Threat Database Trojans Trojan.MSIL.Tasker

Trojan.MSIL.Tasker

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,706
Threat Level: 80 % (High)
Infected Computers: 85
First Seen: May 25, 2024
Last Seen: July 4, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Tasker on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operation, symptoms, and most importantly, the steps to remove it from your computer.

What Is Trojan.MSIL.Tasker?

Trojan.MSIL.Tasker, as detected, suggests a type of Trojan horse malware. Trojans are malicious programs that disguise themselves as legitimate software to gain unauthorized access to a computer system. The name itself does not directly imply a specific malware family but indicates it's written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic bytecode. This means the malware could potentially run on any system that supports .NET Framework, making it versatile and potentially dangerous.

How Trojan.MSIL.Tasker Operates

Typically, Trojans like Trojan.MSIL.Tasker operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a variety of malicious activities, including but not limited to, stealing sensitive information, downloading additional malware, or providing unauthorized access to the attacker. The specific operation of Trojan.MSIL.Tasker can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or programs starting automatically without user intervention. Additionally, changes in browser settings or the appearance of unknown programs in the list of installed applications can also indicate a Trojan infection. Since Trojans can be designed to remain stealthy, some infections may not exhibit noticeable symptoms until significant damage has been done.

How to Remove Trojan.MSIL.Tasker

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This can usually be done by restarting your computer and pressing the F8 key repeatedly during boot-up.
  2. Perform a full scan with a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to maximize its effectiveness against the latest threats.
  3. Uninstall suspicious programs that were installed around the time the malware was detected. Be cautious and only remove programs you do not recognize or no longer need.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure all traces of the malware have been removed.

Conclusion

The removal of Trojan.MSIL.Tasker requires careful and immediate action to prevent further damage to your system and protect your personal data. By following the steps outlined in this report, you should be able to remove the malware and restore your system's security. Remember, prevention is key; always be cautious when downloading software, keep your operating system and applications updated, and use reputable security software to protect against future threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Tasker
Signature status: No Signature

Known Samples

MD5: c9870cea7f5f87bdd6a8f793b59020b0
SHA1: eadd3818a0769d33a980bb5cd4ebdf7b5d3cfab0
SHA256: 131418B0845245F4A70B658CB94B959900CAA6D8B924B1F537F264319A2F6A54
File Size: 2.23 MB, 2233856 bytes
MD5: 62fc23efe3b4a8a91ddd53f364ae45b5
SHA1: 4a0a40ff1b7eefd6381d63891832c1ddc63942bf
SHA256: A808F4E5300070B9F0C03CB25A3A6840B1D3C085F4FE4D27A4B69EA712480EB0
File Size: 550.40 KB, 550400 bytes
MD5: 12b73f83648d21e59f1716f70e5941b2
SHA1: 93006226584e9119d08ace3ece8a1182c66f134c
SHA256: 2ABF6A90346CCE761FB03DDD7CA9572F3524C2C04E39852EC6B10FA08134C2EB
File Size: 901.15 KB, 901152 bytes
MD5: 900e637da23efa18a140d9bd99a98db4
SHA1: e75821cb7470eb7d37a1ffd29825aed32fb8e0d2
SHA256: 751AB2D83A93E4DCBD81EC3984DA1705D28192847A3352CC1F2B85649EA02105
File Size: 608.26 KB, 608256 bytes
MD5: 2209d3c84c2b6fca7dabcec4425338c1
SHA1: edc82af6cfc2c448e22ca8abb016e205ae78079b
SHA256: E587CDD43A4551A274A5DD6767E366C70F7D088F124C661798B6F90B5BEF56CE
File Size: 514.05 KB, 514048 bytes
Show More
MD5: f64014965047ef83adeb0259951459fd
SHA1: b1e789dff76e037f309b44b236889bf4553b2953
SHA256: 332F96931E79C8E9658D2A748E4E6AE7D6D60650029D3B51E9ADD9AAB28E4995
File Size: 547.33 KB, 547328 bytes
MD5: 90d39687f0567fc85f7acd8e5d23ad77
SHA1: b4bdeaa6bee91d54d3c975598d03323417a75c86
SHA256: BEA88EE1C06E71585C0314F32B99F35D34DA2D0C9AC82A4D977239097114B76D
File Size: 898.56 KB, 898560 bytes
MD5: dd0122d97f71e3b34a18eba5018aa6e1
SHA1: 8be6fae5afa5921c2c1138b3dab3ec844ea8bfd3
SHA256: AE9BA6697A0CCFB8F8AC0425F292E5AB54FB48159E63AB29CF2587A9399B5C05
File Size: 1.66 MB, 1657856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.8.1.0
  • 2.5.6.155
  • 1.0.0.0
  • 0.4.4.0
Comments Administrateur des bases de données XMed sur SQL Server 2005-2016
Company Name
  • A10 Technologie
  • ButterScroll
  • ClamAVGui
  • Everywhere.Windows
  • OnionHopV2.Core
File Description
  • BiirtualScore.Pos
  • ButterScroll
  • ClamAVGui
  • Everywhere.Windows
  • OnionHopV2.Core
  • XMedAdmin
File Version
  • 4.8.1.0
  • 2.5.6.155
  • 1.0.0.0
  • 0.4.4
Internal Name
  • BiirtualScore.Pos.exe
  • ButterScroll.dll
  • ClamAVGui.dll
  • Everywhere.Windows.dll
  • OnionHopV2.Core.dll
  • XMedAdmin.exe
Legal Copyright
  • Copyright © 2016 A10 Technologie
  • Copyright © 2021
Original Filename
  • BiirtualScore.Pos.exe
  • ButterScroll.dll
  • ClamAVGui.dll
  • Everywhere.Windows.dll
  • OnionHopV2.Core.dll
  • XMedAdmin.exe
Product Name
  • BiirtualScore.Pos
  • ButterScroll
  • ClamAVGui
  • Everywhere.Windows
  • OnionHopV2.Core
  • XMedAdmin
Product Version
  • 4.8.1.0
  • 2.5.6.155
  • 1.0.0+f97eaafaa247645a40fa45623bcde4f26f655f14
  • 1.0.0+e22acbfd08692fe3f087920848e0af4627373c36
  • 1.0.0
  • 0.4.4+1c8d4a2a212abddf7c3ffbd069190ee8e4779c7d

File Traits

  • .NET
  • 2+ executable sections
  • Agile.net
  • dll
  • Fody
  • HighEntropy
  • NewLateBinding
  • Run
  • x64
  • x86

Block Information

Total Blocks: 1,392
Potentially Malicious Blocks: 11
Whitelisted Blocks: 590
Unknown Blocks: 791

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? x ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? ? 0 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? 0 0 ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 0 ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 x ? 0 ? ? 0 0 ? 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 0 0 ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? ? x ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 0 ? x ? 0 0 ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? ? ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? x ? 0 0 ? ? ? ? 0 0 ? 0 0 0 0 ? 0 ? 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 0 0 ? 0 ? 0 ? ? 0 0 ? 0 ? ? 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 ? ? 0 0 ? x ? ? ? ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? 0 ? 0 0 0 0 ? ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? 0 0 ? 0 0 ? ? ? 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 ? ? ? x 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Keyboard Access
  • GetKeyState
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...