services.exe

The executable services.exe has been detected as malware by 28 anti-virus scanners.
MD5:
06f058ee1c88409f29882b6f6a791c7c

SHA-1:
d590afc6e3075b3fd7d61c9f42d7b3fe49e667f8

SHA-256:
94871fc703e8530a3e6fb8c54a0c64558611bf79a24e582b2892aabdd180c439

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/30/2024 5:31:05 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Xema.variant
5.0.

Avira AntiVirus
TR/Delf.aam.35
7.9.1.160

Emsisoft A-Squared
Trojan-GameThief.Win32.Nilage!IK
4.5.0.50

avast!
Win32:Delf-KRS
2014.9-170305

AVG
Generic3
2018.0.2448

Bitdefender
Trojan.Generic.2267138
1.0.20.320

Clam AntiVirus
Trojan.Delf-658
0.98/17011

Comodo Security
TrojWare.Win32.Trojan.Delf.~QJ
3924

Dr.Web
Trojan.Worker
9.0.1.064

ESET NOD32
Win32/Delf.AAM
11.4864

Fortinet FortiGate
Spy/Delf
3/5/2017

F-Prot
W32/Trojan.BUQM
v6.4.5.1.85

F-Secure
Trojan.Generic.2267138
11.2017-05-03_1

G Data
Trojan.Generic.2267138
17.3.19

IKARUS anti.virus
Trojan-GameThief.Win32.Nilage
t3scan.1.1.80.0

K7 AntiVirus
Trojan.Win32.Delf
13.7.10.972

Kaspersky
Trojan.Win32.Delf
14.0.0.-1263

McAfee
Generic Delphi.c
5600.6104

Microsoft Security Essentials
PWS:Win32/Yahmali.A
1.163.1557.0

Norman
W32/Obfuscated.H!genr
11.20170305

nProtect
Trojan/W32.Small.37888.E
2009.1.8.0

Prevx
Medium Risk Malware
3.0

Quick Heal
Trojan.Delf.aam
3.17.10.00

Rising Antivirus
Trojan.Win32.Delf.aam
23.00.65.17303

Sophos
Mal/Behav-053
4.50

Trend Micro
TSPY_YAHMALI.B
10.465.05

Vba32 AntiVirus
Trojan.Win32.Delf.aam
3.12.12.2

ViRobot
Trojan.Win32.Delf.39168
2010.2.13.2186

File size:
37 KB (37,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\services.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x4FEC

Entry point:
55, 8B, EC, 83, C4, F0, B8, B4, 4F, 40, 00, E8, 58, E9, FF, FF, 33, C0, 55, 68, 5A, 50, 40, 00, 64, FF, 30, 64, 89, 20, E8, 89, EC, FF, FF, 84, C0, 75, 07, E8, D8, F1, FF, FF, EB, 32, 68, B8, 44, 40, 00, 68, E8, 03, 00, 00, 68, 90, 04, 00, 00, 6A, 00, E8, 58, EA, FF, FF, 68, D4, 47, 40, 00, 6A, 64, 68, 90, 04, 00, 00, 6A, 00, E8, 45, EA, FF, FF, E8, 0C, EC, FF, FF, 84, C0, 75, F7, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 61, 50, 40, 00, C3, E9, 41, DB, FF, FF, EB, F8, E8, AE, DF, FF, FF, 8B, C0, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
16.5 KB (16,896 bytes)

Remove services.exe - Powered by Reason Core Security