Malware

Bulz.368911 information

Malware Removal

The Bulz.368911 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.368911 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Bulz.368911?


File Info:

name: F0C4F90AA9D0106B31E1.mlw
path: /opt/CAPEv2/storage/binaries/5a3b82ccde335eb5b3e8efc0ead9c262385736763a69c0dc1323c390ae75ec5f
crc32: 9E206C33
md5: f0c4f90aa9d0106b31e1eba93e2e9319
sha1: 3a5f9393c1305513f503468478bf7a9247483ac1
sha256: 5a3b82ccde335eb5b3e8efc0ead9c262385736763a69c0dc1323c390ae75ec5f
sha512: eb6f8a173a0c7aa516cfe768c32635d0d9fd4e4cedf6fe5bb59d35b277603c65d9b3a37a050681aaf4d3c9462194fea0866b1add982d662d79c91d239f5fbee6
ssdeep: 196608:qZuuAETgwpSqP+p4c6xNYmgN51FOVLR3wKGR13YfRHwTt8KqZ4/zV9LgYCD25w2Q:qZuJI896cm2SNwTRFumSxZm9LRLVO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17ED6337269738794E88FF674D1221A77E2FFF8319125A3C1C4383921FBA681E94177A4
sha3_384: 98fc37b16bce1091ce014f8d2ac5ba73ed4d539878a6f73edd8ec5d1afc95032a4842be1d9d0a0fe930f8c732f1677a9
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-01-30 03:57:45

Version Info:

FileDescription: setup
FileVersion: 12.0.3396.99
LegalCopyright: Copyright 2017 All rights reserved.
ProductName: setup
Translation: 0x0409 0x04e4

Bulz.368911 also known as:

LionicTrojan.Win32.RegRun.4!e
MicroWorld-eScanGen:Variant.Bulz.368911
FireEyeGeneric.mg.f0c4f90aa9d0106b
McAfeeArtemis!F0C4F90AA9D0
CylanceUnsafe
ZillyaDropper.Dapato.Win32.54101
K7AntiVirusTrojan ( 0053b57b1 )
AlibabaTrojanDropper:Win32/Dapato.c200b26e
K7GWTrojan ( 0053b57b1 )
Cybereasonmalicious.aa9d01
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.KLJHOUY
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Dapato.plmi
BitDefenderGen:Variant.Bulz.368911
NANO-AntivirusTrojan.Win32.Small.ffqsfo
AvastWin32:Trojan-gen
TencentWin32.Trojan-dropper.Dapato.Ecto
Ad-AwareGen:Variant.Bulz.368911
EmsisoftGen:Variant.Bulz.368911 (B)
ComodoMalware@#18rrz1noc7g18
DrWebTrojan.MulDrop9.1960
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
IkarusTrojan.PSW.Coins
GDataGen:Variant.Bulz.368911
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1225009
MAXmalware (ai score=84)
ArcabitTrojan.Bulz.D5A10F
ZoneAlarmTrojan-Dropper.Win32.Dapato.plmi
MicrosoftTrojan:Win32/Occamy.C5A
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.HPDefender.R345942
ALYacGen:Variant.Bulz.368911
VBA32TrojanDropper.Dapato
MalwarebytesMalware.AI.1900585922
MaxSecureTrojan.Malware.74098563.susgen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.368911?

Bulz.368911 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment