taskmgr.exe

The application taskmgr.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from lp5.bongacams24.com.
MD5:
79a87f9b9ad433f42b3942d3eb7c6917

SHA-1:
eb52dd05424a9b4ec059fe085548595bdaca15f2

SHA-256:
c618649311f0fb6c85010a15daa0a0f93ce3cdc2a612e8ff1684d2bfdf854231

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/15/2024 11:54:44 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AegisLab AV Signature
DangerousObject.Multi.Gen
2.1.4+

AVG
Generic36
2017.0.2847

Dr.Web
Trojan.Siggen6.55013
9.0.1.031

ESET NOD32
Win32/CoinMiner.ZM
10.12948

Fortinet FortiGate
W32/CoinMiner.ZM!tr
1/31/2016

IKARUS anti.virus
Trojan.Win32.CoinMiner
t3scan.2.0.4.0

K7 AntiVirus
Trojan
13.213.18582

McAfee
Artemis!79A87F9B9AD4
5600.6503

Reason Heuristics
Trojan.Downloader (M)
16.7.30.11

VIPRE Antivirus
Trojan.Win32.Generic
46838

Zillya! Antivirus
Adware.OutBrowse.Win32.80053
2.0.0.2638

File size:
71.5 KB (73,216 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\windows\taskmgr.exe

File PE Metadata
Compilation timestamp:
8/9/2015 12:09:22 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
1536:QRbGqZFpX2/DI0EimRkN8hwkbWjNdGz7h9p:QRb0/DI/tRkN8GtpdG/h9p

Entry address:
0x1000

Entry point:
48, 83, EC, 28, 49, C7, C0, F8, 01, 00, 00, 48, 31, D2, 48, B9, D4, 48, 01, 40, 01, 00, 00, 00, E8, E3, 3F, 00, 00, 48, 31, C9, E8, E7, 3F, 00, 00, 48, 89, 05, B0, 38, 01, 00, 4D, 31, C0, 48, C7, C2, 00, 10, 00, 00, 48, 31, C9, E8, D4, 3F, 00, 00, 48, 89, 05, 8F, 38, 01, 00, E8, B6, D5, 00, 00, E8, 01, D4, 00, 00, E8, 6C, B1, 00, 00, E8, 6B, A9, 00, 00, E8, 22, 9F, 00, 00, E8, A1, 9A, 00, 00, E8, 98, 98, 00, 00, E8, BF, 96, 00, 00, E8, 26, 96, 00, 00, E8, 89, 7F, 00, 00, E8, CC, 6B, 00, 00, E8, D3, 57, 00...
 
[+]

Code size:
54.5 KB (55,808 bytes)

The file taskmgr.exe has been seen being distributed by the following URL.

Remove taskmgr.exe - Powered by Reason Core Security