Malware

Should I remove “Bulz.428892”?

Malware Removal

The Bulz.428892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.428892 virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Bulz.428892?


File Info:

name: 7835AB2C41278A66CFD7.mlw
path: /opt/CAPEv2/storage/binaries/3345e73320ddcbe7b196252e46e3777ab2ad5a99bcef8a46651199b36753554f
crc32: 953C3FA4
md5: 7835ab2c41278a66cfd729d9f05b829a
sha1: 89684e1176ee314e69144bbfe6b6bd250696ddf8
sha256: 3345e73320ddcbe7b196252e46e3777ab2ad5a99bcef8a46651199b36753554f
sha512: 37e2773120f04b59f4a9091a8ace5efddf39917b4bee0917bb758044427af5efeace90f05ce49ab403d3873061db5b28378686633edaa72eb5fcc5426b94d131
ssdeep: 49152:D33XFhYpfcGv0DO8LaxqVNL69NauyAJuqAq2ORIZB7pc2q1N:jHFhacE0paxKL2NaQ98Fq1N
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1E9A53385177EFE3FC83046B3AC505E32822AFFCDDA010B4666A7574C7E156DE128762A
sha3_384: 401775af9a8bac84bc6619c3d49867d0a5379cfbd6baf19f9eeac430e948b6bda8f52a6e2b88bc5188f735c2b8ac9204
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-04-10 21:15:50

Version Info:

Translation: 0x0000 0x04b0
Comments: VLC media player
CompanyName: VideoLAN
FileDescription: vlc
FileVersion: 3.0.3.0
InternalName: Fortnite hack v.exe
LegalCopyright: Copyright © 1996-2018 VideoLAN and VLC Authors
LegalTrademarks: VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
OriginalFilename: Fortnite hack v.exe
ProductName: VLC media player
ProductVersion: 3.0.3.0
Assembly Version: 0.0.0.0

Bulz.428892 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MinerNET.20
MicroWorld-eScanGen:Variant.Bulz.428892
FireEyeGeneric.mg.7835ab2c41278a66
CAT-QuickHealTrojan.MsilFC.S20983501
ALYacGen:Variant.Bulz.428892
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Bomitag.D
K7AntiVirusTrojan ( 0057c5581 )
AlibabaTrojan:MSIL/CoinMiner.5f0d4249
K7GWTrojan ( 0057c5581 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW64/MSIL_Troj.BCG.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/CoinMiner.BIP
Paloaltogeneric.ml
ClamAVWin.Trojan.CoinMiner-9851722-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.428892
NANO-AntivirusTrojan.Win64.MinerNET.iuvavi
AvastWin64:CoinminerX-gen [Trj]
Ad-AwareGen:Variant.Bulz.428892
SophosMal/Generic-S + Troj/Miner-ABL
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Bulz.428892 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.428892
AviraTR/CoinMiner.xekaq
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.R415360
McAfeeArtemis!7835AB2C4127
VBA32Trojan.MSIL.Convagent
MalwarebytesTrojan.BitCoinMiner
APEXMalicious
IkarusTrojan.MSIL.CoinMiner
eGambitUnsafe.AI_Score_99%
FortinetMSIL/CoinMiner.BIP!tr
AVGWin64:CoinminerX-gen [Trj]
PandaTrj/CI.A

How to remove Bulz.428892?

Bulz.428892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment