services.exe

ibn

Wave Corporate Sistemas LTDA

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable services.exe has been detected as malware by 4 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘services’.
Publisher:
Microsoft Corporation  (signed by Wave Corporate Sistemas LTDA)

Product:
ibn

Version:
2.00.0012

MD5:
25844a5d99fb1102f5c835dc6f955725

SHA-1:
7bdb57cd6c4624fd47c601043587b885f5e86170

SHA-256:
443ce3127a1ad14d905a07b8dad56a934d8ae1c47b179c7e4765acf57bb8cfe1

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/23/2024 4:14:03 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

F-Prot
W32/VB-Backdoor-PEK-based!Maxim
4.6.5.141

Sophos
Virus 'Mal/VBThief-A'
5.22

File size:
2 MB (2,081,776 bytes)

Product version:
2.00.0012

Copyright:
Microsoft Corporation

Trademarks:
Microsoft Corporation

Original file name:
services.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\services.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/30/2011 9:00:00 PM

Valid to:
3/30/2014 8:59:59 PM

Subject:
CN=Wave Corporate Sistemas LTDA, OU=Register, O=Wave Corporate Sistemas LTDA, STREET="Rua Waltrudes Correa, 297", L=São Paulo, S=São Paulo/Pq. São Domingos, PostalCode=05122-070, C=BR

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00FCD29A2214E069668A4734CCC2CF8ADD

File PE Metadata
Compilation timestamp:
9/8/2011 1:17:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:U3F/JtG0pVofIdJ8dJDdJndJrdJ1VofoStQlfkULHNKO0Pqa0EZS08+AoDXrIF:U3lG0pQ9StQx7Nz0PQ08+pra

Entry address:
0x52F4

Entry point:
68, 6C, 58, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 8E, 3F, 19, 80, 80, 6D, 98, 4B, 9A, 89, 84, 47, E4, 77, D7, A8, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 57, 61, 76, 65, 42, 6C, 6F, 63, 6B, 65, 72, 00, 7D, 23, 32, 2E, 00, 00, 00, 00, 01, 00, 11, 00, 78, 0B, 41, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, FC, 0E, 41, 00, 98, 91, 5F, 00, 00, 00, 00, 00, C0, 1B, E7, 0E, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
2 MB (2,064,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
services

Command:
C:\windows\services.exe


Remove services.exe - Powered by Reason Core Security