PUA

About “Mal/Generic-S + OxyPumper (PUA)” infection

Malware Removal

The Mal/Generic-S + OxyPumper (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + OxyPumper (PUA) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Mal/Generic-S + OxyPumper (PUA)?


File Info:

name: 2E8B10D23226372E94B1.mlw
path: /opt/CAPEv2/storage/binaries/b6db5560e3ac016e4375473fd3d1fb214c03afcc6982d6e3e1267da6bb71fa98
crc32: 7740371E
md5: 2e8b10d23226372e94b14b3122d74213
sha1: 298efd571dcc74f0308b3ac957eda19c9328269e
sha256: b6db5560e3ac016e4375473fd3d1fb214c03afcc6982d6e3e1267da6bb71fa98
sha512: f72261e9cfa5cea66f84b83209e2d537ddd92b315a8d6b09d17aecd1607d4ab3af763e1976afde8a6687d57626bccd61fe639730665bc1635bcceb4109422d30
ssdeep: 3072:rZOaek9dhlv9ebNaHEeKgVYbp3BjVq5U0s58KrO9QQr:rc8d9ebAHEreYbJBF0s5Q+Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8E3181A7656CE11C26D253AC8DF461843F8AE862A73DB5E3DCE725C15423B3AC0E6CD
sha3_384: b193591476d2469a7ec686149ab3e30955be2a575e561ae644636f688f19f46a8712ebad092e3a71a8d27883e7a5850b
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-21 13:33:39

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Service for Internet Information
FileVersion: 7.0.6101.18862
InternalName: inetinfo.exe
LegalCopyright: Copyright© 2012-2017
OriginalFilename: inetinfo.exe
ProductVersion: 7.0.6101.18862
Assembly Version: 7.0.6101.18862

Mal/Generic-S + OxyPumper (PUA) also known as:

LionicTrojan.MSIL.TaskLoader.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2e8b10d23226372e
ALYacGen:Variant.Razy.975534
CylanceUnsafe
ZillyaDownloader.TaskLoader.Win32.329
SangforTrojan.MSIL.TaskLoader.gen
K7AntiVirusAdware ( 0057dd0b1 )
AlibabaTrojanDownloader:MSIL/TaskLoader.9ba10425
K7GWAdware ( 0057dd0b1 )
Cybereasonmalicious.232263
CyrenW32/TaskLoader.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.OxyPumper.AK
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.MSIL.TaskLoader.gen
BitDefenderGen:Variant.Razy.975534
MicroWorld-eScanGen:Variant.Razy.975534
AvastWin32:AdwareX-gen [Adw]
TencentMsil.Trojan-downloader.Taskloader.Hugh
Ad-AwareGen:Variant.Razy.975534
SophosMal/Generic-S + OxyPumper (PUA)
DrWebTrojan.PWS.Stealer.31383
TrendMicroTROJ_GEN.R002C0PJP21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Razy.975534 (B)
IkarusAdWare.MSIL.OxyPumper
GDataGen:Variant.Razy.975534
JiangminTrojanDownloader.MSIL.afbj
AviraHEUR/AGEN.1203189
Antiy-AVLTrojan/Generic.ASMalwS.34C3730
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmHEUR:Trojan-Downloader.MSIL.TaskLoader.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
AhnLab-V3Trojan/Win32.MSILKrypt.C2265893
McAfeeGenericRXHX-YF!2E8B10D23226
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
MalwarebytesAdware.OxyPumper
TrendMicro-HouseCallTROJ_GEN.R002C0PJP21
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:d3s0da9uvIy0cSiRpLiV+g)
YandexPUA.OxyPumper!BQ46JINlYTc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/OxyPumper
BitDefenderThetaGen:NN.ZemsilF.34212.jq0@aCxzRGo
AVGWin32:AdwareX-gen [Adw]
PandaTrj/GdSda.A
CrowdStrikewin/grayware_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Mal/Generic-S + OxyPumper (PUA)?

Mal/Generic-S + OxyPumper (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment