Malware

Bulz.281856 malicious file

Malware Removal

The Bulz.281856 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.281856 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

How to determine Bulz.281856?


File Info:

crc32: F29C3639
md5: a55554e50125ebf0cc5538695da7d8c8
name: A55554E50125EBF0CC5538695DA7D8C8.mlw
sha1: 4e82b949f238f461874c5e420cbde3b1bc51b54f
sha256: 5ca9d8e4b9f2a19b6443bc6be26ba180bfc79d767b3e4033fa6757efe3ba8e48
sha512: 7f2d023c17574ee335eb24a4e5798de5d55e3c39cb465b520e28966d6a47407e1ad392398d3f01631c296747d7bca79862c846c27837066966c7b1774b4bf2fa
ssdeep: 196608:Fq4+Pc14BLg1m0pGpNxw2pmlsUCcIOVscBHBUq2corUNgZTnS81+q2kyz:FwcOkop46mPHodUNmnS81+qS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.0.0.2
CompanyName: Gbsoft Corporation
Comments: This installation was built with Inno Setup.
ProductName: Ideo Converter 6.2.0.7271
ProductVersion: 1.0.0.2
FileDescription: Ideo Converter
Translation: 0x0000 0x04b0

Bulz.281856 also known as:

K7AntiVirusTrojan ( 005722f11 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1661
ALYacGen:Variant.Bulz.281856
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.50f404b1
K7GWTrojan ( 005722f11 )
Cybereasonmalicious.50125e
CyrenW32/Trojan.WVJS-8389
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyTrojan.Win32.Ekstak.ahtkm
BitDefenderGen:Variant.Bulz.281856
MicroWorld-eScanGen:Variant.Bulz.281856
TencentWin32.Trojan.Ekstak.Llgv
Ad-AwareGen:Variant.Bulz.281856
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGen:Variant.Bulz.281856
EmsisoftGen:Variant.Bulz.281856 (B)
JiangminTrojan.Ekstak.boaz
AviraTR/Drop.Agent.erhjs
MicrosoftTrojan:Win32/Tiggre!rfn
GDataGen:Variant.Bulz.281856
AhnLab-V3PUP/Win32.DownloadAssistant.R360466
McAfeeArtemis!A55554E50125
MAXmalware (ai score=88)
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.111377413.susgen
FortinetRiskware/Ekstak
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Bulz.281856?

Bulz.281856 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment