Malware

Bulz.499894 information

Malware Removal

The Bulz.499894 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.499894 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Bulz.499894?


File Info:

name: E2E8D8275558C0305D7D.mlw
path: /opt/CAPEv2/storage/binaries/5dc3a55e8d6a97e6c5a7c7cbc18ee4f97813b607ecfe053987f78955995740bc
crc32: E79C8297
md5: e2e8d8275558c0305d7d882aa332a4bb
sha1: 4dfe7ab6fd257cfd91d1a0ff3b364e297f515269
sha256: 5dc3a55e8d6a97e6c5a7c7cbc18ee4f97813b607ecfe053987f78955995740bc
sha512: 6534fe3bafd0d24e064737f32050e81e1b7de0d1741388743c8ec82a4b646792a875da0c81fdc36ca447d85e6e6b0733dbf2908871d7e7fbe77bf962ef9f68a6
ssdeep: 49152:YYNChpNqOslduZ9WkXpEAEJTR9h+iivtA8Rhx3Zb5HfmI3RdVfM9EV:YJpEAbiiu8FJb5/d7VfZ
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T194C5D007A3B3C4E8C99BC1708216C7B2E930715B45347E7E1BE4DB231B25E5497AE7A8
sha3_384: 3720c993333d37c5c94ed0de8e291e821fa7e652bf5d0e9d2c6e12ce1fe0e1c4c590b716a0d998aa670c078989464b9c
ep_bytes: 4883ec28488b0545fe2500c700000000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Bulz.499894 also known as:

LionicTrojan.Win32.Bsymem.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.499894
FireEyeGen:Variant.Bulz.499894
McAfeeArtemis!E2E8D8275558
CylanceUnsafe
ZillyaTrojan.Bsymem.Win32.2458
SangforTrojan.Win32.Bsymem.aapj
AlibabaTrojan:Win32/Bsymem.4f2d43a8
SymantecTrojan.Gen.MBT
KasperskyHEUR:Trojan.Win32.Bsymem.pef
BitDefenderGen:Variant.Bulz.499894
AvastWin64:Malware-gen
TencentWin32.Trojan.Bsymem.Alim
Ad-AwareGen:Variant.Bulz.499894
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WLA21
McAfee-GW-EditionBehavesLike.Win64.BadFile.vc
EmsisoftGen:Variant.Bulz.499894 (B)
AviraHEUR/AGEN.1144152
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.499894
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.R425102
VBA32Trojan.Bsymem
ALYacGen:Variant.Bulz.499894
TrendMicro-HouseCallTROJ_GEN.R002C0WLA21
YandexTrojan.Bsymem!Ux6tHtZ+zrw
IkarusTrojan.Win64.Rozena
FortinetW64/GenKryptik.FFIJ!tr
AVGWin64:Malware-gen
MaxSecureTrojan.Malware.73798755.susgen

How to remove Bulz.499894?

Bulz.499894 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment