Malware

Bulz.46397 removal

Malware Removal

The Bulz.46397 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.46397 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

How to determine Bulz.46397?


File Info:

name: B7107A9EDB7EBF44FA6C.mlw
path: /opt/CAPEv2/storage/binaries/d2058fe7abe87c2dbb0ef32bcc4d89c9c02a10752980167846c264ca931e3243
crc32: D0D8F448
md5: b7107a9edb7ebf44fa6c4aac840ec6a5
sha1: dc21b5706d9ea110b42c718d9654c7778a46ee83
sha256: d2058fe7abe87c2dbb0ef32bcc4d89c9c02a10752980167846c264ca931e3243
sha512: deca845ecf33ebb83bd6f3ed490d3e38ed610f9caa4239cd6482ac8f216acd0d5fada210cd4e8ffb05e21ff506af53a98a83f9446adb97d74fc91da9ff87fc23
ssdeep: 98304:eb7UZ3Y38WilHMA2qvO9axKVq3n6woFlCYZmSq4kzGvnneIyC40L5:AoRY32lZvm1wqwobCUXqRz4dL5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E256BD65F242E837D4630730DC1FC2F92525BE10EE349A8B76A47E0D7F76682B924396
sha3_384: 743eca51a4fc54600771efdc162d2b8b6bc3b43d2ec206d5bbb13cc92b2752588e5f8535502c17d10a9c7b975e5bc9ea
ep_bytes: 558bec83c4f053b8181b6700e80b50d9
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Bulz.46397 also known as:

LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.b7107a9edb7ebf44
McAfeeArtemis!B7107A9EDB7E
CylanceUnsafe
SangforTrojan.Win32.Agent.HX6Q1A
Cybereasonmalicious.edb7eb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KIYUZEE
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.46397
NANO-AntivirusTrojan.Win32.GenericKD.eljkyx
MicroWorld-eScanGen:Variant.Bulz.46397
AvastWin32:Trojan-gen
EmsisoftGen:Variant.Bulz.46397 (B)
DrWebTrojan.Hosts.47788
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/Crypt.XPACK.Gen5
GDataGen:Variant.Bulz.46397
ALYacGen:Variant.Bulz.46397
MAXmalware (ai score=89)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.Heuristic.1006
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.46397?

Bulz.46397 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment