Malware

Bulz.640291 (B) (file analysis)

Malware Removal

The Bulz.640291 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.640291 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Bulz.640291 (B)?


File Info:

crc32: 33F1B52E
md5: c5b67e395ab1f21ebd513a781bc0738f
name: C5B67E395AB1F21EBD513A781BC0738F.mlw
sha1: 80e136714f522c5f2f05cc2e212fc6ef33c9440f
sha256: 09051100b870aeeaef873faede980196935ea93a17c351336894d0e74176c34f
sha512: f4590b5077aa7f2cfd51fa983f6050b4abc6fc1b48b560db99dc1be1a2a8260bffaff8d8d4992a0bf645a99b7cce325897c3d3c3bac30a19c7150df048425ae2
ssdeep: 24576:XztVKaLtNFZqeD68NFZqe5GhNxKQtatP/RqiW:DtLPZqeu8PZqeuKqEPZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright CC xa92017 .
Assembly Version: 1.3.0.1
InternalName: dothesoftware.exe
FileVersion: 1.3.0.1
CompanyName: frrfhh ltd
LegalTrademarks: frrfhh
Comments: frrfhh
ProductName: frrfhh Client
ProductVersion: 1.3.0.1
FileDescription: frrfhh
OriginalFilename: dothesoftware.exe

Bulz.640291 (B) also known as:

K7AntiVirusAdware ( 005465501 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.35753
ALYacGen:Variant.Bulz.640291
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 005465501 )
CyrenW32/Trojan.BNQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.CloudGuard.D
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
BitDefenderGen:Variant.Bulz.640291
NANO-AntivirusRiskware.Win32.CloudScout.ezbizf
MicroWorld-eScanGen:Variant.Bulz.640291
TencentMalware.Win32.Gencirc.114cea81
Ad-AwareGen:Variant.Bulz.640291
SophosCloudGuard (PUA)
ComodoApplicUnwnt@#25co7k764y1a4
BitDefenderThetaGen:NN.ZemsilF.34170.tn0@ayi3L6f
VIPREMSIL.Adware.CloudGuard
McAfee-GW-EditionGenericRXEG-DQ!C5B67E395AB1
FireEyeGeneric.mg.c5b67e395ab1f21e
EmsisoftGen:Variant.Bulz.640291 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.CloudScout.od
AviraADWARE/CloudGuard.Gen
Antiy-AVLTrojan/Generic.ASMalwS.250F280
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Bulz.D9C523
SUPERAntiSpywareAdware.CloudGuard/Variant
GDataGen:Variant.Bulz.640291
AhnLab-V3PUP/Win32.CloudGuard.R222514
McAfeeGenericRXEG-DQ!C5B67E395AB1
MAXmalware (ai score=95)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
YandexPUA.CloudGuard!2tPVRI6Deb8
IkarusAdWare.MSIL.Cloudguard
FortinetMSIL/CloudGuard.D
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Bulz.640291 (B)?

Bulz.640291 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment