Threat Database Trojans Trojan.Tasker.EA

Trojan.Tasker.EA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,480
Threat Level: 80 % (High)
Infected Computers: 147
First Seen: December 15, 2023
Last Seen: June 30, 2026
OS(es) Affected: Windows

The detection of Trojan.Tasker.EA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, steal sensitive information, or disrupt its normal functioning. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Tasker.EA?

Trojan.Tasker.EA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" refers to the mythological Trojan Horse, where attackers hid inside a giant wooden horse to gain access to a protected city. Similarly, Trojan malware hides within or masquerades as legitimate software to gain unauthorized access to a computer system. The ".EA" suffix may indicate a specific variant or classification of the Trojan, but without more detailed information, it's challenging to determine its exact characteristics or behaviors.

How Trojan.Tasker.EA Operates

Trojan horses like Trojan.Tasker.EA typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a wide range of malicious activities, including stealing personal data, installing additional malware, providing unauthorized access to the attacker, or disrupting system operation. These actions can lead to significant security breaches, financial loss, and compromise of personal information. The specific operations of Trojan.Tasker.EA would depend on its design and the intentions of its creators, which could range from data theft to using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks.

Symptoms of Infection

The symptoms of a Trojan.Tasker.EA infection can vary widely, depending on its primary function and the extent of the infection. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or programs starting automatically. You might also notice that your browser settings have changed without your input, or you're being redirected to unwanted websites. In some cases, the infection might not display obvious symptoms, making it difficult to detect without the use of antivirus software.

How to Remove Trojan.Tasker.EA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools if necessary.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware. Ensure your antivirus software is updated with the latest definitions before running the scan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not essential to your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and run another full scan with your anti-malware software to ensure that all remnants of the malware have been removed. This step is crucial to confirm the system is clean and to remove any potential leftovers that could reinfect the system.

Conclusion

Removing Trojan.Tasker.EA and preventing future infections require a combination of technical knowledge, the right tools, and cautious behavior online. By understanding how Trojans operate and taking proactive steps to secure your system, you can significantly reduce the risk of infection. Regularly updating your operating system and software, avoiding suspicious downloads, and using reputable antivirus software are key components of a comprehensive security strategy. If you're unsure about any part of the removal process or if the problem persists after attempting to remove the malware, consider seeking help from a professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.Tasker.EA
Signature status: No Signature

Known Samples

MD5: 048fff653043bbd4843e5e6579e16982
SHA1: ad8dfd2b326c21346966f90dcb89559c910237ca
SHA256: 5B0D27BE3704FF222160D9E9DDABEE18BE19CABF4CE5A8C6BE1FD5D1C1DD2875
File Size: 188.42 KB, 188416 bytes
MD5: 4cf6be68e175ee5e2258a189720ba755
SHA1: fe73d50e30bed0ab4c5307d35564a97b1fdf5448
SHA256: EBA5FB0826994C1ED02E5878F269E35E0C5B60A8EA9C99107086F8E139C92B0D
File Size: 188.42 KB, 188416 bytes
MD5: 849812e4b99493b132a08b0108f4febe
SHA1: 8253dee8ea02ddfe9f7c5121cf94c77963e7ce96
SHA256: BBE8841DCB1BAED6142579871D3C327316C975954CD58EA2FE28A454B06AF9ED
File Size: 180.22 KB, 180224 bytes
MD5: c1565b3e5ad6b39a98f40c2347bc42bf
SHA1: 784b46d8030a6dfbed6477fa31bf12c3d679c9ea
SHA256: 0C0C49E766A609D300161CEA0F810329D839A40EB428BDE5B177AE8FCA993CB0
File Size: 188.42 KB, 188416 bytes
MD5: 78d71ba60a11cd94cef9820d224f1c5b
SHA1: 979fbd408d87a276e067c9ace7cb7df44621215b
SHA256: CF9119E76BAF144F3B826D2A0F7A1DF7E163231136475A531F7C7740B7E62767
File Size: 217.09 KB, 217088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
File Description
  • Archivo autoextractor de archivos CAB de Win32
  • Programma di autoestrazione di file CAB Win32
  • Win32 Cabinet Self-Extractor
File Version
  • 11.00.22621.4744 (WinBuild.160101.0800)
  • 11.00.22621.4315 (WinBuild.160101.0800)
  • 11.00.22621.4311 (WinBuild.160101.0800)
  • 11.00.22621.1 (WinBuild.160101.0800)
Internal Name
  • Wextract
Legal Copyright
  • © Microsoft Corporation. All rights reserved.
  • © Microsoft Corporation. Todos los derechos reservados.
  • © Microsoft Corporation. Tutti i diritti riservati.
Original Filename
  • WEXTRACT.EXE
  • WEXTRACT.EXE .MUI
Product Name
  • Internet Explorer
  • ZOICWARE
Product Version
  • 11.00.22621.4744
  • 11.00.22621.4315
  • 11.00.22621.4311
  • 11.00.22621.1

File Traits

  • CAB SFX
  • HighEntropy
  • Wextract
  • x64

Block Information

Total Blocks: 116
Potentially Malicious Blocks: 59
Whitelisted Blocks: 57
Unknown Blocks: 0

Visual Map

0 0 1 x 0 2 0 0 0 0 0 0 0 0 1 1 0 0 x x x x x x 0 x x x 1 x 0 0 0 0 0 x 0 0 x x 0 x x 0 x x 0 x x x x x 0 0 x x 0 0 0 x x 0 x x 1 x x x x x 1 x 0 0 x 0 0 0 x x 0 0 0 x x x x 0 x 0 x x x x x 0 x x x x x x 0 x x 0 0 x x 0 x 2 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Tasker.E
  • Tasker.EA

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\pshost.134029675447925709.5200.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134242124116615249.8268.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_3242lyk2.phq.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_alccnloe.3p4.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_wmz3n0nu.wgc.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_wwhpfxt0.tb3.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\info_computer.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\info_computer.bat Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ixp000.tmp\info_computer.bat_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\kmseldi_original.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\kmseldi_original.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\max.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\max.ps1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\run zoicware.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\run zoicware.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Jdbvosbz\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 쨉驰⭇ǜ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Zkdezijc\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 叨箠荅ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 뙐箢荅ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Ewdfdonc\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ㆧ૰軬ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ૴軬ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Tfxwktgp\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ⸦⡭ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⡱ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
Show More
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateTransaction
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenKeyTransactedEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory

187 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
  • WriteConsole
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Network Winsock2
  • WSAConnect
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen
Process Manipulation Evasion
  • NtUnmapViewOfSection
Service Control
  • OpenSCManager
  • OpenService
Process Terminate
  • TerminateProcess

Shell Command Execution

PowerShell.exe -noprofile -Sta -executionpolicy bypass -File max.ps1
cmd /c "INFO_COMPUTER.bat"
WriteConsole:
WriteConsole: ----------------
WriteConsole: !!!CONDIVIDERE
Show More
WriteConsole: PER ASSISTENZA
WriteConsole: Sono connesso co
WriteConsole: Il mio nome comp
WriteConsole: Il mio ip e:
C:\WINDOWS\system32\ipconfig.exe ipconfig
C:\WINDOWS\system32\find.exe find "IPv4"
WriteConsole: Stato del mio fi
C:\WINDOWS\system32\netsh.exe netsh advfirewall show allprofiles state
WriteConsole: Premi spazio per
cmd /c KMSELDI_original.bat
WriteConsole: ================
WriteConsole: Wait...
C:\WINDOWS\system32\cacls.exe "C:\WINDOWS\system32\cacls.exe" "C:\WINDOWS\system32\config\system"
C:\WINDOWS\system32\chcp.com chcp 866
WriteConsole: e294acc3ace294acc39120e294acc2a1
C:\WINDOWS\system32\timeout.exe timeout /t 7
cmd /c "RUN ZOICWARE.bat"
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -nop -ExecutionPolicy Bypass -c "iex([io.file]::ReadAllText($env:0))"

Trending

Most Viewed

Loading...