Malware

How to remove “Bulz.661315”?

Malware Removal

The Bulz.661315 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.661315 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Bulz.661315?


File Info:

name: B74EB21A554D0C335FA4.mlw
path: /opt/CAPEv2/storage/binaries/e23892ac8c6fe8bf04c4c8612029097090aa8683ecd1258961aa398fe743b087
crc32: CEADB44B
md5: b74eb21a554d0c335fa4002dce2dd081
sha1: 6a2a904955c37bcb926b4969398d64964c49a993
sha256: e23892ac8c6fe8bf04c4c8612029097090aa8683ecd1258961aa398fe743b087
sha512: 54de520acbfcda11ab8bd1507d7474c82e7aa46aac1f444abc4c1ac19fb5bff3fd823727071404279964731d8bc0df324e37ecae4bbe2c76855a48cc2a056c72
ssdeep: 1536:8Hx5JSGAdd+RF115dq8BhhgHaym55VumRUoC4r1SC9vn7xWNT+0a9XM8F:qW7u1LbWu5nbWbaxHF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0440DE037E1C323E836053C60B649D24B6ADD6DBB23CD6B27443F792EB1D9109AE564
sha3_384: 35c4dadf09ed204c0faf97bb5354d441917229be2d71b7a3f04a01b68fbedfedc6994d97431175272f02828975c0d840
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-04-13 22:31:59

Version Info:

Translation: 0x0000 0x04b0
Comments: me
CompanyName: if
FileDescription: Blow
FileVersion: 9.9.8.5
InternalName: Publisher.exe
LegalCopyright: love
LegalTrademarks: me
OriginalFilename: Publisher.exe
ProductName: you
ProductVersion: 9.9.8.5
Assembly Version: 7.8.9.8

Bulz.661315 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.661315
FireEyeGeneric.mg.b74eb21a554d0c33
ALYacGen:Variant.Bulz.661315
CylanceUnsafe
K7AntiVirusAdware ( 00507f311 )
AlibabaAdWare:MSIL/Perseus.ef4063fb
K7GWAdware ( 00507f311 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.CsdiMonetize.N
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Perseus.gen
BitDefenderGen:Variant.Bulz.661315
NANO-AntivirusTrojan.Win32.CsdiMonetize.eoxhka
SUPERAntiSpywarePUP.Amonetize/Variant
AvastWin32:Adware-gen [Adw]
TencentMsil.Adware.Csdimonetize.Pepq
Ad-AwareGen:Variant.Bulz.661315
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#2uh5ry0a23rjt
DrWebTrojan.MulDrop3.23511
VIPREMSIL.Adware.CsdiMonetize
TrendMicroTROJ_GEN.R002C0WJL21
McAfee-GW-EditionRDN/Generic PUP.x
EmsisoftGen:Variant.Bulz.661315 (B)
IkarusAdWare.MSIL.Csdimonetize
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1136161
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Bulz.661315
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSIL.R195555
McAfeeRDN/Generic PUP.x
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesAdware.Tuto4PC
TrendMicro-HouseCallTROJ_GEN.R002C0WJL21
YandexPUA.CsdiMonetize!kGD6/MAZGIo
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetAdware/CsdiMonetize
BitDefenderThetaGen:NN.ZemsilF.34294.pq0@aC@lOsd
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.a554d0
PandaTrj/GdSda.A

How to remove Bulz.661315?

Bulz.661315 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment