Malware

About “Bulz.43669” infection

Malware Removal

The Bulz.43669 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.43669 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Bulz.43669?


File Info:

name: F3A7010F300BA8426C75.mlw
path: /opt/CAPEv2/storage/binaries/30865d15d97565f46bd25e23e47c752f625906867122b632e5bbfd750bad6980
crc32: 87564685
md5: f3a7010f300ba8426c75068910afab80
sha1: d5b5b892c561f8b884df6965193327bfbfad0243
sha256: 30865d15d97565f46bd25e23e47c752f625906867122b632e5bbfd750bad6980
sha512: e3250b149a5c60b30a37a70292dad380370e72e463c733311dae750737c29a04811eb63dd47d471036ed9e048fb0f89a65fbc0d13cff57854d42c50a32f09773
ssdeep: 3072:lvDf3TQcHU7a0OAes+4+uoNd8AAoHLJW/07L3/Pq5ECeOFp5:VfjQEIZOr4+uoNW7HI4heO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4F3AE1037E0E0B2D0A219346AF1E6B10E7EBD710679914B63E85B796F70ADC9F3531A
sha3_384: 4585a5f99bbf1b36f4139777d30dc861fa2d6232617fbcc29a2300fb58b56af68e59187d061f021920b9b9741468f392
ep_bytes: e8a6560000e989feffff8bff558bec83
timestamp: 2013-05-24 22:39:43

Version Info:

CompanyName: PixelByte Software LTD
FileDescription: Demand UI Manager Control Program
FileVersion: 5.4.2.2
InternalName: demuimgr
LegalCopyright: Copyright (C) 2008-2013 - PixelByte Software LTD
OriginalFilename: demuimgr
ProductName: Demand UI Manager Control Program
ProductVersion: 5.4.2.2
Translation: 0x0415 0x04b0

Bulz.43669 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.f3a7010f300ba842
ALYacGen:Variant.Bulz.43669
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Urausy.a5b3a12a
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.ACSW
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BBYB
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.wwvs
BitDefenderGen:Variant.Bulz.43669
NANO-AntivirusTrojan.Win32.RiskGen.bsbaym
MicroWorld-eScanGen:Variant.Bulz.43669
AvastWin32:Urausy-AE [Trj]
TencentWin32.Trojan-spy.Zbot.Eddn
Ad-AwareGen:Variant.Bulz.43669
EmsisoftGen:Variant.Bulz.43669 (B)
ComodoMalware@#lpbliqc5qsv0
DrWebTrojan.PWS.Panda.4389
ZillyaTrojan.Kryptik.Win32.917627
TrendMicroTROJ_SPNR.14FD13
McAfee-GW-EditionRansom-FCDW!F3A7010F300B
SophosMal/Generic-R + Mal/EncPk-AKK
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Bulz.43669
JiangminTrojan/Foreign.ghf
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1224299
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Bulz.DAA95
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
ZoneAlarmTrojan-Spy.Win32.Zbot.wwvs
MicrosoftRansom:Win32/Urausy.C
Acronissuspicious
McAfeeRansom-FCDW!F3A7010F300B
VBA32Hoax.Foreign
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_SPNR.14FD13
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.Foreign!DNdlym87h7I
IkarusTrojan-Ransom.Foreign
eGambitGeneric.Malware
FortinetW32/Foreign.CTBV!tr
BitDefenderThetaGen:NN.ZexaF.34212.ku0@aaY6LqnO
AVGWin32:Urausy-AE [Trj]
Cybereasonmalicious.f300ba
PandaTrj/Dtcontx.E

How to remove Bulz.43669?

Bulz.43669 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment