Malware

GenPack:Generic.Mulinex.B7096C3C malicious file

Malware Removal

The GenPack:Generic.Mulinex.B7096C3C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Generic.Mulinex.B7096C3C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine GenPack:Generic.Mulinex.B7096C3C?


File Info:

name: 15841A2381D63007E827.mlw
path: /opt/CAPEv2/storage/binaries/c466b423ffb9e1a1f739b5ceea3cf96e124a28b187f33b63393ff649985b9d16
crc32: 08A6327F
md5: 15841a2381d63007e827de1d1f7e4a11
sha1: c579bf805ca6896b96fea50cc8d84b691d20908f
sha256: c466b423ffb9e1a1f739b5ceea3cf96e124a28b187f33b63393ff649985b9d16
sha512: 8745a318ad6463e9155c94bd47ff8b7daf4e32f037e228df036dc6eeaec74de09440a35c80f24049db8f86abd21434ed5bf1716d5d6b625d0133ae065ec6ffa4
ssdeep: 6144:mvXxth5oGMTu9TsVjqeU7XM8ewz+TPaoXtGUFp0RltAb+6NKUNZ8o0NpkSq:mrPz9TQGeiXM8Hyjao8UFpIbAxKUNcB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1678423677BED5624D12E7BB9C26F47D0826EF9592887074F018164EB7A18360CE07EF8
sha3_384: b3596c292fce18547d49d87e2b773c2c9b4c87a08f756d4c5128619d8dba6b5cbbb7e2f18d31f316ea499adf64be06ca
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2021-12-28 18:38:54

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Depuración del programa de instalación de Microsoft DirectX
FileVersion: 4.9.0.0904
InternalName: dxsetup.exe
LegalCopyright: Copyright © Microsoft Corporation. Reservados todos los derechos.
OriginalFilename: dxsetup.exe
ProductName: Microsoft® DirectX para Windows®
ProductVersion: 4.9.0.0904
Translation: 0x040a 0x04b0

GenPack:Generic.Mulinex.B7096C3C also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.59687
MicroWorld-eScanGenPack:Generic.Mulinex.B7096C3C
FireEyeGeneric.mg.15841a2381d63007
CAT-QuickHealTrojanpws.Qqpass.16543
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005376ae1 )
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.381d63
ArcabitGenPack:Generic.Mulinex.B7096C3C
BitDefenderThetaGen:NN.ZexaF.34114.xmuaaegvUtjb
CyrenW32/Coinminer.CW.gen!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.BUF
ClamAVWin.Dropper.Mulinex-9922824-0
KasperskyVHO:Trojan.Win32.Miner.gen
BitDefenderGenPack:Generic.Mulinex.B7096C3C
AvastOther:Malware-gen [Trj]
RisingBackdoor.Agent!1.B7E4 (CLASSIC)
Ad-AwareGenPack:Generic.Mulinex.B7096C3C
EmsisoftGenPack:Generic.Mulinex.B7096C3C (B)
BaiduWin32.Trojan.Farfli.e
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Malicious PE
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.CoinMiner
JiangminTrojan.Sasfis.tq
AviraHEUR/AGEN.1207618
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/CoinMiner
GDataGenPack:Generic.Mulinex.B7096C3C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356028
VBA32BScope.Trojan.Dynamer
ALYacGenPack:Generic.Mulinex.B7096C3C
MalwarebytesRiskWare.BitCoinMiner
APEXMalicious
YandexTrojan.GenAsa!yjdVfs5kyhw
MAXmalware (ai score=82)
FortinetW32/CoinMiner.BUF!tr
AVGOther:Malware-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove GenPack:Generic.Mulinex.B7096C3C?

GenPack:Generic.Mulinex.B7096C3C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment