Malware

Bulz.581977 malicious file

Malware Removal

The Bulz.581977 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.581977 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Bulz.581977?


File Info:

crc32: CA4FA4AA
md5: d7328ec415afead8ac14fdb4b9645c1b
name: D7328EC415AFEAD8AC14FDB4B9645C1B.mlw
sha1: 9d3a8ba7861c06881ef63929f841e1452500163e
sha256: d8496d072e29b2cfdeda1988750626b8ab6a1c587c3d91396cdad272d9217546
sha512: 48354a1b1320a157cbc919ddaa7e87a3780147d4de5f2bfa125ca30f35ae5f625cb3e34ae7c2078c6bcb2094f2feb429d8b4e8cdf8d00b7165d97a5062804d46
ssdeep: 12288:fgZDc9F3nC0Py3gAhtUXXXjHeEdZzC6cUbC7VpJixVSiykgFrvBi7nV:fqUTHeEdp3cXriy1YV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2009
Assembly Version: 1.0.0.7
InternalName: TimerQue.exe
FileVersion: 1.0.0.7
CompanyName: National Shirt Shop
LegalTrademarks:
Comments:
ProductName: GameAttempt
ProductVersion: 1.0.0.7
FileDescription: GameAttempt
OriginalFilename: TimerQue.exe

Bulz.581977 also known as:

Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.581977
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Variant.Bulz.581977
SymantecScr.Malcode!gdn30
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Bulz.581977
Ad-AwareGen:Variant.Bulz.581977
BitDefenderThetaGen:NN.ZemsilF.34088.Ym0@aqW@bRb
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
FireEyeGeneric.mg.d7328ec415afead8
EmsisoftGen:Variant.Bulz.581977 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Bulz.581977
McAfeeAgentTesla-FCTJ!D7328EC415AF
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.581977?

Bulz.581977 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment