Malware

Bulz.347474 malicious file

Malware Removal

The Bulz.347474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.347474 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Bulz.347474?


File Info:

name: FB5766FBA6C19502E1FB.mlw
path: /opt/CAPEv2/storage/binaries/e16a983737db1a1d919139919dcc325f5ef2255408c5211a344ae8626091d504
crc32: 90B9C847
md5: fb5766fba6c19502e1fb86132164c07a
sha1: c8554dd3cb5e9df72bdbe7fb901467d3ce30c77d
sha256: e16a983737db1a1d919139919dcc325f5ef2255408c5211a344ae8626091d504
sha512: b2ddeb32b73e83d889616027f3b421261eb56725e2400a39342c89d52c0b57b7093a381a7a8e0429b0bdf569a18eb262e02c819c68142d0af752f348282eb88f
ssdeep: 49152:L1cPEd51u9c9Vj5bLOcdlMaaatajesmTE+xQ/2X3fMKc41nvr3we5Xe:Ld5xN5bCQlMakehE6a2HEI1vr3xd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10DD52316F324D846C109B63D4C91E7B8679ECFE03811B26061B1BE97BA31DE76E5E4C2
sha3_384: a66422a9a2d77b75922b436ecdc12d6bbe0740a1be9a18942cdcb223950631e33670c2a914b16e5960fe17d7a2bf3144
ep_bytes: e840b0ffff0000486561705265416c6c
timestamp: 2012-04-09 04:53:49

Version Info:

FileVersion: 1.0.0.0
FileDescription: 天龙专用登录器
ProductName: 天龙专用登录器
ProductVersion: 1.0.0.0
CompanyName: 天龙专用登录器
LegalCopyright: 天龙专用登录器 版权所有
Comments: 天龙专用登录器
Translation: 0x0804 0x04b0

Bulz.347474 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.StartPage1.16039
MicroWorld-eScanGen:Variant.Bulz.347474
FireEyeGeneric.mg.fb5766fba6c19502
VIPREGen:Variant.Bulz.347474
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0056626f1 )
K7GWUnwanted-Program ( 0056626f1 )
Cybereasonmalicious.3cb5e9
BitDefenderThetaGen:NN.ZexaF.36722.VA0@aSDdjZdb
CyrenW32/S-47c1ea66!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Packed.A potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Bulz.347474
AvastWin32:Evo-gen [Trj]
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Bulz.347474 (B)
GDataGen:Variant.Bulz.347474
MAXmalware (ai score=80)
Kingsoftmalware.kb.b.925
ArcabitTrojan.Bulz.D54D52
MicrosoftTrojan:Win32/Emotet!ml
GoogleDetected
ALYacGen:Variant.Bulz.347474
VBA32BScope.Trojan.Reconyc
Cylanceunsafe
RisingMalware.Undefined!8.C (TFE:5:Z6UeVAcTJhG)
YandexTrojan.GenAsa!Nqix1nLXlqU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Bulz.347474?

Bulz.347474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment