes)

Product version:
8.00.0014

Copyright:
Microsoft Copyright 2015

Trademarks:
Microsoft Corporation Inc.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/15/2014 9:00:00 PM

Valid to:
5/16/2015 8:59:59 PM

Subject:
CN=Wave Corporate Sistemas LTDA, O=Wave Corporate Sistemas LTDA, STREET="Rua Waltrudes Correa, 297", L=São Paulo, S=São Paulo, PostalCode=05122070, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5CF9AD4E9073852DEFA5388B9A06D3DD

File PE Metadata
Compilation timestamp:
5/16/2015 7:11:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x4F10

Entry point:
68, 70, 57, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 38, 00, 00, 00, AF, CD, CD, 5F, C9, 57, 57, 41, 9E, 12, 33, B2, D9, DD, 31, 45, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 6C, 69, 65, 6E, 74, 00, 00, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 4C, 69, 62, 72, 61, 72, 79, 00, 0B, 0A, 01, 00, 00, 00, 00, 00, 00, 00, 01, 00, 07, 00, B8, CC, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 5C, CE, 40, 00, 50, E4, 4C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
820 KB (839,680 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
win

Command:
C:\windows\services.exe


Remove services.exe - Powered by Reason Core Security