Malware

Bulz.215042 removal

Malware Removal

The Bulz.215042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.215042 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Bulz.215042?


File Info:

name: C156E26A1AD47B024519.mlw
path: /opt/CAPEv2/storage/binaries/1b3834ad0b08683a388fc98aa3507d80a5d16f80023846c80da3db51e84f94ba
crc32: 7D8026AB
md5: c156e26a1ad47b02451926327c17abff
sha1: 2d3ee93beab918f930af32dc74d240fbad49a171
sha256: 1b3834ad0b08683a388fc98aa3507d80a5d16f80023846c80da3db51e84f94ba
sha512: 6f5da124a67beddc1112867b313bee2a113172b101d7d1ed52e2bb4d1c20589966287fa67faa990903517f168fa8e7542237327acce12e3e82a3fc3b87d12be2
ssdeep: 49152:FS23ZfEvE048wuusuxLOoNjlAKZUhdbrRL5d47+Z8ipDI1quAb7/i:FS23ZfES8wC85AKZKFrXlz/i
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DB266C40F9DB44F5EB0B653085A7923F6730660A8336CBD7CA442F97F85BAD21933266
sha3_384: 11dde3e1b76606a87917902c531a50cc1b04092f884772a0ac89c52848d847fd4bc630dcfe36869af0aaccefecc10234
ep_bytes: e91bd9ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Bulz.215042 also known as:

LionicTrojan.Win32.Convagent.b!c
MicroWorld-eScanGen:Variant.Bulz.215042
ALYacGen:Variant.Bulz.215042
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005600971 )
AlibabaBackdoor:Win32/Windigo.dce36fb2
K7GWTrojan ( 005600971 )
Cybereasonmalicious.a1ad47
Elasticmalicious (high confidence)
ESET-NOD32a variant of WinGo/RanumBot.AN
APEXMalicious
KasperskyBackdoor.Win32.Windigo.bq
BitDefenderGen:Variant.Bulz.215042
NANO-AntivirusTrojan.Win32.SpyBot.haslts
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Windigo.Svqs
Ad-AwareGen:Variant.Bulz.215042
EmsisoftGen:Variant.Bulz.215042 (B)
DrWebTrojan.SpyBot.931
ZillyaTrojan.RanumBot.Win32.389
McAfee-GW-EditionBehavesLike.Win32.TrojanVeil.rh
FireEyeGen:Variant.Bulz.215042
SophosMal/Generic-S
IkarusTrojan.WinGo.Ranumbot
GDataGen:Variant.Bulz.215042
JiangminTrojan.Poebot.e
AviraTR/ATRAPS.Gen
ArcabitTrojan.Bulz.D34802
ViRobotTrojan.Win32.Z.Spybot.4574208
ZoneAlarmBackdoor.Win32.Windigo.bq
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C3155694
MAXmalware (ai score=89)
VBA32Trojan.SpyBot
TrendMicro-HouseCallTROJ_GEN.R002H0CF622
RisingTrojan.Generic@AI.100 (RDML:MLS+bYDSGs9RijcdaP6r7g)
YandexRiskware.NetTool!/xcnET2WDLs
SentinelOneStatic AI – Malicious PE
FortinetW32/RanumBot.AN!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.215042?

Bulz.215042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment