Malware

Bulz.308465 removal

Malware Removal

The Bulz.308465 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.308465 virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Bulz.308465?


File Info:

crc32: 3AEE6D39
md5: f7d6a427bc5d8b42b300fbd2860a1ade
name: F7D6A427BC5D8B42B300FBD2860A1ADE.mlw
sha1: a04d956240cd795ceb71820e5f986784ef85715c
sha256: bdc8b504e3219edf13a3caa87b4746af659c40edb723d8986cbbd7cf4953ea98
sha512: f819158762a42f86e0a52c61afd558680565f2d9da2a48c195069fc2d9f67a7f1db46e10ab4c9ece3fea88f01f57d3f361ca5942ea64eb8f9fbf0f893c1573c3
ssdeep: 98304:eCd/pVQKbefjKLX0Rq+1wW2Bru1aaqfEeyiuWHalaLN6AOM1G4yX/PcA/UQ4ocE:7d/qfodr61OnBggXANKgpS032JH0S
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagude
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Bulz.308465 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.308465
FireEyeGeneric.mg.f7d6a427bc5d8b42
CAT-QuickHealTrojan.Agent
McAfeeArtemis!F7D6A427BC5D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Bulz.308465
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7bc5d8
CyrenW32/Trojan.BUIF-6743
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Eb.boo
AlibabaTrojan:Win32/Azorult.1e60704d
TencentWin32.Trojan.Eb.Efuk
Ad-AwareGen:Variant.Bulz.308465
EmsisoftGen:Variant.Bulz.308465 (B)
ComodoMalware@#1htlfx5k4ur8s
F-SecureHeuristic.HEUR/AGEN.1122056
TrendMicroTROJ_GEN.R06CC0DAI21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
SophosMal/Generic-S
IkarusTrojan.MalPack
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1122056
MAXmalware (ai score=89)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Bulz.D4B4F1
AegisLabHacktool.Win32.ArchSMS.lsIq
ZoneAlarmTrojan.Win32.Eb.boo
GDataGen:Variant.Bulz.308465
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4305263
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.@pKfayVoSJbG
ALYacGen:Variant.Bulz.308465
VBA32BScope.Trojan.Zenpack
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.NNPAFWX
TrendMicro-HouseCallTROJ_GEN.R06CC0DAI21
RisingTrojan.Kryptik!1.D106 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/HEUR/QVM11.1.A0DF.Malware.Gen

How to remove Bulz.308465?

Bulz.308465 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment