Malware

Bulz.703851 removal guide

Malware Removal

The Bulz.703851 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.703851 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Bulz.703851?


File Info:

name: 3C7519D452C9E027DCB9.mlw
path: /opt/CAPEv2/storage/binaries/00544308067c5c2aa6337be65c89687057967f54445790d6b4c58a807a20fc78
crc32: B17A0E04
md5: 3c7519d452c9e027dcb9812104993753
sha1: 4d9f8bb511bbf506c090efdae532b624f04a7eb8
sha256: 00544308067c5c2aa6337be65c89687057967f54445790d6b4c58a807a20fc78
sha512: d6fc5624c9fcf54e4cade606a41e6088e13ddb4082ae4697be48f92c7621d98a8bf7be6c15d93448b2ad78523ce87092951a8ed72927b56cbfd6bad8316a2bd6
ssdeep: 24576:cjPBoDTviKFLD03kj+jSxQhCgxgwgv8mp+J/Iu7QmRURRcDqp/TLky8BoeZl6FeR:cnkjmSxinSakmREcDqp/TL8HhotY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118B54A01BBE8CE2BF1BF27B6647102550BF4F85AAB72E78F554029AE1C527005D193BB
sha3_384: 45b353270cd184fca14e6eba24da3651a5a5108e87de8114b95d0c525f55f1d567a899190d09a6bf389f3a808dbbce23
ep_bytes: ff2574a06500000000000000000048a0
timestamp: 2016-12-08 14:07:33

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Slimhem
FileVersion: 1.0.0.0
InternalName: Slimhem.exe
LegalCopyright: Copyright © 2016
LegalTrademarks:
OriginalFilename: Slimhem.exe
ProductName: Slimhem
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.703851 also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.703851
FireEyeGen:Variant.Bulz.703851
ALYacGen:Variant.Bulz.703851
CylanceUnsafe
VIPREGen:Variant.Bulz.703851
SangforRansom.MSIL.Slimhem.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.13967754
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Filecoder.Slimhem.B
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.juvp
BitDefenderGen:Variant.Bulz.703851
NANO-AntivirusTrojan.Win32.Blocker.ekffye
AvastWin32:Malware-gen
TencentWin32.Trojan.Blocker.Lmbd
Ad-AwareGen:Variant.Bulz.703851
SophosMal/MSIL-AW
ZillyaTrojan.Blocker.Win32.36386
TrendMicroRansom_Blocker.R002C0RFR22
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Bulz.703851 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.703851
JiangminTrojan.Blocker.geh
AviraTR/FileCoder.tutjt
Antiy-AVLTrojan/Generic.ASMalwS.8470
ViRobotTrojan.Win32.Z.Blocker.2460672
MicrosoftRansom:Win32/Genasom!rfn
CynetMalicious (score: 99)
McAfeeArtemis!3C7519D452C9
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallRansom_Blocker.R002C0RFR22
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!QsDFGkMTf/M
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.74774605.susgen
FortinetW32/Blocker.JUVP!tr
BitDefenderThetaGen:NN.ZemsilF.34582.wo0@aerL0Dl
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Bulz.703851?

Bulz.703851 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment