Malware

Bulz.394615 removal instruction

Malware Removal

The Bulz.394615 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.394615 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (11 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
s2lol.com
www.s2lol.com
dl.volamthoidai.com
www.google-analytics.com
static.adtimaserver.vn
adtima-static.zascdn.me
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org
edgedl.me.gvt1.com

How to determine Bulz.394615?


File Info:

crc32: 63CA40CB
md5: efdac981641bca8effa4fcf95545d987
name: EFDAC981641BCA8EFFA4FCF95545D987.mlw
sha1: b73a8d0de365858a157afbad122084c28993be23
sha256: e800f75cc27d0e8941f0909ae1d78cf6ce881c46a581ba98882a83612c2f5a05
sha512: c4efbefca36b255de53279e26056268242ee7372b76fe44226779921c4d3e9460d634eabcda13670de645cf12ee97a2633106f24b4bf5eba9765290a6e163c5a
ssdeep: 24576:BtbW/bWKH0WLXmul1/eBRkZCCV09+Ck/1aPdEbi:26k0Xul1WBR59gNaPdb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 PkVoLam1.Net 2021
Assembly Version: 1.0.0.0
InternalName: AutoUpdate.exe
FileVersion: 1.0.0.0
CompanyName: PkVoLam1.Net
LegalTrademarks: AutoUpdate Pro
Comments: AutoUpdate Pro
ProductName: PkVoLam1.Net
ProductVersion: 1.0.0.0
FileDescription: AutoUpdate Pro
OriginalFilename: AutoUpdate.exe

Bulz.394615 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Bulz.394615
SangforTrojan.Win32.Sabsik.TE
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.1641bc
CyrenW32/MSIL_Kryptik.DDH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Trojan.Generic-9801687-0
BitDefenderGen:Variant.Bulz.394615
MicroWorld-eScanGen:Variant.Bulz.394615
Ad-AwareGen:Variant.Bulz.394615
BitDefenderThetaGen:NN.ZemsilF.34088.6m0@amy4eBo
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Bulz.394615
EmsisoftGen:Variant.Bulz.394615 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1137947
Antiy-AVLTrojan/Generic.ASMalwS.3466C59
MicrosoftRansom:Win32/Hermes
GDataGen:Variant.Bulz.394615
AhnLab-V3Ransomware/Win.Hermes.C4567031
McAfeeArtemis!EFDAC981641B
MAXmalware (ai score=99)
MalwarebytesMalware.AI.71443216
TrendMicro-HouseCallTROJ_GEN.R002H0CHK21
IkarusTrojan-PWS.Win32.OnLineGames
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Bulz.394615?

Bulz.394615 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment