Malware

Should I remove “Bulz.164648”?

Malware Removal

The Bulz.164648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.164648 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
clayroot2016.linkpc.net

How to determine Bulz.164648?


File Info:

crc32: E031F31B
md5: fc73fd996ef3b665fb9aab971de920df
name: FC73FD996EF3B665FB9AAB971DE920DF.mlw
sha1: 78dd72a9982c2adf0c862268fdf1ec45ecea2ee2
sha256: db107694378358951d9f9c5b4bfe99761ef778f63531a10ee2fd4607e79d0c5e
sha512: 930f5c50b320baed4c8e5f34891de120aa997f90dedcdaa64ab1ae37c53c759a525f64bcff63fe7c01747818becfcc43cac480ec45d9402bbd18faeead4989b6
ssdeep: 384:4NVjYTDG8gpk2u5n3XAxvZ9q9vDNEnxcoN1x:4PSxHnAXWvhSL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ClientRVDNS.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: ClientRVDNS.exe

Bulz.164648 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.164648
FireEyeGeneric.mg.fc73fd996ef3b665
ALYacGen:Variant.Bulz.164648
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Bulz.164648
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34634.am0@aSv5zTk
CyrenW32/Revetrat.A.gen!Eldorado
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Packed.Razy-9645384-0
KasperskyHEUR:Backdoor.MSIL.Revenge.gen
RisingBackdoor.Revetrat!1.C8D4 (CLASSIC)
Ad-AwareGen:Variant.Bulz.164648
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Siggen2.38271
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionGenericRXKA-TT!FC73FD996EF3
EmsisoftGen:Variant.Bulz.164648 (B)
IkarusTrojan.MSIL.Agent
AviraTR/ATRAPS.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.RRAT
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Bulz.D28328
AhnLab-V3Trojan/Win32.RL_Generic.C3517676
ZoneAlarmHEUR:Backdoor.MSIL.Revenge.gen
GDataGen:Variant.Bulz.164648
CynetMalicious (score: 100)
ESET-NOD32a variant of MSIL/Agent.ATK
McAfeeGenericRXKA-TT!FC73FD996EF3
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.LimeRat
ZonerTrojan.Win32.86676
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.ATK!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.9982c2

How to remove Bulz.164648?

Bulz.164648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment