taskmgr.exe

The executable taskmgr.exe has been detected as malware by 5 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft’. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information.
MD5:
c073f898740a8672d79a3b5b077bf769

SHA-1:
4296fc5fb95b3a038c2abab2875a695810eec9be

SHA-256:
5ed5972bf2491d7858643f993c49cf83ae3956028ee1481af0981167f3cdceef

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/1/2025 8:13:49 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.DownLoader18.35402
9.0.1.05190

ESET NOD32
MSIL/Bladabindi.AZ trojan
6.3.12010.0

F-Prot
W32/MSIL_Troj.AP.gen
4.6.5.141

F-Secure
Generic.MSIL.Bladabindi.E3D187BA
5.16.24

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AL
1.237.1214.0

File size:
46 KB (47,104 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\taskmgr.exe

File PE Metadata
Compilation timestamp:
3/12/2017 12:32:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0xD12E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
44.5 KB (45,568 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft

Command:
"C:\ProgramData\taskmgr.exe"..


Remove taskmgr.exe - Powered by Reason Core Security