Malware

Bulz.177972 removal instruction

Malware Removal

The Bulz.177972 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.177972 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
theshadow.publicvm.com

How to determine Bulz.177972?


File Info:

crc32: E6CB23A5
md5: b1665a16ffe76b759da26180485d310d
name: B1665A16FFE76B759DA26180485D310D.mlw
sha1: 78a1e25c28f8dd17f6bc176bff8e4f4a941aacfe
sha256: 2160f3421843c9f8c521c55b36f95c08d024effeda06494bd88f5576a4848bd5
sha512: 5b1a62bc499aacc4edb1865911d25d8bd6f50de105fbbb4449c94110d75105fd6a170894115ead224861a093f9aac05f5dd6c1caefabc3a33f1b1b1b40f5cf91
ssdeep: 1536:L1xrmcmtR4SqBrg9mIWVCjBPSRcYaY+K6BUgXvrd4HV3VnB0My+ZzSi1RBBKgMR:L1xkhzENWiVFnT11vBKfRcXT5a1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: system.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: system
ProductVersion: 1.0.0.0
FileDescription: system
OriginalFilename: system.exe

Bulz.177972 also known as:

K7AntiVirusTrojan-Downloader ( 004c3e061 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.113
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.177972
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.68113
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/Kryptik.bd76eaaa
K7GWTrojan-Downloader ( 004c3e061 )
Cybereasonmalicious.6ffe76
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.OOP
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.MSIL.Agent.gen
BitDefenderGen:Variant.Bulz.177972
NANO-AntivirusTrojan.Win32.Kryptik.fhipnc
MicroWorld-eScanGen:Variant.Bulz.177972
TencentMsil.Backdoor.Agent.Pdby
Ad-AwareGen:Variant.Bulz.177972
SophosMal/Generic-R + Mal/FakeMS-S
BitDefenderThetaGen:NN.ZemsilF.34294.km0@aqzvTIe
McAfee-GW-EditionGenericRXFW-MG!B1665A16FFE7
FireEyeGeneric.mg.b1665a16ffe76b75
EmsisoftGen:Variant.Bulz.177972 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Generic.ASMalwS.27F87D0
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Bulz.D2B734
GDataGen:Variant.Bulz.177972
McAfeeGenericRXFW-MG!B1665A16FFE7
MAXmalware (ai score=100)
VBA32Trojan.MSIL.gen.a.10
MalwarebytesMalware.AI.372641279
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.CCRA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.177972?

Bulz.177972 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment