Malware

Bulz.183170 removal guide

Malware Removal

The Bulz.183170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.183170 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.183170?


File Info:

name: 41229A1D0790ACA66B34.mlw
path: /opt/CAPEv2/storage/binaries/5e378d3e590263b9f1e3d4683406d59968fb24aef883c3dd9be637ae28ab509d
crc32: 92BF6311
md5: 41229a1d0790aca66b34607f4cf0771b
sha1: 003704e131abfab7dcfb07759f14a4a40917b219
sha256: 5e378d3e590263b9f1e3d4683406d59968fb24aef883c3dd9be637ae28ab509d
sha512: 03a23449249a8cdd4d5c722ab8ae84ce834431c307c3a739496d65bcc71790d50090cea49b4953b76e12b88769cc7f9a6bec1df8fe2371564d6bfc8315fd759e
ssdeep: 6144:stn81yUh+s0rnW6uWz6g5dED5igANwfSA6EntdXWgdcA:m8cS5gnGz/x+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F647C2532A20863C4AD3BF09973D240A77BAE95452F73CA7EE7D5C225E4B8C4811F97
sha3_384: 67443bfe6c25d23db780fe045794f069d99bfdba4492e80f7138b8ab0d2fac25ea8911c00fa36d2cc844f623e5440eea
ep_bytes: ff2504424100cccc033002000c000000
timestamp: 2019-03-09 11:28:28

Version Info:

CompanyName: TeAM SolidSQUAD-SSQ
LegalCopyright: TeAM SolidSQUAD-SSQ
LegalTrademarks: TeAM SolidSQUAD-SSQ
ProductName: SolidWorks 2019 Activator
ProductVersion: 2019.2
Comments:
FileDescription:
FileVersion: 27.2.0.51
InternalName:
OriginalFilename:
Translation: 0x0409 0x04e4

Bulz.183170 also known as:

LionicTrojan.MSIL.Miner.4!c
MicroWorld-eScanGen:Variant.Bulz.183170
FireEyeGeneric.mg.41229a1d0790aca6
CAT-QuickHealTrojan.ZpevdoFC.S7082207
ALYacGen:Variant.Bulz.183170
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:MSIL/Miner.10ac0fb4
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d0790a
Elasticmalicious (high confidence)
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Bulz.183170
SUPERAntiSpywareTrojan.Agent/Gen-Bulz
Ad-AwareGen:Variant.Bulz.183170
EmsisoftGen:Variant.Bulz.183170 (B)
ComodoMalware@#v6pckcxelase
ZillyaTrojan.Miner.Win32.15210
TrendMicroTROJ_GEN.R002C0CLL21
McAfee-GW-EditionBehavesLike.Win32.Worm.fh
IkarusTrojan.Win32.Tiggre
GDataGen:Variant.Bulz.183170
JiangminTrojan.MSIL.alpxg
WebrootW32.Malware.Gen
ArcabitTrojan.Bulz.D2CB82
MicrosoftTrojan:Win32/Tiggre!plock
McAfeeGenericRXGX-XR!41229A1D0790
VBA32TScope.Trojan.MSIL
MalwarebytesRiskWare.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0CLL21
MaxSecureTrojan.Malware.74324777.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34712.tu0@aOEwD7ii
PandaTrj/GdSda.A

How to remove Bulz.183170?

Bulz.183170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment