Malware

Bulz.278905 (file analysis)

Malware Removal

The Bulz.278905 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.278905 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Bulz.278905?


File Info:

name: 42A5E9725ADBFEBEF46D.mlw
path: /opt/CAPEv2/storage/binaries/d96803b26f646aa066d90d8eef0676980adc2b45d0c3ca66bf7ff710e9f042ad
crc32: 798A37F7
md5: 42a5e9725adbfebef46dfbc96db37742
sha1: b15fe143b4a665e4d402779d7593eb21bc43a7f7
sha256: d96803b26f646aa066d90d8eef0676980adc2b45d0c3ca66bf7ff710e9f042ad
sha512: 0162e9df202cdd6a972083bab7de672526e3ccdfe64f01d40a80c81e1552e3d561eaf401f48c66dca6c431fe42406f8e12d5f044ea753f502ef5ddbcf54eaa3b
ssdeep: 12288:ikyfILQQZbccjrQrmUuO34x+kSsoKQRu6KFjew8prKxElw/fjCFdV:iJX6JjrP7Oox+kSsU5CRCFdV
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18265761AD198ED02FB34953B0B5F36AE9B68D3CBCD00442A7D8CA537EF33151945B29A
sha3_384: a6a8fc6ec7d1b7ea7a940dde43c6c64bc39bdfa2a4859a28873aa632fcee95687c8a1ca81538f571f293b626c3095be9
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2011-10-09 03:43:36

Version Info:

FileVersion: 1.0.0.0
FileDescription: Www.018it.Com
ProductName: Www.018it.Com
ProductVersion: 1.0.0.0
CompanyName: 尊少
LegalCopyright: Www.018it.Com
Comments: Www.018it.Com
Translation: 0x0804 0x04b0

Bulz.278905 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwgJ
AVGWin32:Malware-gen
ElasticWindows.Generic.Threat
MicroWorld-eScanGen:Variant.Bulz.278905
FireEyeGeneric.mg.42a5e9725adbfebe
SkyhighBehavesLike.Win32.Generic.th
McAfeePUP-XAG-TR
Cylanceunsafe
SangforRiskware.Win32.Imestartup.Vuyu
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaRiskWare:Win32/IMEStartup.64ccc769
K7GWPassword-Stealer ( 004c2be91 )
K7AntiVirusPassword-Stealer ( 004c2be91 )
BitDefenderThetaGen:NN.ZedlaF.36802.Cv8@aylXWQbb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.QQTen.NAN
CynetMalicious (score: 100)
ClamAVWin.Trojan.Blackhole-9949082-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.IMEStartup.gen
BitDefenderGen:Variant.Bulz.278905
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.140455b2
EmsisoftGen:Variant.Bulz.278905 (B)
VIPREGen:Variant.Bulz.278905
TrendMicroTROJ_GEN.R002C0PC424
SophosMal/Generic-S
IkarusTrojan.Win32.Sasfis
VaristW32/Trojan.ISO.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumTrojWare.Win32.Zusy.172@4r3412
ArcabitTrojan.Bulz.D44179
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.IMEStartup.gen
GDataWin32.Trojan.PSE.15IBL0F
GoogleDetected
VBA32HackTool.Sniffer.WpePro
ALYacGen:Variant.Bulz.278905
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0PC424
RisingTrojan.Generic@AI.100 (RDML:cNy1ZZtVRlbp06aUBm7eqw)
YandexBackdoor.BlackHole!DtxDP+LjDSI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.FYCN!tr
DeepInstinctMALICIOUS

How to remove Bulz.278905?

Bulz.278905 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment