|  | 
| taskmgr.exe (5.1.2600.1106)
| Contained in software | 
|---|
 | Name: | Windows XP Home Edition, Deutsch | 
|---|
 | License: | commercial | 
|---|
 | Information link: | http://www.microsoft.com/windowsxp/ | 
|---|
 | File details | 
|---|
 | Filepath: | C:\WINDOWS\system32 \ taskmgr.exe | 
|---|
 | Filedate: | 2002-08-29 14:00:00 | 
|---|
 | Version: | 5.1.2600.1106 | 
|---|
 | Filesize: | 133.632 bytes | 
|---|
 | Checksum and file hashes | 
|---|
 | CRC32: | 53F7655F | 
|---|
 | MD5: | 5193 5775 4683 477F 5609 D021 1D1D 7B52 | 
|---|
 | SHA1: | E548 1F84 70FF 1E36 FDB3 0472 54DF 75DE DDD4 FC06 | 
|---|
 | Version resource information | 
|---|
 | CompanyName: | Microsoft Corporation | 
|---|
 | FileDescription: | Windows Task-Manager | 
|---|
 | FileOS: | Windows NT, Windows 2000, Windows XP, Windows 2003 | 
|---|
 | FileType: | Application | 
|---|
 | FileVersion: | 5.1.2600.1106 | 
|---|
 | InternalName: | taskmgr | 
|---|
 | LegalCopyright: | © Microsoft Corporation. Alle Rechte vorbehalten. | 
|---|
 | OriginalFilename: | taskmgr.exe | 
|---|
 | ProductName: | Betriebssystem Microsoft® Windows® | 
|---|
 | ProductVersion: | 5.1.2600.1106 | 
|---|
 
 taskmgr.exe was found in the following malware reports:
|  | 
|---|
 | Trojan.Nullpos | 
|---|
 | Technical details ...Displays the message: Copies the file, %System%TASKMGR.EXE, to the %Windows% folder....
 ...Modifies the file, %System%TASKMGR.EXE. Note: %System% is a variable....
 Removal instructions
 ...Reset the screen saver. Copy the file %Windows%TASKMGR.EXE to the %System% folder....
 ...5. To copy the file %Windows%TASKMGR.EXE to the %System% folder...
 ...Using Windows Explorer, locate the file Taskmgr.exe in the %Windir% folder and copy it to the %System% folder....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.nullpos.html
 | 
|---|
 | Trojan.Dingsta.A | 
|---|
 | Technical details ...Adds the value: "taskmgr.exe" = "%Path%svch0st.exe"...
 ...Adds the value: "taskmgr.exe" = "%Path%svch0st.exe"...
 ...Adds the value: "taskmgr.exe" = "%Path%svch0st.exe"...
 Removal instructions
 ...right pane, delete the value: "taskmgr.exe" = "%Path%svch0st.exe"...
 ...right pane, delete the value: "taskmgr.exe" = "%Path%svch0st.exe"...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.dingsta.a.html
 | 
|---|
 | W32.HLLW.Lovgate.G@mm | 
|---|
 | Technical details ...Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch...
 ...The worm monitors the remote thread in either Explorer.exe or Taskmgr.exe. If the thread is stopped,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.g@mm.html
 | 
|---|
 | Trojan.AprilFool | 
|---|
 | Technical details ...Value 1: "DisableTaskMgr"="1" This value prevents you from...
 Removal instructions
 ...following to 0 as shown here: "DisableTaskMgr"="0" "DisableLockWorkstation"="0"...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.aprilfool.html
 | 
|---|
 | W32.HLLW.Lovgate.H@mm | 
|---|
 | Technical details ...Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch...
 ...The worm monitors the remote thread in either Explorer.exe or Taskmgr.exe. If the thread is stopped,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.h@mm.html
 | 
|---|
 | W32.HLLW.Lovgate.I@mm | 
|---|
 | Technical details ...Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch...
 ...The worm monitors the remote thread in either Explorer.exe or Taskmgr.exe. If the thread is stopped,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.i@mm.html
 | 
|---|
 | W32.HLLW.Lovgate.J@mm | 
|---|
 | Technical details ...Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch...
 ...The worm monitors the remote thread in either Explorer.exe or Taskmgr.exe. If the thread is stopped,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.j@mm.html
 | 
|---|
 | W32.HLLW.Lovgate.K@mm | 
|---|
 | Technical details ...Injects a process-watching routine as a thread into either Explorer.exe or Taskmgr.exe. This remote thread will launch...
 ...The worm monitors the remote thread in either Explorer.exe or Taskmgr.exe. If the thread is stopped,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.k@mm.html
 | 
|---|
 | Trojan.StartPage.G | 
|---|
 | Technical details ...following copies of itself: %Windir%system	askmgr.exe %Windir%N0TEPAD.EXE...
 ...Adds the value: "taskmgr"="%Windows%system	askmgr.exe"...
 Removal instructions
 ...right pane, delete the value: "taskmgr"="%Windows%system	askmgr.exe"...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.g.html
 | 
|---|
 | Backdoor.Assasin | 
|---|
 | Technical details ...Sysedit.exe Taskmgr.exe Taumon.exe...
 ......
 Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.assasin.html
 | 
|---|
 |  |