taskswatch.exe

M/s Children Code

The application taskswatch.exe by M/s Children Code has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TasksWatch’. It is also typically executed from the user's temporary directory.
Publisher:
M/s Children Code  (signed and verified)

MD5:
2bd7eb2b1464c59d0628de3ab0279f11

SHA-1:
a7bc75328f512ade91db6044a1b26e80cf56baae

SHA-256:
6bb64dc082dd091ee58d09c92aa20bba3a4313f3cdd86a0615b203550c5eedf6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 8:01:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.5.10

File size:
1.2 MB (1,289,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\taskswatch.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/10/2014 1:00:00 AM

Valid to:
2/11/2015 12:59:59 AM

Subject:
CN=M/s Children Code, O=M/s Children Code, STREET="Plot No. F-125,", STREET="Sector 74,", STREET="Industrial Area, Phase 8B", L=Mohali, S=Punjab, PostalCode=160071, C=IN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
355CDFD525F643928F3A5700D87F0799

File PE Metadata
Compilation timestamp:
3/20/2014 6:04:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:AqRE57Qo9L5iyOxWuvn+uZumtqUGu9vXJvS5+bY2m8LoRm:VRETl5OF+uZTcFuZXYp2LX

Entry address:
0x342000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 10, 13, 00, 2D, FF, 91, 0A, 10, 05, F4, 91, 0A, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 81, 63, EF, 13, 68, 41, 39, 14, 5A, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 51, 74, 3F, 3A, 50, 00, F3, 82, A0, 58, 37, DE, C1, E2...
 
[+]

Code size:
33 KB (33,792 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TasksWatch

Command:
"C:\users\{user}\appdata\local\temp\taskswatch.exe"


Remove taskswatch.exe - Powered by Reason Core Security