Malware

What is “Bulz.42402”?

Malware Removal

The Bulz.42402 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.42402 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Bulz.42402?


File Info:

name: 48F55B347E25A7C8F460.mlw
path: /opt/CAPEv2/storage/binaries/5d0035a1cea7c5a8c61e7083f14380b1ba37c276980c5f80f845d5c523c2d7bb
crc32: E37B4CBB
md5: 48f55b347e25a7c8f46099e68be378ca
sha1: 1999bc51902d15939f9b52e57d842b0135c27575
sha256: 5d0035a1cea7c5a8c61e7083f14380b1ba37c276980c5f80f845d5c523c2d7bb
sha512: d2dfdff111321c96f1b1bd578b2740c8923296ef8c7eeef58199f4d2bb240ff82f25104466a6067e948108643cdaf81f24b76f92ff4c0d922a23c298d5b04182
ssdeep: 3072:uAJPSHm8gn5nXTBfcFbKI5pkjBDxeqo3eUIL:uOSHm8gnhTB0FbhmD8q1D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E604BE00B5C0C2B3D4B7113544EACB758A3978720B6E95D7FB9E2BB65E212E097352CE
sha3_384: a52f43c1c1befaf52cbf7077bc5ce7cd8a2fa2ff0f49d7db3b3d4ddcb864f637a02b09e057dbe1a52025863d163c69ae
ep_bytes: e8dd5b0000e9a4feffff6a0c68c81342
timestamp: 2009-09-20 11:43:57

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: syncui
FileVersion: 1.0.0.0
InternalName: syncui.exe
LegalCopyright: Copyright © Microsoft 2010
OriginalFilename: syncui.exe
ProductName: syncui
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.42402 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.a!c
AVGFileRepMalware [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.16845
MicroWorld-eScanGen:Variant.Bulz.42402
FireEyeGeneric.mg.48f55b347e25a7c8
CAT-QuickHealBackdoor.Bladabindi.S1958953
SkyhighBehavesLike.Win32.Redline.cc
McAfeeGeneric BackDoor.aam
ZillyaDownloader.Agent.Win32.111981
SangforTrojan.Win32.Generic.ky
AlibabaTrojan:MSIL/Injector.d155f233
Cybereasonmalicious.47e25a
BitDefenderThetaGen:NN.ZexaF.36802.lq0@aShMVYi
VirITTrojan.Win32.Generic.MTO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.HE
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Score-6912404-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.42402
SUPERAntiSpywareTrojan.Agent/Gen-Mdrop
AvastFileRepMalware [Trj]
TencentWin32.Trojan.Generic.Iajl
EmsisoftGen:Variant.Bulz.42402 (B)
VIPREGen:Variant.Bulz.42402
Trapminemalicious.high.ml.score
SophosMal/Mdrop-BK
SentinelOneStatic AI – Malicious PE
WebrootRootkit.Gen
MAXmalware (ai score=99)
Kingsoftmalware.kb.a.983
MicrosoftTrojan:Win32/Orsam!rts
XcitiumMalware@#3j996kita6tdr
ArcabitTrojan.Bulz.DA5A2
ViRobotWorm.Win32.Autorun.284737
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.42402
GoogleDetected
AhnLab-V3Downloader/Win32.Agent.C100885
VBA32Trojan-Inject.Memtest
ALYacGen:Variant.Bulz.42402
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Generic@AI.97 (RDML:SCD6q3nqz8LtHaD/B3GEtA)
IkarusTrojan.Win32.Jorik
MaxSecureTrojan-Downloader.Agent.EDBQ
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudTrojan:MSIL/Bulz

How to remove Bulz.42402?

Bulz.42402 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment