Malware

How to remove “Bulz.467870”?

Malware Removal

The Bulz.467870 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.467870 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Bulz.467870?


File Info:

name: 93EFE2783132EDA7FCAC.mlw
path: /opt/CAPEv2/storage/binaries/84c285b73c6c445b8c2cd905296a1d25d3f68c338f387ae8f4aca885c23bcd52
crc32: AC4B9DE5
md5: 93efe2783132eda7fcacc3a76aa91505
sha1: ccb8952ea526e686ed9e1cf7464270cc078d3b7c
sha256: 84c285b73c6c445b8c2cd905296a1d25d3f68c338f387ae8f4aca885c23bcd52
sha512: 7fbde076da8c65d481ddb485910245df017b738ce44ea881af86ae0b1acd955d625fd7d06ecd92299b6d26225607edfd4719853c86ffb31de1826361ad244f2c
ssdeep: 49152:5Cz0jEtc4hS4POsbFb/A7n0B68y/wrFQmuXuFdHWjIjCzw+W7SC64M:sQB4jOsZGnv80wZVuXuFdH0Ies04
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1CAD5233C67EC4900EBED5B3CF5A5059101F2AA06A197779BB00D6EED3B7239E9C4211E
sha3_384: 052bbe2cb98c7152cc40840c90da5e17ad2eea8ce6de1ce75e953307364cd3ae8a6ff5aa4f98db9f3bd8ae871e97673c
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2054-11-22 04:55:05

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Strike-Recode
FileVersion: 1.0.0.0
InternalName: Strike-Recode.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Strike-Recode.exe
ProductName: Strike-Recode
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.467870 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.467870
FireEyeGeneric.mg.93efe2783132eda7
ALYacGen:Variant.Bulz.467870
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 00574e2d1 )
AlibabaPacked:MSIL/VMProtect.6263a781
K7GWTrojan ( 00574e2d1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW64/Trojan.NJND-2831
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.467870
AvastWin64:Malware-gen
Ad-AwareGen:Variant.Bulz.467870
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
EmsisoftGen:Variant.Bulz.467870 (B)
IkarusTrojan.MSIL.Vmprotect
GDataGen:Variant.Bulz.467870
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4520483
McAfeeArtemis!93EFE2783132
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H09EG21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.117761408.susgen
FortinetRiskware/Application
WebrootW32.Malware.Gen
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Bulz.467870?

Bulz.467870 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment