Malware

What is “Bulz.638145”?

Malware Removal

The Bulz.638145 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.638145 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.638145?


File Info:

name: 9F0D10048A720E1001BC.mlw
path: /opt/CAPEv2/storage/binaries/851fb328616a6e33239bf816b983b31de305c2ba1564e7a9228933c55e5597e7
crc32: CF742629
md5: 9f0d10048a720e1001bc6a2bc9cd5fc6
sha1: 65d62f6c3b356ad9cd980af81e35fc3ecce4e57a
sha256: 851fb328616a6e33239bf816b983b31de305c2ba1564e7a9228933c55e5597e7
sha512: aef3d0f470b480ac15512eb08db2d5f6d2a6df2dd07f326111a854ee0eaf1df7f0826cd52c8eb0ec78e7a1d206e924f8974570909172a10f3589df11e42f6050
ssdeep: 768:DMGnYmtcLDs/saQRF7DeUfc2coKdJBexLvDCcSjXO3XJAv8RRzIXMOih/e0:voLDYsacF7HcboCJBOCcXXJACKihZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA13BF5326E46467FA938A3109B7A737CFB7D7100622059B07643E6F6E703839E1B187
sha3_384: 4f0cc5581ac3b7acfadcb77c92d4388fffa7bf76fa315d7e7622699f421cec40359dbb072ba38f0be5f11c54d4aaad56
ep_bytes: 81c480feffff53555631c057895c2418
timestamp: 2009-12-05 22:50:35

Version Info:

Comments: 4nV2hXMn1gM4sfqrkrwBlzijQqmh
FileDescription: Download da Internet
InternalName: 4nV2hXMn1gM4sfqr
LegalCopyright: 4nV2hXMn1gM4sf
LegalTrademarks: 4nV2hXMn1gM4sfqrkrwB
OriginalFilename: 4nV2hXMn1gM4sfqrkrwB
Translation: 0x0000 0x04e4

Bulz.638145 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Bulz.638145
FireEyeGeneric.mg.9f0d10048a720e10
CAT-QuickHealSftwrBndlr.NSIS.Fourthrem.B
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_90% (D)
BaiduNSIS.Adware.AdLoad.c
CyrenW32/Adload.ZYAC-0944
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Fraudster.A
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.AdLoad.flrs
BitDefenderGen:Variant.Bulz.638145
NANO-AntivirusTrojan.Nsis.Fraudster.dylxrk
SUPERAntiSpywarePUP.AdLoad/Variant
AvastNSIS:AdwareX-gen [Adw]
EmsisoftGen:Variant.Bulz.638145 (B)
DrWebTrojan.Fraudster.2374
VIPREGen:Variant.Bulz.638145
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataNSIS.Application.Fourthrem.A
JiangminAdware/Adload.anj
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
ArcabitTrojan.Bulz.D9BCC1
ZoneAlarmnot-a-virus:AdWare.Win32.AdLoad.flrs
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3PUP/Win.Adload.C5391597
Acronissuspicious
ALYacGen:Variant.Bulz.638145
MAXmalware (ai score=85)
MalwarebytesAdload.Adware.Downloader.DDS
TrendMicro-HouseCallPAK_Xed-21
MaxSecureAdware.W32.AdLoad.flrs_251898
FortinetAdware/AdLoad.FLXZ
AVGNSIS:AdwareX-gen [Adw]
Cybereasonmalicious.48a720
DeepInstinctMALICIOUS

How to remove Bulz.638145?

Bulz.638145 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment