Malware

Bulz.193649 removal

Malware Removal

The Bulz.193649 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.193649 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
puffpuff421.top

How to determine Bulz.193649?


File Info:

crc32: B579FE2F
md5: 232d0e1d974efae19648aa54121fcbdc
name: 232D0E1D974EFAE19648AA54121FCBDC.mlw
sha1: a001508a5be5b5da6d78141c7b084bd2605c7ac4
sha256: 218333bd24c8318b23dd2c9579df008329219ef3841a9bcbc17b4a725c075cae
sha512: 8d7b07aa4ffc2bb596988fe8b70cea3ff3221429eebd1fb026b0fe5eb40b7791e64c1bc5f3e2c057cf348f6194068c294fbc78f7d8d64139add4ec9b4133b06d
ssdeep: 12288:9+wDf6zdizawMP9QZoFEIy0uHyp+/rSRyVR:9+wSzdIRMP9QZauHvjgyVR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0147 0x01ed

Bulz.193649 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.193649
FireEyeGeneric.mg.232d0e1d974efae1
McAfeeTrojan-FSUC!232D0E1D974E
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Bulz.193649
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a5be5b
CyrenW32/Kryptik.CGZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Generickdz-9789082-0
KasperskyHEUR:Trojan.Win32.Zenpak.vho
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareGen:Variant.Bulz.193649
EmsisoftGen:Variant.Bulz.193649 (B)
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zenpak.ebf
MicrosoftTrojan:Win32/EmotetCrypt.MS!MTB
ArcabitTrojan.Bulz.D2F471
ZoneAlarmHEUR:Trojan.Win32.Zenpak.vho
GDataGen:Variant.Bulz.193649
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R354833
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34634.BqW@aeSN10PG
ALYacGen:Variant.Bulz.193649
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HHHF
MAXmalware (ai score=80)
eGambitUnsafe.AI_Score_90%
FortinetW32/GenericKDZ.F7A5!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.4CD7.Malware.Gen

How to remove Bulz.193649?

Bulz.193649 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment