Adware

What is “Adware.Bulz.2318”?

Malware Removal

The Adware.Bulz.2318 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Bulz.2318 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

How to determine Adware.Bulz.2318?


File Info:

name: 5866FBA9EDF312151441.mlw
path: /opt/CAPEv2/storage/binaries/9fce288d2282133572d9655cab23fe88afb45d1f5e2802b21f08c92a25f6cbb2
crc32: F8D265CF
md5: 5866fba9edf3121514418208d8ce9aae
sha1: 1643604cf743cd551de701655ef5838c319ba202
sha256: 9fce288d2282133572d9655cab23fe88afb45d1f5e2802b21f08c92a25f6cbb2
sha512: 3ccc2d8d047e437c34f34a1f8e71c5015dc6b871c31887b8ba6fb5a3b3bdfc46b38684e0144d5135f1a7c5bd698ae39a12a8c20beb19f93e9f54ec943b0d9b56
ssdeep: 49152:+v5PaaUHZlzKgKteGhKJ+Lhk3HeZZ+Qkh6gR1kWi6f4Zo+cX4:akPnzfiA2+Qc6g1/i6fW2X4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131C53351D29284B2F26336F0632A85FC4FBBBD415878706CB24DBD5A8FA6B71458C723
sha3_384: 1eea017f5da3ce21e693a52d4ffb6593e4a4aeedebc69c6e570ce53ea9f6fb9b80bf9f9661a40bdaf6653af00cd3386b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2020-12-02 14:17:55

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Vne Recorder Setup
FileVersion: 1.0.0.9
LegalCopyright:
ProductName: Vne Recorder
ProductVersion: 1.0.0.9
Translation: 0x0000 0x04b0

Adware.Bulz.2318 also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Bulz.2318
FireEyeGen:Variant.Adware.Bulz.2318
McAfeeArtemis!5866FBA9EDF3
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9edf31
ArcabitTrojan.Adware.Bulz.D90E
CyrenW32/Convagent.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Convagent-9827235-0
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Adware.Bulz.2318
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Convagent.Swbe
Ad-AwareGen:Variant.Adware.Bulz.2318
SophosMal/Generic-S
DrWebTrojan.Siggen9.22670
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
EmsisoftGen:Variant.Adware.Bulz.2318 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Convagent.i
AviraHEUR/AGEN.1140093
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Adware.Bulz.2318
AhnLab-V3Malware/Win32.Generic.C4251095
ALYacGen:Variant.Adware.Bulz.2318
MAXmalware (ai score=64)
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002H0CL421
FortinetRiskware/Application
AVGWin32:AdwareX-gen [Adw]

How to remove Adware.Bulz.2318?

Adware.Bulz.2318 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment