FABS.EXE

FABS - file change and backup server

MAGIX AG

The executable FABS.EXE, “Verzeichnisüberwachung und Hilfsaufgaben für die Medienbibliothek” has been detected as malware by 5 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “FABS - Helping agent for MAGIX media database”.
Publisher:
MAGIX AG

Product:
FABS - file change and backup server

Description:
Verzeichnisüberwachung und Hilfsaufgaben für die Medienbibliothek

Version:
2.1.28.0

MD5:
a44c99682db50e0ad65a8b7c54109247

SHA-1:
b2c89e918cfb8871b77a44f9c1834a7b7eabc304

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/23/2024 2:39:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Hoblig [Heur]
160917-0

Clam AntiVirus
BC.Win.Trojan.Xpaj-7
0.98/23209

Dr.Web
Win32.Xpaj.1
9.0.1.05190

ESET NOD32
Win32/Goblin.D.Gen virus
6.3.12010.0

F-Prot
W32/Xpaj.A!Generic
4.6.5.141

File size:
2 MB (2,051,584 bytes)

Product version:
2.1.28.0

Copyright:
Copyright (C) 2005 MAGIX AG, All rights reserved.

Original file name:
FABS.EXE

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\common files\magix services\database\bin\fabs.exe

File PE Metadata
Compilation timestamp:
9/14/2010 9:47:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xC8F29

Entry point:
E8, FE, E0, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, F1, E1, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, C7, 01, 8C, 80, 58, 00, E8, 6D, E1, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 98, D4, FC, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 44, E3, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, E8, 93, E2, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, 85, E4...
 
[+]

Entropy:
6.4305

Code size:
1.3 MB (1,326,592 bytes)

Service
Display name:
FABS - Helping agent for MAGIX media database

Service name:
Fabs

Description:
Watches filechanges, does automatic backups and configuration stuff.

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove FABS.EXE - Powered by Reason Core Security