Malware

Bulz.49188 (file analysis)

Malware Removal

The Bulz.49188 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.49188 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

crt.usertrust.com

How to determine Bulz.49188?


File Info:

crc32: 72ECE9D8
md5: 57a43361e270a8af30e54cf875f8a3ae
name: PRODUCT SPECIFICATION.exe
sha1: af06c70beb57c82b2d083b1dbbdf1977d5ba29ff
sha256: 189c657a03542965ec7bf8dff7ab727210eb88ddd7a76b1b95bb12a852e2c5c9
sha512: 277ac8b491b0b62556317ca77233b651db91f6dd8e0b39d15cc31f26556557c0a5804e7f6b3a5bc1eaef251242fd90c53b16fff792c5d4183844fc7551f57716
ssdeep: 98304:nnaFrd6MbYRo4mfJuODcnquG7Dfm4BdtaKhjtiu1K2WV2JBoP:nnaFrd6MbY8cquGXfbAgmP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019 Reason Software Company Inc.
Assembly Version: 3.0.0.16
InternalName: rsEngineHelper.exe
FileVersion: 3.0.0.16
CompanyName: Reason Software Company Inc.
LegalTrademarks: Reason Core Security is a trademark of Reason Software Company Inc.
Comments: Reason Security Engine Helper
ProductName: Reason Core Security
ProductVersion: 3.0.0.16
FileDescription: Reason Security Engine Helper
OriginalFilename: rsEngineHelper.exe

Bulz.49188 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.49188
FireEyeGeneric.mg.57a43361e270a8af
McAfeeArtemis!57A43361E270
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056c8741 )
BitDefenderGen:Variant.Bulz.49188
K7GWTrojan ( 0056c8741 )
SymantecML.Attribute.HighConfidence
AvastWin32:Adware-gen [Adw]
AlibabaTrojan:MSIL/GenKryptik.3deec88f
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareGen:Variant.Bulz.49188
ComodoTrojWare.Win32.UMal.ytcqs@0
F-SecureTrojan.TR/Kryptik.qhwkq
FortinetMSIL/GenKryptik.EQHI!tr
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
AviraTR/Kryptik.qhwkq
MAXmalware (ai score=81)
ArcabitTrojan.Bulz.DC024
MicrosoftTrojan:Win32/Ymacco.AA18
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZemsilF.34182.@p1@a4IVQJk
ALYacGen:Variant.Bulz.49188
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of MSIL/GenKryptik.EQHI
TrendMicro-HouseCallTROJ_GEN.F0D1C00HD20
GDataGen:Variant.Bulz.49188
AVGWin32:Adware-gen [Adw]
Qihoo-360Generic/Trojan.da6

How to remove Bulz.49188?

Bulz.49188 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment