Adware

About “Adware.Bulz.5915” infection

Malware Removal

The Adware.Bulz.5915 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Bulz.5915 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rtrkpi3.com
tpbhumantest.bid
www.bing.com
ww12.tpbhumantest.bid

How to determine Adware.Bulz.5915?


File Info:

crc32: DE6FC52E
md5: b136bc58c304e559829c937ba33aeef2
name: B136BC58C304E559829C937BA33AEEF2.mlw
sha1: cc0a03e78d992b9fef3250483d0ebe996721a64d
sha256: 20677d302bf2afebdd5b11ffe48b450ab4153c70a0562dd07e7f7d55036a9b1e
sha512: 30105014dac96bbcf19e31b7cf5b0954d6d1e168cc620a5a2bb2456c04cc5ce99a972ff6d7fe29f4ef09c93ee5e92df671fdbf4945f06909a9453731a1f9226e
ssdeep: 768:OXhhTvmq76TK+dcarMDn0DwN3y5hkmp7X:ohbQtOarM70DwaN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright xa9 1985-2003 ancient JK Corporation
InternalName: Math-Game
FileVersion: 1.00
CompanyName: ancient JK
LegalTrademarks: Copyright protected.
Comments: A perfect game to improve your math skills, for kids as well as adults.
ProductName: Math-Game
ProductVersion: 1.00
OriginalFilename: Math-Game.exe

Adware.Bulz.5915 also known as:

K7AntiVirusTrojan-Downloader ( 0053bd761 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.452
CAT-QuickHealTrojan.SkeeyahMF.S3661235
ALYacGen:Variant.Adware.Bulz.5915
MalwarebytesMalware.AI.2085241701
AlibabaAdWare:Win32/DealPly.4a7e6120
K7GWTrojan-Downloader ( 0053bd761 )
Cybereasonmalicious.8c304e
CyrenW32/Trojan.GKM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Adload.NTX
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.drmxk
BitDefenderGen:Variant.Adware.Bulz.5915
NANO-AntivirusRiskware.Win32.DealPly.fhnjhm
MicroWorld-eScanGen:Variant.Adware.Bulz.5915
TencentWin32.Adware.Dealply.Pbyk
Ad-AwareGen:Variant.Adware.Bulz.5915
SophosGeneric PUA MM (PUA)
ComodoApplication.Win32.AdLoad.TU@7v70mx
BitDefenderThetaAI:Packer.645A3D4B21
McAfee-GW-EditionPUP-XGK-KB
FireEyeGeneric.mg.b136bc58c304e559
EmsisoftGen:Variant.Adware.Bulz.5915 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.jrbs
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Adware.Bulz.5915
AhnLab-V3Trojan/Win32.Skeeyah.R236985
McAfeePUP-XGK-KB
MAXmalware (ai score=99)
VBA32Adware.DealPly
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!UkB0BD4yebs
IkarusTrojan-Downloader.Win32.Adload
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealPly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Adware.Bulz.5915?

Adware.Bulz.5915 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment