Malware

Bulz.184887 (file analysis)

Malware Removal

The Bulz.184887 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.184887 virus can do?

  • The executable is likely packed with VMProtect

How to determine Bulz.184887?


File Info:

crc32: 12C642BB
md5: 06e1ca5423361fdd630d8ef2383e581a
name: 06E1CA5423361FDD630D8EF2383E581A.mlw
sha1: 0fe47ae2cc5da3c9beea485902cc2522c4832dc1
sha256: 6cca341921b136ab86f45568c0315fee7a1bbad7eeb49b3d602dfb90aa707f2d
sha512: 0a2b1889635ea999defb71013f0407f1eef1c253800d69bcdc746d6fc5675cf1a694165168da0c365d3b7fff9ae3213bc21a42935dedb6f4139a8755ace83eff
ssdeep: 12288:tX9WCPkIAsWPIkcuniocuniXNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNS:tNWCRBWO3Fg6a1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: MH - LOADER.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: MH - LOADER
ProductVersion: 1.0.0.0
FileDescription: MH - LOADER
OriginalFilename: MH - LOADER.exe

Bulz.184887 also known as:

K7AntiVirusTrojan ( 7000001c1 )
LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.184887
CylanceUnsafe
SangforVirus.Win32.Save.a
AlibabaTrojan:MSIL/VMProtBad.d8ef4827
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.423361
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.B
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
BitDefenderGen:Variant.Bulz.184887
MicroWorld-eScanGen:Variant.Bulz.184887
Ad-AwareGen:Variant.Bulz.184887
SophosMal/Generic-R + Mal/VMProtBad-A
BitDefenderThetaGen:NN.ZemsilF.34236.!u1@aixqlLb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.06e1ca5423361fdd
EmsisoftGen:Variant.Bulz.184887 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Tnega!ml
GDataGen:Variant.Bulz.184887
AhnLab-V3Malware/Win32.RL_Generic.C4263117
McAfeeArtemis!06E1CA542336
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
PandaTrj/Orbond.A
IkarusTrojan.MSIL.Vmprotect
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/VMProtBad.A!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Bulz.184887?

Bulz.184887 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment