Malware

Bulz.316528 information

Malware Removal

The Bulz.316528 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.316528 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Bulz.316528?


File Info:

name: A5001DA0744FF19341D9.mlw
path: /opt/CAPEv2/storage/binaries/bdeb3277b5d2a203587db8a6551f58952d9dd57d4f52607e717e94889120608a
crc32: 72006A31
md5: a5001da0744ff19341d9df974100aa1d
sha1: 0df116bfe8e02bf4370ad9faef56b29e2b1114d0
sha256: bdeb3277b5d2a203587db8a6551f58952d9dd57d4f52607e717e94889120608a
sha512: e41a0008bd652ec4150ce4d0b2161814cedefbfacc48ccbaa1ad6ce54dbaa29f92db64db6f9b897218cbfa4e2b698eafac5988f76b972b46cc3439b7b9f90ca5
ssdeep: 1536:NQpQ5EP0ijnRTXJ3m7KDWutBEJzt3u42zdUk0+Bj8QL:NQIURTXJ2eDWoG448dUr+Bj8q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C63E15B31C588B7F9A616705A6B8777E3BBB7042762510B2B244FBF36221C38935283
sha3_384: a4a7517c8e595972bcd43b0d192b8ed5e9c68440443441e56177190a4550207e5a20a2ffbe21024bd7fb1fca7c1554b2
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Bulz.316528 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Bulz.316528
FireEyeGen:Variant.Bulz.316528
McAfeeArtemis!A5001DA0744F
CylanceUnsafe
ZillyaTrojan.Scar.Win32.104304
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/EncPk.6cc5e0eb
Cybereasonmalicious.0744ff
BitDefenderThetaGen:NN.ZexaF.34182.cmW@aC3Durm
CyrenW32/Zbot.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.BNJGUEZ
TrendMicro-HouseCallTROJ_GEN.R002C0PA822
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.316528
NANO-AntivirusTrojan.Win32.Scar.cfhsrw
APEXMalicious
TencentWin32.Trojan.Generik.Ljjk
SophosMal/EncPk-ACO
ComodoMalware@#274h13jrf6bj4
DrWebTrojan.MulDrop7.36803
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PA822
McAfee-GW-EditionGenericRXFQ-IN!B62D87A029B0
EmsisoftGen:Variant.Bulz.316528 (B)
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3517056
KingsoftWin32.Troj.Scar.hr.(kcloud)
MicrosoftTrojan:Win32/Occamy.CBD
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.316528
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.C2912722
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Bulz.316528
AvastWin32:Malware-gen
RisingPUA.Presenoker!8.F608 (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Scar.HRGL!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.316528?

Bulz.316528 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment