services.exe

Services and Controller app

Microsoft

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable services.exe, “Services and Controller app” has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DDXPPXCE’.
Publisher:
Microsoft Corporation  (signed by Microsoft)

Product:
Microsoft® Windows® Operating System

Description:
Services and Controller app

Version:
5.1.2600.5512 (xpsp.080413-2111)

MD5:
ac628d92b013e9adf93252038b42a99c

SHA-1:
e9a5c0e99873b024159dd4caf24f66e340960c59

SHA-256:
d2bb6fc686d6efe2f0c44ade9c36b5333fe5fbe94908f2e8349b288d04b654f5

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 6:43:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Generic
17.3.2.13

File size:
393 KB (402,448 bytes)

Product version:
5.1.2600.5512

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\reza.reza-pc\userdata\services.exe

Digital Signature
Signed by:

Authority:
Microsoft

Valid from:
12/31/1999 11:00:00 PM

Valid to:
12/31/2098 11:00:00 PM

Subject:
CN=Microsoft

Issuer:
CN=Microsoft

Serial number:
3C7D826D713CFF9646BDA02B7E542C7B

File PE Metadata
Compilation timestamp:
8/10/2010 5:02:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x26C2B

Entry point:
E8, 73, 6A, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, A0, 37, 45, 00, 75, 02, F3, C3, E9, F3, 6A, 00, 00, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 91, 24, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 4B, 13, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 6C, 24, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, AA, 6B, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, 8B, 44, 24, 04, 85, C0, 74, 12, 83, E8, 08, 81...
 
[+]

Entropy:
6.3201

Code size:
256 KB (262,144 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DDXPPXCE

Command:
C:\users\reza.reza-pc\userdata\services.exe


Remove services.exe - Powered by Reason Core Security