tasksgr.exe

Microsoft Windows System

Microsoft Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Tasksgr(TM)’.
Publisher:
Microsoft Inc.

Product:
Microsoft Windows System

Description:
Windows Manager System

Version:
6.1.7601.17514

MD5:
dea7ceda1017fea3aec9e6925fc7ef8f

SHA-1:
b6f44f66e409dc4b9b9aebe40ada4ca77d67211c

SHA-256:
2c6ac1cb59f797aac3c550207d7b0a37bf3773bf74a9f83ac05147781434430f

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 4:44:29 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
Trojan.Win32.Agent
14.0.0.4034

Qihoo 360 Security
Win32/Trojan.341
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R08NH07CQ14
7.2.101

File size:
162.5 KB (166,400 bytes)

Product version:
6.1.7601.17514

Copyright:
© Microsoft Corporation. All rights reserved.

Trademarks:
© Microsoft Corporation. All rights reserved.

Original file name:
Microsoft Security (TM).exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\microsoft\system\tasksgr.exe

File PE Metadata
Compilation timestamp:
3/6/2014 2:35:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:/k0+b/9KkCNuEPZXMT9GUk0+b/9KkCNu:/LkChZXs9PLkC

Entry address:
0x1909E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
92.5 KB (94,720 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Tasksgr(TM)

Command:
C:\users\{user}\appdata\roaming\microsoft\system\tasksgr.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to p3nlhg636c1636.shr.prod.phx3.secureserver.net  (50.62.101.1:80)

TCP (HTTP):
Connects to 184.173.167.110-static.reverse.softlayer.com  (184.173.167.110:80)

TCP (HTTP):
Connects to 184.173.167.104-static.reverse.softlayer.com  (184.173.167.104:80)

Scan tasksgr.exe - Powered by Reason Core Security