Trojan

Trojan.Win32.Tasker.auju malicious file

Malware Removal

The Trojan.Win32.Tasker.auju is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Tasker.auju virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Checks the version of Bios, possibly for anti-virtualization

How to determine Trojan.Win32.Tasker.auju?


File Info:

name: 7B7CFE46454F0F7A9C04.mlw
path: /opt/CAPEv2/storage/binaries/47e2b9d18762b81536a9a236a382302f9fcb3114e3723a2e90277b903448b536
crc32: FDA8DD0A
md5: 7b7cfe46454f0f7a9c046636eb66dda0
sha1: 9ef56977d9b96e81e42f94ef29b144698685e5d3
sha256: 47e2b9d18762b81536a9a236a382302f9fcb3114e3723a2e90277b903448b536
sha512: 28e5b8eca9048855829528d8e235e52168588c247e036acae791927b9f703394975c38dedcc01a6bdfcefdd1e580d882d97f6eec3a6983c1b21fb4a04cdd0cfd
ssdeep: 98304:29fRAjb646h1C9DUCDYU1cMMihUjRWzNa4Cj6QqHXk+HcJi:2955h1CFUBU5Uh4C7qH0aR
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T14536CE27B70C525DF944183AA0C2FA01EB0456D5AEFEF1E4DB7BAD873742CE4714A1A2
sha3_384: 3ebfffeaa3b9dab0876782a77612798bc6467d0f783f1a3639067706bc2765af12298c8faeb5a62f0c6133ce2d78a37f
ep_bytes: e88201000041524989e24152498b7210
timestamp: 2021-12-02 14:29:49

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 16.6.30320.27
InternalName: vs_community.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: vs_community.exe
ProductName: Microsoft Visual Studio Community
ProductVersion: 16.6.30320.27
Translation: 0x0409 0x04b0

Trojan.Win32.Tasker.auju also known as:

LionicTrojan.Win64.Agentb.trtl
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47544263
ALYacTrojan.GenericKD.47544263
MalwarebytesTrojan.MalPack
VIPRETrojan-Spy.Win32.Banker.to (fs)
AlibabaTrojan:Win32/Tasker.cf0574f3
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GenCBL.ANJ
Paloaltogeneric.ml
KasperskyTrojan.Win32.Tasker.auju
BitDefenderTrojan.GenericKD.47544263
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.47544263
SophosMal/Generic-R + Mal/BadCert-Gen
ComodoTrojWare.Win32.Agent.kzpiz@0
DrWebTrojan.MulDrop19.10258
ZillyaTrojan.GenCBL.Win32.3471
TrendMicroTROJ_GEN.R002C0RL621
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.47544263
EmsisoftTrojan.GenericKD.47544263 (B)
IkarusPUA.Themida
GDataTrojan.GenericKD.47544263
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Tasker.au.(kcloud)
GridinsoftTrojan.Heur!.012100A3
ArcabitTrojan.Generic.D2D577C7
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!7B7CFE46454F
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.FL
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0RL621
YandexTrojan.Tasker!zDPWD+y/jGE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/GenCBL
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Tasker.auju?

Trojan.Win32.Tasker.auju removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment