Malware

Bulz.416501 removal tips

Malware Removal

The Bulz.416501 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.416501 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Bulz.416501?


File Info:

name: 906A30920714850DD358.mlw
path: /opt/CAPEv2/storage/binaries/1836d30c8e3259faa1bb21abb9dc8a0c2bc7e4b927596343ec7e1fe133fa1b23
crc32: 85350D39
md5: 906a30920714850dd35837e5b4d9a5c6
sha1: 0603092d879ccd528fcea41c5aff017cac449ab7
sha256: 1836d30c8e3259faa1bb21abb9dc8a0c2bc7e4b927596343ec7e1fe133fa1b23
sha512: 754ac86fef3e5713dbb362bf3d7ef58b8331002099d550c3508619830f241b4218d3cb420b100b7ff35430e715ad42849871ceaba7c21906c1924874a7014bc2
ssdeep: 98304:N+6oXU/1cDgCoZnr10ifGtGVEXfg2XsbXaiQ0Bg64Y8:I6oKFhfGTXopXk0Bg48
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB1633867AC71158D0F0A73044CE7E658B6BB3679105A126A0A86CC7BFFF33F1E95681
sha3_384: 35dab9e9095fdbc28c1d366eccc06aa34bd224eae802c71051947acdd7014adb6ed6dba87a14a4281f96dfb957bb3a0c
ep_bytes: eb085d21220000000000e9d8adfeff00
timestamp: 2011-03-28 05:42:56

Version Info:

FileDescription: Windows 激活工具
FileVersion: 1.8.0.0
ProductName: Windows 激活工具
ProductVersion: 1.8.0.0
Translation: 0x0409 0x04e4

Bulz.416501 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.416501
FireEyeGeneric.mg.906a30920714850d
ALYacGen:Variant.Bulz.416501
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/PornoAsset.1c42cbe5
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.34742.@Z0@aG9umwci
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.VMProtect.E
KasperskyTrojan-Ransom.Win32.PornoAsset.dbrt
BitDefenderGen:Variant.Bulz.416501
AvastWin32:Dropper-gen [Drp]
TencentWin32.Trojan.Pornoasset.Hqva
Ad-AwareGen:Variant.Bulz.416501
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Bulz.416501 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.416501
AviraHEUR/AGEN.1203975
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Trickbot!ml
CynetMalicious (score: 100)
McAfeePacked-GV!906A30920714
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:g+Cz8NosxHgjZzayYMSLPg)
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.d879cc

How to remove Bulz.416501?

Bulz.416501 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment