Malware

What is “Bulz.351902”?

Malware Removal

The Bulz.351902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.351902 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.351902?


File Info:

crc32: 0BF8AABB
md5: 1cbbe85fc2beb34e2ed3ff87d7613fac
name: 1CBBE85FC2BEB34E2ED3FF87D7613FAC.mlw
sha1: e8eb33e8676d927eaea657884694faa05a91a728
sha256: 6e0f67620da1ee82c0cfc0c166f2a027fdd8af9c8f4622952b19bed41de60b7b
sha512: a5897b6fa3d856836a7e7fae73c5c5788e85bfc9c778ae4420f8ddcc951861cd81dcfdcbc3f7c2d58ccc50ffce4c13f9ecd2ee7f75337286f293d15a60654b0b
ssdeep: 12288:nzQle+KeFuR6A6myW55LpFB6gOp1ak3ogzPSqUq50K+08os2mWKk7esGaUpbBa9:oPuX6mj55LpUyqVKK+09s32T/aY9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015 Realtek Semiconductor Corp.
InternalName: RtlUpd
FileVersion: 3, 0, 0, 0
CompanyName: Realtek Semiconductor Corp.
Comments: Developed by Archeng
ProductName: Realtek HD Auido Update and remove driver Tool
ProductVersion: 3, 0, 0, 0
FileDescription: Driver Update and remove for Windows x64 or x86_32
OriginalFilename: RtlUpd.EXE
Translation: 0x0409 0x04b0

Bulz.351902 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject4.7789
MicroWorld-eScanGen:Variant.Bulz.351902
FireEyeGeneric.mg.1cbbe85fc2beb34e
Qihoo-360HEUR/QVM03.0.9617.Malware.Gen
ALYacGen:Variant.Bulz.351902
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f32301 )
BitDefenderGen:Variant.Bulz.351902
K7GWTrojan ( 004f32301 )
Cybereasonmalicious.8676d9
BitDefenderThetaGen:NN.ZemsilF.34590.Wm0@aGp!6Wci
CyrenW32/MSIL_RRat.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
Ad-AwareGen:Variant.Bulz.351902
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1138167
TrendMicroTROJ_GEN.R014C0WBR21
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Bulz.351902 (B)
IkarusTrojan.MSIL.EzirizNetReactor
AviraHEUR/AGEN.1138167
MicrosoftTrojan:Win32/Wacatac.D6!ml
ArcabitTrojan.Bulz.D55E9E
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataGen:Variant.Bulz.351902
CynetMalicious (score: 100)
McAfeeArtemis!1CBBE85FC2BE
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1197544150
ESET-NOD32a variant of MSIL/Packed.EzirizNetReactor.BI
TrendMicro-HouseCallTROJ_GEN.R014C0WBR21
TencentMsil.Backdoor.Androm.Ebrn
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Kryptik.YMN!tr
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Bulz.351902?

Bulz.351902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment