Malware

Should I remove “Bulz.617114”?

Malware Removal

The Bulz.617114 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.617114 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Bulz.617114?


File Info:

name: 2FB9E010563D99F6B662.mlw
path: /opt/CAPEv2/storage/binaries/c2730984abe53737b6cf50f8231c74eb7c90071912a55e2792c08eebebbdb637
crc32: 007244AB
md5: 2fb9e010563d99f6b66272d3cf41ad67
sha1: d0e62dd59bb4b9c93d9987ed8038e876d17d2fe8
sha256: c2730984abe53737b6cf50f8231c74eb7c90071912a55e2792c08eebebbdb637
sha512: a20e4584216cd728a30ae3018b2ce9df35ec07a87db91771f2e04c1987d4aadfb0c69c516c972b23827ee6ddf1a749ea2dec71939e247b99fce0ecab74f6fad7
ssdeep: 1536:E4Ip25wt8ql3HKzf1SOl37RkWOALqWV+V5d+8Nlh2Qxb:lIp25wt8q1KZT9RzOAW/F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A683F7AC2FDD2C8CD9DC1EF25485BE97C19A4EC189F9490E126E1C98DB82CAFC347525
sha3_384: 8bf335af68c63d88c25e7418311c367b1e594d276a83ca204aaaa99469a8d0b5a78cf20f9464d4cff33e418a5b498761
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-05-19 21:40:53

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ramazana daspar harambwa lem
FileVersion: 1.0.0.0
InternalName: ramazana daspar harambwa lem.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: ramazana daspar harambwa lem.exe
ProductName: ramazana daspar harambwa lem
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.617114 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.617114
FireEyeGeneric.mg.2fb9e010563d99f6
ALYacGen:Variant.Bulz.617114
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1427755
SangforTrojan.MSIL.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.f004ad17
K7GWTrojan ( 004dbbdf1 )
K7AntiVirusTrojan ( 004dbbdf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CPX
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Bulz.617114
NANO-AntivirusTrojan.Win32.Kryptik.fcnkso
AvastWin32:Malware-gen
TencentMsil.Trojan.Generic.Hvtp
Ad-AwareGen:Variant.Bulz.617114
EmsisoftGen:Variant.Bulz.617114 (B)
ComodoMalware@#1ma0ux2kxo82i
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GH321
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Bulz.617114
JiangminTrojan.MSIL.jemm
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.262FECB
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/MSILKrypt09.Exp
McAfeeArtemis!2FB9E010563D
MAXmalware (ai score=98)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0GH321
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.AQJ!tr
BitDefenderThetaGen:NN.ZemsilF.34294.fm0@aGXMrok
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Bulz.617114?

Bulz.617114 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment