services.exe

The executable services.exe has been detected as malware by 40 anti-virus scanners.
MD5:
4fdbd1a20103477d5e72a27138b6cb9b

SHA-1:
330ac9767c842e5ad743164b79c37343f4d5935d

SHA-256:
55ca04a77e3b244ede8b16fe2af3824216b74c0ba07530af3e9772a2f17328a9

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
4/27/2024 12:06:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Generic.21020
354

Agnitum Outpost
Backdoor.Prorat
7.1.1

AhnLab V3 Security
Trojan/Win32.Prorat
16.02.15

Avira AntiVirus
BDS/Prorat.ae.23
7.11.150.70

avast!
Win32:Prorat-FE [Trj]
2014.9-160215

AVG
BackDoor.Generic2
2017.0.2832

Baidu Antivirus
Backdoor.Win32.ProRat
4.0.3.16215

Bitdefender
Backdoor.Generic.21020
1.0.20.230

Bkav FE
W32.FakeServicesTA1.Trojan
1.3.0.4959

Clam AntiVirus
Trojan.Prorat.AE
0.98/213

Comodo Security
Backdoor.Win32.Agent.AVW84
18286

Dr.Web
BackDoor.ProRat.2558
9.0.1.046

Emsisoft Anti-Malware
Backdoor.Win32.Prorat
8.16.02.15.07

ESET NOD32
Win32/Prorat.NAH
10.9816

Fortinet FortiGate
W32/Prorat.KOM!tr
2/15/2016

F-Prot
W32/ProratP.H
v6.4.7.1.166

F-Secure
Backdoor:W32/Prorat.gen!A
11.2016-15-02_2

G Data
Backdoor.Generic.21020
16.2.24

IKARUS anti.virus
Packed.Win32.Klone
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.177.12109

Kaspersky
Backdoor.Win32.Prorat
14.0.0.656

Malwarebytes
Trojan.Backdoor
v2016.02.15.07

McAfee
BackDoor-AVW
5600.6488

Microsoft Security Essentials
Backdoor:Win32/Prorat.K
1.10502

MicroWorld eScan
Backdoor.Generic.21020
17.0.0.138

NANO AntiVirus
Trojan.Win32.Prorat.brahkz
0.28.0.59911

Norman
Prorat.IF
11.20160215

nProtect
Backdoor/W32.Prorat.349228.E
14.05.18.01

Panda Antivirus
Bck/Prorat.X
16.02.15.07

Qihoo 360 Security
Backdoor.Win32.ProRat.A
1.0.0.1015

Quick Heal
Backdoor.Prorat.dz.n3
2.16.14.00

Rising Antivirus
NORMAL:Backdoor.Win32.ProRat.g!1225759
23.00.65.16213

Sophos
Troj/Prorat-Fam
4.98

Total Defense
Win32/ProRat.Z
37.0.10944

Trend Micro House Call
BKDR_PRORAT.BL
7.2.46

Trend Micro
BKDR_PRORAT.BL
10.465.15

Vba32 AntiVirus
MalwareScope.Trojan-PSW.Pinch.1
3.12.26.0

VIPRE Antivirus
Backdoor.Win32.Prorat.aa
29342

ViRobot
Backdoor.Win32.A.Prorat.349228.F
2011.4.7.4223

Zillya! Antivirus
Backdoor.Prorat.Win32.2450
2.0.0.1792

File size:
341 KB (349,228 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\services.exe

File PE Metadata
Compilation timestamp:
6/2/2005 7:36:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
6144:C36i6htdvIydnCseroPQKvU9wPhFOXQsZrPTeoHm0HhDtdT22CpuvNJSE7V1XDmO:E6/DdQHroPTAwpwXQsBPTeoG0HhDtdCk

Entry address:
0x1FCE90

Entry point:
60, BE, 00, 90, 5A, 00, 8D, BE, 00, 80, E5, FF, C7, 87, 9C, 90, 1D, 00, C5, 75, A7, 0D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
340 KB (348,160 bytes)

Remove services.exe - Powered by Reason Core Security