Trojan

Trojan.Win32.Tasker.auzg removal

Malware Removal

The Trojan.Win32.Tasker.auzg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Tasker.auzg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Tasker.auzg?


File Info:

name: 0D9839B2C093E9AD7A61.mlw
path: /opt/CAPEv2/storage/binaries/23b95d94297a16d00f05e8bacc059ff4a4a8e2c19f81e8202714bd9331275fe3
crc32: 59DA2DBD
md5: 0d9839b2c093e9ad7a61d902151599d2
sha1: 9649d7e2ad6afaad035b9176eb59b4a0c4721f41
sha256: 23b95d94297a16d00f05e8bacc059ff4a4a8e2c19f81e8202714bd9331275fe3
sha512: 365620ed4e3d8f19c9eebdb4f1cb9facc9519a7d0b0e75b9d0e90f22ba03d45d9857db386a34962eecdb674aaa3bd93ca1155cf701a8f7da7e5c5b1ff5e2197e
ssdeep: 196608:PPW/rlvd9wrq5uGUt9rTma1NDZQaxtoCwyshFM/3MosH1Y:PPW/rZdyrq5fU/nmt+TwyshFE8DHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130A633F48BBAEF9BE2EDA93AF9F8733F1AC12000931E3D76079594C57A441C9501E265
sha3_384: b34e5a4b461304ccb64df9f40da4fe52b33858d22494a47d09a3cd0c03046df0699ae6ed090c0856901b221326d2ca22
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

0: [No Data]

Trojan.Win32.Tasker.auzg also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Coins.i!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.41966
MicroWorld-eScanTrojan.GenericKD.39094307
FireEyeGeneric.mg.0d9839b2c093e9ad
CAT-QuickHealTrojan.Miner.KG5
ALYacTrojan.GenericKD.39094307
CylanceUnsafe
SangforTrojan.Win32.Tasker.auzg
K7AntiVirusTrojan ( 0058d0661 )
AlibabaTrojanPSW:Win32/Tasker.0942f329
K7GWTrojan ( 0058d0661 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.3BDE11631F
CyrenW32/Trojan.LXVF-4894
ESET-NOD32multiple detections
ZonerProbably Heur.ExeHeaderL
Paloaltogeneric.ml
KasperskyTrojan.Win32.Tasker.auzg
BitDefenderTrojan.GenericKD.39094307
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
RisingTrojan.Generic@AI.100 (RDMK:iK5gCUjMw0F6Ue7ytpyGCA)
Ad-AwareTrojan.GenericKD.39094307
SophosMal/Generic-R
ComodoMalware@#153np5lw1790h
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.39094307 (B)
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKD.39094307
AviraHEUR/AGEN.1211746
MAXmalware (ai score=84)
ArcabitTrojan.Generic.D2548823
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4986777
Acronissuspicious
McAfeeArtemis!0D9839B2C093
VBA32Trojan.InjectNET
MalwarebytesMalware.AI.4152777934
APEXMalicious
TencentWin32.Trojan-qqpass.Qqrob.Iiy
YandexTrojan.Tasker!IQ0A0Ds2ijI
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Cybereasonmalicious.2c093e
PandaTrj/CI.A

How to remove Trojan.Win32.Tasker.auzg?

Trojan.Win32.Tasker.auzg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment