Malware

About “Bulz.103656” infection

Malware Removal

The Bulz.103656 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.103656 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

Related domains:

dnsqa-m03.c644a3e76e438794c399ea1ccdb9206b.me

How to determine Bulz.103656?


File Info:

crc32: 770ED894
md5: 78ba83f913ed708ddb7d76456e4cd5a9
name: 78BA83F913ED708DDB7D76456E4CD5A9.mlw
sha1: baf0c3c63405ac496065f4c2de877f8023c398f9
sha256: 1e47722cd54d88a25a9910f04d43fdf35d07a85820f6ccad2a6f62f612479a88
sha512: 152a2cbae30bea491ce67f5f531d8416ce34e82a4e5d774805a1c1e87c298ba07f6bf5d26e9a1915bf0aa6f713dcca0b5b8ee87e7877e36de867e0107806907a
ssdeep: 24576:CQi0PlIyQ2S3ZjULi71qg/MBTlP0QjcpMXVJoT:C9EmLJjlGpf8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: NitS8DxasEOr
ProductVersion: 1.4
FileDescription: NitS8DxasEOr Setup
Translation: 0x0000 0x04b0

Bulz.103656 also known as:

K7AntiVirusAdware ( 0054654b1 )
LionicAdware.Win32.CloudScout.2!c
DrWebTrojan.Siggen7.34130
CynetMalicious (score: 99)
ALYacTrojan.Agent.CSCN
CylanceUnsafe
ZillyaAdware.CloudScout.Win32.612
SangforSuspicious.Win32.Evo.gen
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/CloudScout.0447ec46
K7GWAdware ( 0054654b1 )
Cybereasonmalicious.913ed7
SymantecPUA.Gen.2
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:AdWare.Win32.CloudScout.fcn
BitDefenderGen:Variant.Bulz.103656
NANO-AntivirusTrojan.Win32.CloudGuard.ewrqtm
MicroWorld-eScanGen:Variant.Bulz.103656
TencentWin32.Adware.Cloudscout.Ajvu
SophosGeneric Reputation PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34266.tn0@a8wBJud
VIPRECloudScout
McAfee-GW-EditionBehavesLike.Win32.PUPInstaller.cc
FireEyeGen:Variant.Bulz.103656
EmsisoftGen:Variant.Bulz.103656 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1124694
MicrosoftTrojan:Win32/Occamy.C
GDataTrojan.Agent.CSCN
McAfeeArtemis!78BA83F913ED
MAXmalware (ai score=97)
VBA32Adware.CloudScout
MalwarebytesAdware.DNSUnlocker.Generic
PandaTrj/CI.A
YandexPUA.CloudGuard!k+U6fzp4lKc
FortinetMSIL/CloudGuard.D
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Bulz.103656?

Bulz.103656 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment