Malware

Should I remove “Bulz.334502”?

Malware Removal

The Bulz.334502 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.334502 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Bulz.334502?


File Info:

name: E7E2E8D591F855EF8562.mlw
path: /opt/CAPEv2/storage/binaries/8fe730cb781ca625135354d4ad9236b28836c5dbf60390a2196dc25e517665ab
crc32: F10D28C8
md5: e7e2e8d591f855ef8562203453c59968
sha1: 0018ca87f17bf5dc51eeeb19bf2b099d9abab356
sha256: 8fe730cb781ca625135354d4ad9236b28836c5dbf60390a2196dc25e517665ab
sha512: ffa078ade05511af227d7803c5c36bf80877362acae93c7c781aa172c90a80fcbc5456759a44e9a4aa54db300865caf2a7f2944ee3babe7d51d41a256056add3
ssdeep: 98304:B9fRYjM8BDLEujA8B3rqo51pk1JgKBFSC+p/v8rgzXnr/7:ffRYDA0A8B37pUFChUr67/7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3062201B8E42691D10806332FA7BB3250573FA42B76DD2EEB5DBAE276F2A414D1F345
sha3_384: 681da2e71e32b2cea0201fa4bc9b7ccb7e562a12dbe6243c2f23faf6ce0401fb7fd29c6713e10794d1a93c6ff91231fe
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:52

Version Info:

Comments: 页游大厅 v4.8
CompanyName: 凡游网络
FileDescription: 页游大厅 v4.8 安装程序
FileVersion: 4.8.1.1619
LegalCopyright: 版权所有 (C)2013 凡游网络
PrivateBuild: 11:30:52
ProductName: 页游大厅
ProductVersion: 4.8.1.1619
SpecialBuild: 100001
Translation: 0x0804 0x03a8

Bulz.334502 also known as:

LionicRiskware.Win32.Agent.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.334502
FireEyeGen:Variant.Bulz.334502
ALYacGen:Variant.Bulz.334502
CylanceUnsafe
SangforPUP.Win32.Agent.gen
CrowdStrikewin/grayware_confidence_90% (W)
AlibabaDownloader:Win32/Kuaiba.1e4e67d9
K7GWAdware ( 005624dd1 )
K7AntiVirusAdware ( 005624dd1 )
ArcabitTrojan.Bulz.D51AA6
CyrenW32/Kuaiba.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Kuaiba.L
APEXMalicious
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Bulz.334502
AvastWin32:Malware-gen
RisingPUA.Kuaiba!8.F612 (CLOUD)
Ad-AwareGen:Variant.Bulz.334502
EmsisoftGen:Variant.Bulz.334502 (B)
TrendMicroTROJ_GEN.R002C0PB122
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.wc
SophosGeneric PUA AA (PUA)
MAXmalware (ai score=85)
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
MicrosoftPUAAdvertising:Win32/Kuaiba
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Agent.gen
GDataGen:Variant.Bulz.334502
McAfeeArtemis!E7E2E8D591F8
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.3429950463
TrendMicro-HouseCallTROJ_GEN.R002C0PB122
TencentWin32.Adware.Kuaiba.Anfm
SentinelOneStatic AI – Suspicious PE
FortinetAdware/Kuaiba.L
AVGWin32:Malware-gen
Cybereasonmalicious.591f85
PandaTrj/CI.A

How to remove Bulz.334502?

Bulz.334502 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment