Malware

Bulz.3242 (file analysis)

Malware Removal

The Bulz.3242 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.3242 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Bulz.3242?


File Info:

crc32: AB10A0CA
md5: a672795bd94f8179275ce522aa66bd75
name: A672795BD94F8179275CE522AA66BD75.mlw
sha1: b3edfa834f9add8cf00ca3ad569778641a050648
sha256: 897f374bfddfc8bea799b5e24d9b96ed445af84eb2b7705a44c5b6f5cfa2bd4b
sha512: 126358bf1993faef76a8eae9f9a94514526a205a352adc2e8401919d0f0897cdc4a2850618a89f44dc5b7f0a3614823a24334775dd32b311d3be5074f3bc3208
ssdeep: 192:ZYBc0L/ynZCndHWoI+ETL/cDJ61q4lz9yo0ytnpPIo0IGfyz4Qpkn4pnju4jpWB:ZYiCynZCnObfsYlzKKn/0Xfyze+niFC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Epatage.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Epatage
ProductVersion: 1.0.0.0
FileDescription: Epatage
OriginalFilename: Epatage.exe

Bulz.3242 also known as:

K7AntiVirusTrojan ( 004d3df31 )
DrWebTrojan.PWS.Steam.15645
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.3242
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Filecoder.2e2df807
K7GWTrojan ( 004d3df31 )
Cybereasonmalicious.bd94f8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AC
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan-Ransom.MSIL.Generic
BitDefenderGen:Variant.Bulz.3242
NANO-AntivirusTrojan.Win32.Ransom.hoyqly
MicroWorld-eScanGen:Variant.Bulz.3242
TencentMsil.Trojan.Generic.Lmkg
Ad-AwareGen:Variant.Bulz.3242
SophosMal/Generic-S
ComodoMalware@#21yg8mvn0remt
BitDefenderThetaGen:NN.ZemsilF.34670.bm0@aOARr2b
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.a672795bd94f8179
EmsisoftGen:Variant.Bulz.3242 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.pyqg
WebrootW32.Trojan.MSIL
AviraHEUR/AGEN.1115170
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/AgentTesla!ml
AegisLabTrojan.MSIL.Generic.j!c
GDataGen:Variant.Bulz.3242
AhnLab-V3Trojan/Win32.RL_Generic.C3997092
McAfeeArtemis!A672795BD94F
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
RisingRansom.Generic!8.E315 (CLOUD)
YandexTrojan.Filecoder!5Yt1OSk0iwQ
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder.AC!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/Rootkit.Generic.HgIASOcA

How to remove Bulz.3242?

Bulz.3242 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment