wwtask.exe

Trauma Zer0

Aleste Participacoes e Empreendimentos Ltda

The application wwtask.exe, “Trauma Zer0 Network Agent Core” by Aleste Participacoes e Empreendimentosa has been detected as a potentially unwanted program by 4 anti-malware scanners. It runs as a windows Service named “Network Agent Driver Tz0”.
Publisher:
Aleste Technology  (signed by Aleste Participacoes e Empreendimentos Ltda)

Product:
Trauma Zer0

Description:
Trauma Zer0 Network Agent Core

Version:
2.0.2.2

MD5:
99a4281417d148b8983385a127f5862c

SHA-1:
c12f60e06e6c228ea21fbcf7a8c637a2477df1e3

SHA-256:
4567a5a7893178acd0e6ef77051e5ae8043d7f3cb82a14fd20e8e8ce0a0aad3f

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
5/5/2024 11:47:40 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Trojan.Generic.8804815
11.5.0.6191

F-Secure
Trojan.Generic.8804815
5.15.96

Kaspersky
not-a-virus:HEUR:RemoteAdmin.Win32.IVirtuaGroup
15.0.0.562

Norman
Trojan.Generic.8804815
28.05.2016 13:03:37

File size:
1.6 MB (1,643,260 bytes)

Product version:
2.0.0.0

Copyright:
Aleste Technology

Trademarks:
Aleste Technology

Original file name:
wwtask.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\wwtask.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/20/2012 12:00:00 AM

Valid to:
2/8/2013 11:59:59 PM

Subject:
CN=Aleste Participacoes e Empreendimentos Ltda, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Aleste Participacoes e Empreendimentos Ltda, L=Montenegro, S=Rio Grande do Sul, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70A36A6A7CFB4487DE17F295AA61DC03

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:yIkYWNei4ZxQy1a+tupGnH0uF0MhDZHHT0QkxeO/zB:IYm4ZxtrUuphDRHYQ/Sl

Entry address:
0x1000

Entry point:
B8, A4, C7, 8C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 13, 5F, AC, 93, F6, DA, 0E, 4A, 3E, 62, 1D, 64, 84, 49, A8, 0C, 99, B2, F5, 69, 35, D4, 52, AF, E7, 82, B9, EB, DF, 2D, 1B, DD, 5F, 55, ED, BE, 51, CB, BA, 79, 06, CE, B9, 06, C3, 57, 03, D8, 92, 66, 83, 3E, 63, CF, BF, AD, A3, E9, EF, F3, 52, AE, 0A, A5, DF, 59, 93, 9E, CE, E4, D8, D0, 15, 4F, 3E, 32, F6, F9, 2A, 83, D0, 95, A4, 50, B5, 67, D6, DD, 48, 2C, 15, 57, 27...
 
[+]

Packer / compiler:
PECompact v2

Code size:
3.9 MB (4,136,960 bytes)

Service
Display name:
Network Agent Driver Tz0

Service name:
NetworkAgent

Description:
Manages objects protocols in the Network and Dial-Up synchronizations

Type:
Win32OwnProcess, InteractiveProcess

Group:
Network


Remove wwtask.exe - Powered by Reason Core Security