Home Malware Programs Trojans Trojan.OxyPumper

Trojan.OxyPumper

Posted: April 23, 2016

Threat Metric

Ranking: 1,529
Threat Level: 8/10
Infected PCs: 336,831
First Seen: April 23, 2016
Last Seen: March 10, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\WindowsUpdater\Updater.exe File name: Updater.exe
Size: 49.66 KB (49664 bytes)
MD5: ad5790070d459c64b1a6353979b570e1
Detection count: 459
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\WindowsUpdater\Updater.exe
Group: Malware file
Last Updated: April 21, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\\systemlocation\\utcwatcher.exe File name: utcwatcher.exe
Size: 69.12 KB (69120 bytes)
MD5: 059fd9d60ee47bc6b266a4fe7a9da1b5
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\\systemlocation\\utcwatcher.exe
Group: Malware file
Last Updated: December 6, 2020
C:\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1FWEW28N\updater[1].exe File name: updater[1].exe
Size: 51.2 KB (51200 bytes)
MD5: 9c9cec8413f429aa121c7238be78898d
Detection count: 262
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1FWEW28N\updater[1].exe
Group: Malware file
Last Updated: November 19, 2021
C:\Users\<username>\ReportSender\ReportSender.exe File name: ReportSender.exe
Size: 49.66 KB (49664 bytes)
MD5: 4ad090268af0a45317126f2dae8c4a7e
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\ReportSender\ReportSender.exe
Group: Malware file
Last Updated: April 29, 2023
C:\Users\<username>\AppData\Roaming\ErrorReporting\ermgr.exe File name: ermgr.exe
Size: 66.56 KB (66560 bytes)
MD5: ccb2406905986e0bc7ab7e8025932d72
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\ErrorReporting\ermgr.exe
Group: Malware file
Last Updated: October 22, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\\simpleapps\\wizardguid.exe File name: wizardguid.exe
Size: 33.79 KB (33792 bytes)
MD5: 80c1c53ce63cba93572b31f02ec92f5a
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\\simpleapps\\wizardguid.exe
Group: Malware file
Last Updated: June 23, 2021

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathInternetInfoTool.lnkRegexp file mask%ALLUSERSPROFILE%\VCore\VCore.exe%ALLUSERSPROFILE%\WindowsReporting\wermgr.exe%ALLUSERSPROFILE%\WindowsVideoErrorReporting\wvermgr.exe%APPDATA%\Adobe\Manager.exe%APPDATA%\ErrorReporting\ermgr.exe%APPDATA%\freetools\guids.exe%APPDATA%\simpleapps\wizardguid.exe%APPDATA%\simpletools\masterguid.exe%APPDATA%\systemlocation\utcwatcher.exe%APPDATA%\WindowsUpdater\Updater.exe%LOCALAPPDATA%\IIS\inetinfo.exe%USERPROFILE%\ReportSender\ReportSender.exe%WINDIR%\Manager.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\EDSUpdSrv%ALLUSERSPROFILE%\InstallChecker%ALLUSERSPROFILE%\RegisterObject%ALLUSERSPROFILE%\RenewalService%ALLUSERSPROFILE%\UpService%ALLUSERSPROFILE%\VideoMemoryDiagnostic%APPDATA%\KeyCreator%APPDATA%\ReportErr%APPDATA%\perftrack%APPDATA%\threatdatabase%APPDATA%\utctimer%LOCALAPPDATA%\InetInfo%LOCALAPPDATA%\SrvInetInfo%LOCALAPPDATA%\inetinfoservice%LOCALAPPDATA%\inst%LOCALAPPDATA%\instopch%LOCALAPPDATA%\netinfokit%LOCALAPPDATA%\netinformapp%LOCALAPPDATA%\tubeinetinfo%UserProfile%\Local Settings\Application Data\netinformapp%UserProfile%\SoundProvider%appdata%\SysInfoTool%appdata%\syshost%appdata%\systemdiag%appdata%\timerutc%appdata%\toolsyshost%appdata%\videoappriser
Loading...