wwtask.exe

Trauma Zer0

Aleste Participacoes e Empreendimentos Ltda

The executable wwtask.exe, “Trauma Zer0 Network Agent Core” has been detected as malware by 4 anti-virus scanners. It runs as a windows Service named “Network Agent Driver Tz0”.
Publisher:
Aleste Technology  (signed by Aleste Participacoes e Empreendimentos Ltda)

Product:
Trauma Zer0

Description:
Trauma Zer0 Network Agent Core

Version:
2.0.2.8

MD5:
758b0f55d889f78913e6304308fc3ba9

SHA-1:
e570a4caf00501774eb73e1dc9e1b186ffae78f1

SHA-256:
9d51c3876526cb02eb6fcee3238a2a63a935dc5f074a3a19e78db332312db543

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/23/2024 1:25:58 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Detection.Undefined
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.12938204
11.5.0.6191

F-Secure
Trojan.Generic.12938204
5.15.96

Norman
Trojan.Generic.12938204
28.05.2016 15:32:18

File size:
1.6 MB (1,648,030 bytes)

Product version:
2.0.0.0

Copyright:
Aleste Technology

Trademarks:
Aleste Technology

Original file name:
wwtask.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\wwtask.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/14/2013 12:00:00 AM

Valid to:
3/15/2014 11:59:59 PM

Subject:
CN=Aleste Participacoes e Empreendimentos Ltda, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Aleste Participacoes e Empreendimentos Ltda, L=Montenegro, S=Rio Grande do Sul, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
320C63DB3AEE1845C496DDB7E2380D06

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Uv4FAMax/wGJl4QQz8Ohf/5EwPKsN9cyySDouvAxURiP2ITIN7InjBJITmG+8:UgFg4oaTz8RwPZXcyyyQwiP2lN7InnYn

Entry address:
0x1000

Entry point:
B8, 78, 17, 8D, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 13, 5F, AC, 93, F6, DA, 0E, 4A, 3E, 62, 1D, 64, 84, 49, A8, 0C, 99, B2, F5, 69, 35, D4, 52, AF, E7, 82, B9, EB, DF, 2D, 1B, DD, 5F, 55, ED, BE, 51, CB, BA, 79, 06, CE, B9, 06, C3, 57, 03, D8, 92, 66, 83, 3E, 63, CF, BF, AD, A3, E9, EF, F3, 52, AE, 0A, A5, DF, 59, 93, 9E, CE, E4, D8, D0, 15, 4F, 3E, 32, F6, F9, 2A, 83, D0, 95, A4, 50, B5, 67, D6, DD, 48, 2C, 15, 57, 27...
 
[+]

Packer / compiler:
PECompact v2

Code size:
4 MB (4,151,808 bytes)

Service
Display name:
Network Agent Driver Tz0

Service name:
NetworkAgent

Description:
Manages objects protocols in the Network and Dial-Up synchronizations

Type:
Win32OwnProcess, InteractiveProcess

Group:
Network


Remove wwtask.exe - Powered by Reason Core Security