Malware

Bulz.468157 removal guide

Malware Removal

The Bulz.468157 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.468157 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.468157?


File Info:

name: D7007D182E12D664B5C1.mlw
path: /opt/CAPEv2/storage/binaries/0ab99d03253f90953a6a6cb301c126a2e36661e1bcf2909d514277ef428062b7
crc32: 50107E1D
md5: d7007d182e12d664b5c16582ef5a6cd9
sha1: 4b5fa27c2da9d9a997908b1c598b934b92262e04
sha256: 0ab99d03253f90953a6a6cb301c126a2e36661e1bcf2909d514277ef428062b7
sha512: 3af331e158745d92cac93e6afa5d667437a7312db846b6adc1d6fc3a0acf37b107409d8d294879adf8d3f484c7af60a3a70d9531e17d7b3ea8f08cebe6f785fc
ssdeep: 12288:jmBFsyrHekxxYG+fWWpj64TxPZE9qXYqLEH:Qn1jY7Ls4lPZ3XHEH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3C4DF5922D1AE36C3B91AB582E9D9743F31CF013A9BD75A05D1BFA77A7BB027C50008
sha3_384: 36eaa4c5d0b720bcd23aece11746410f3f82252fcdbb6d821a97fb24c6f92c4ef9b4163ce41420dfc098a796dbc64bfa
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-12-02 01:01:46

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: luycksbk.exe
LegalCopyright:
OriginalFilename: luycksbk.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.468157 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.468157
FireEyeGeneric.mg.d7007d182e12d664
McAfeeArtemis!D7007D182E12
Cylanceunsafe
VIPREGen:Variant.Bulz.468157
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b98671 )
AlibabaTrojan:MSIL/Injector.863f5f60
K7GWTrojan ( 004b98671 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36132.Hm0@aS7beOn
VirITTrojan.Win32.MSIL5.CETX
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BML
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.Bulz.468157
AvastWin32:Malware-gen
TencentWin32.Trojan.Dropper.Zchl
EmsisoftGen:Variant.Bulz.468157 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Injector.Win32.905411
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.468157
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/MSIL.Injector
XcitiumMalware@#361l75ea58xde
ArcabitTrojan.Bulz.D724BD
ZoneAlarmUDS:Trojan.Multi.GenericML.xnet
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/MSILKrypt14.Exp
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Bulz.468157
MAXmalware (ai score=100)
RisingMalware.Obfus/MSIL@AI.89 (RDM.MSIL2:uyoEStndrWQFQLrLJVzvdg)
YandexTrojan.Injector!G7FA7cMI9aY
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.1728101.susgen
FortinetMSIL/BML!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Bulz.468157?

Bulz.468157 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment