Malware

Bulz.348543 (B) removal guide

Malware Removal

The Bulz.348543 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.348543 (B) virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

How to determine Bulz.348543 (B)?


File Info:

crc32: BD8D007B
md5: 40ffe1d151f3906a436b7ead5ebac196
name: 40FFE1D151F3906A436B7EAD5EBAC196.mlw
sha1: e67692e36d8a165eedba3fcd821d9b909fa6c33a
sha256: 3a8e52b339c221a3aaf7be885774aa929020ae972fa89863721c3c8164b7906c
sha512: c0b4e01d77fce9046d4fcafce07f7cdf03070718d6bc9b20eb32584a937a05f64368bb06d8264dbbd88cab63e5bb8bcfb24271813cabf22e762ce3e00e6b33e7
ssdeep: 6144:ARK2IIXtxeG1A1iD+O4mjQwrUCOkp1qZv9cx6INNQR:ARKl8xrf+32RXTqJ9coqQR
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2019
InternalName: elm
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: elmDynamic Link Library
OLESelfRegister:
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: elm
OriginalFilename: nw_elfDLL.DLL
Translation: 0x0804 0x04b0

Bulz.348543 (B) also known as:

Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.348543
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Bulz.348543
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 90)
MicroWorld-eScanGen:Variant.Bulz.348543
Ad-AwareGen:Variant.Bulz.348543
SophosML/PE-A
BitDefenderThetaGen:NN.ZedlaF.34628.uG8@aWHgK0pj
McAfee-GW-EditionBehavesLike.Win32.Trojan.fh
FireEyeGeneric.mg.40ffe1d151f3906a
EmsisoftGen:Variant.Bulz.348543 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D5517F
AegisLabTrojan.Win32.Bulz.4!c
GDataGen:Variant.Bulz.348543
McAfeeGenericRXAA-AA!40FFE1D151F3
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1181356710
TrendMicro-HouseCallTROJ_GEN.R002H09CM21
IkarusTrojan.Win32.Farfli
Qihoo-360Win32/Trojan.Generic.HgkASQ8A

How to remove Bulz.348543 (B)?

Bulz.348543 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment