Malware

Bulz.350872 removal tips

Malware Removal

The Bulz.350872 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.350872 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Bulz.350872?


File Info:

name: 90754472A3E68828FC90.mlw
path: /opt/CAPEv2/storage/binaries/579aac0f5ac4b97e09d6c7deefe271f5248e56ab870e6e338772046114ca40ac
crc32: E83D7AFD
md5: 90754472a3e68828fc903d6a0546820a
sha1: 815919f9cfde180349841e23597b15f2a1b0573c
sha256: 579aac0f5ac4b97e09d6c7deefe271f5248e56ab870e6e338772046114ca40ac
sha512: da0fa50cdce8834d4e1994cdd864ce2da154201a4e407845a125ea9c3d8f7aef3a3d553cbc6cc3f13a02790be1fd88b703cd1405deffbdd0caaab1978c3f7a4f
ssdeep: 98304:AV8rEYkt2MQBsbl3bSt6fLQj8rGFExU+TNK4g9lnt2F/tnS9PXDozuTgszDKqF+P:AirEfvQWDbS+jg93PzpO6BZjeK+E4Z6w
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE260273A6440CACFFF65230F4E5BE6CD3F5368271A99C1E299D2C4462B0A48B67458F
sha3_384: 9780a1702a0ec45205d274448025161dd62f9b1e79b41e51b59c82e2bc1de98bc47b75858506ce08ee2cd16a60c98fe0
ep_bytes: 6854a94200e8eeffffff000048000000
timestamp: 2016-12-29 00:49:03

Version Info:

Translation: 0x0409 0x04b0
CompanyName: lastax90
ProductName: lastax90
FileVersion: 1.00
ProductVersion: 1.00
InternalName: lastax90
OriginalFilename: lastax90.exe

Bulz.350872 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.VbCrypt.89
MicroWorld-eScanGen:Variant.Bulz.350872
FireEyeGeneric.mg.90754472a3e68828
ALYacGen:Variant.Bulz.350872
CylanceUnsafe
ZillyaBackdoor.Xtreme.Win32.16690
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 000645cb1 )
AlibabaBackdoor:Win32/Xtreme.bf471b2f
K7GWRiskware ( 000645cb1 )
Cybereasonmalicious.2a3e68
BitDefenderThetaGen:NN.ZemsilF.34294.@p0@aq7vRol
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.VBCrypt.B
TrendMicro-HouseCallTROJ_GEN.R002C0WIG21
Paloaltogeneric.ml
ClamAVWin.Packed.Bladabindi-6848156-0
KasperskyBackdoor.Win32.Xtreme.azno
BitDefenderGen:Variant.Bulz.350872
NANO-AntivirusTrojan.Win32.Xtreme.ekejzg
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Bulz.350872
SophosMal/Generic-S
ComodoMalware@#iq22tst8kiud
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WIG21
McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
EmsisoftGen:Variant.Bulz.350872 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Bulz.350872
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.1DB8021
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Bulz.D55A98
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!90754472A3E6
VBA32Malware-Cryptor.VB.gen.2
APEXMalicious
TencentWin32.Backdoor.Xtreme.Hrer
YandexTrojan.GenAsa!Ab1rbPfjmso
IkarusTrojan.MSIL.Injector
eGambitUnsafe.AI_Score_99%
FortinetRiskware/VBCrypt
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.350872?

Bulz.350872 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment