Malware

Bulz.371534 (file analysis)

Malware Removal

The Bulz.371534 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.371534 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.371534?


File Info:

name: C3F176FE065D9ABDEF7B.mlw
path: /opt/CAPEv2/storage/binaries/079aec31a546d43ef203911130bf5d8fc622c046612c02d33eb50c010a935d04
crc32: AC68C7BD
md5: c3f176fe065d9abdef7bbe46e0b9f33c
sha1: 28ef25c04ecff71cf946ddf103824f9d3b7b610b
sha256: 079aec31a546d43ef203911130bf5d8fc622c046612c02d33eb50c010a935d04
sha512: 0407460ba328bf356d7135e34d74d7fa07082a71870781607f1734ca95b0ef740cc776cf54d6e70ff38b093a3aa1d91eb00d647e377af12d669ad4e0f4377252
ssdeep: 768:unDFbqG6Q1jfLRY5Gjrh+i/WMLUQmAFUAWys5IhNJvoxZQsNKjnb6h:sR1jfLRYIrhbWVG2ys5Ihb68nb6h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153636D0A77E09672E9BB4B722DB383C06561BC545F2A871B361C322D3C37B815D7AB19
sha3_384: 781020ad81eab1edfbf8cc2b23296805124ae23258d07940a63cb7f590025e74b315170049f0af0b61d261c99e073c47
ep_bytes: 6804184000e8f0ffffff000000000000
timestamp: 2003-11-19 14:48:18

Version Info:

Translation: 0x0409 0x04b0
Comments: Self Extracting Help Installer for Creeps 2.2.10
CompanyName: Erik Hepsø
FileDescription: Help for Creeps 2.2.10 rev.1
LegalCopyright: Erik Hepsø © 2001
ProductName: Creeps Help
FileVersion: 2.02.0011
ProductVersion: 2.02.0011
InternalName: selfexe
OriginalFilename: selfexe.exe

Bulz.371534 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Bulz.371534
FireEyeGeneric.mg.c3f176fe065d9abd
ALYacGen:Variant.Bulz.371534
CylanceUnsafe
VIPREGen:Variant.Bulz.371534
BitDefenderGen:Variant.Bulz.371534
Cybereasonmalicious.e065d9
tehtrisGeneric.Malware
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.59806c1e
RisingDropper.Generic!8.35E (CLOUD)
Ad-AwareGen:Variant.Bulz.371534
ZillyaTrojan.Generic.Win32.135773
McAfee-GW-EditionBehavesLike.Win32.Trojan.km
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Variant.Bulz.371534 (B)
APEXMalicious
GDataGen:Variant.Bulz.371534
JiangminTrojan.Generic.gtwci
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Bulz.D5AB4E
MicrosoftTrojan:Win32/GandCrypt.PVB!MTB
CynetMalicious (score: 99)
Acronissuspicious
McAfeeArtemis!C3F176FE065D
MAXmalware (ai score=81)
TencentWin32.Trojan.Generic.Taer
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.371534?

Bulz.371534 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment