Adware

Adware.Bulz.7429 (file analysis)

Malware Removal

The Adware.Bulz.7429 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Bulz.7429 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Adware.Bulz.7429?


File Info:

name: 3C13B352D75675EE1327.mlw
path: /opt/CAPEv2/storage/binaries/22f1335c8eb5e94f6330d8fa681cab0ed7ee6fe3f2938dba500fe6f5983d693a
crc32: A2300898
md5: 3c13b352d75675ee132721be91c0d875
sha1: aeb08cb3958ada9e403647925ccbc79c932c3d86
sha256: 22f1335c8eb5e94f6330d8fa681cab0ed7ee6fe3f2938dba500fe6f5983d693a
sha512: c0ee29e70d5f4a58c234aab5e54fa79018b84aacf1798fc932b047bd9b9fc0e0b87e7e10045902d8a3b701eccfc333297528cedf71e6c9e2b07ae1f8d09ded11
ssdeep: 12288:ya5O/Zq9m+n6zMaaMhOzMwKnllS9U3erd2NMjHIQM:ya5OhB+faaMUzyG9U3MuMjHIQM
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1E4A401139B889FEAC04242381AA347F67872A18B5F50D203719DF23C3E6F2B54F2B595
sha3_384: 33bb8183fad31b4a3993ae8125ba71ebbcb5a05e3d6f7eef9437b10656864b219f8479b87c4a75b9071b14addb880d00
ep_bytes: e9b00f00000f98c54889d90f92c4488d
timestamp: 2017-12-09 06:13:06

Version Info:

0: [No Data]

Adware.Bulz.7429 also known as:

LionicRiskware.Win32.BitMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Bulz.7429
McAfeeW64/CoinMiner
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRiskWare:Win32/BitMiner.ead24d3c
Cybereasonmalicious.3958ad
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.EM
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7153852-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
BitDefenderGen:Variant.Adware.Bulz.7429
AvastWin32:XMRStakMiner-F [Trj]
Ad-AwareGen:Variant.Adware.Bulz.7429
SophosGeneric PUA KO (PUA)
ComodoApplicUnwnt@#2hier6rs329vz
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win64.VFlooder.gc
FireEyeGeneric.mg.3c13b352d75675ee
EmsisoftGen:Variant.Adware.Bulz.7429 (B)
IkarusPUA.CoinMiner
GDataWin32.Application.CoinMiner.BA
eGambitUnsafe.AI_Score_94%
AviraHEUR/AGEN.1123692
MAXmalware (ai score=64)
Antiy-AVLTrojan/Generic.ASMalwS.247070C
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Adware.Bulz.D1D05
CynetMalicious (score: 99)
ALYacGen:Variant.Adware.Bulz.7429
MalwarebytesMalware.AI.3199884431
APEXMalicious
RisingHackTool.CoinMiner!1.BEAB (CLASSIC)
YandexTrojan.GenAsa!4gdLUqsURhE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11502151.susgen
FortinetRiskware/BitMiner
AVGWin32:XMRStakMiner-F [Trj]

How to remove Adware.Bulz.7429?

Adware.Bulz.7429 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment