Malware

How to remove “Bulz.723900 (B)”?

Malware Removal

The Bulz.723900 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.723900 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server

How to determine Bulz.723900 (B)?


File Info:

name: B47618861BDC947C7445.mlw
path: /opt/CAPEv2/storage/binaries/f1fc51e48fa374b23390cf0341fb743fdf5c37cf1899b9b6c0df0ba680f1a882
crc32: 8BAD9CC2
md5: b47618861bdc947c7445d18e29d66948
sha1: 6a0c1d2c6862e238e626204eab93d5564445aadb
sha256: f1fc51e48fa374b23390cf0341fb743fdf5c37cf1899b9b6c0df0ba680f1a882
sha512: 894bc9694211a4034f91ff10e9ab1a40fddb5fa4fa5e5f4faedaa97863fe0dbd7366ee28946c8cbb613d03088aaceb62beb8afbf544401b21dafe8dbf1ba46df
ssdeep: 24576:1AfXUwsklujnGPTpiHt/6KvAnjGvzRcVklvgGc2NZPEN/2tzfElm52jtukg16Zn:mfkMlInaTpiN/6Kv+GvsklvgGhFcdOu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B160C026787869AC32DF33C97BE877B06D39D1155B1DACEECE232D507F02523A5684A
sha3_384: 3e3ad592f278a484cb8cb6a8c64797e8cd823c8660a59fcc6f85ecaed3b03ec5e33ac3632f5e63872edb7ce50f854495
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-07 12:11:43

Version Info:

Translation: 0x0000 0x04b0
Comments: Chương trình quản lý câu hỏi và tạo đề thi soạn theo LaTeX cùng nhiều chức năng khác.
CompanyName: My Home
FileDescription: MyLT 2021
FileVersion: 1.0.2.34
InternalName: MyLT.exe
LegalCopyright: Binh Le © 2018
OriginalFilename: MyLT.exe
ProductName: MyLT 2021
ProductVersion: 1.0.2.34
Assembly Version: 1.0.2.34

Bulz.723900 (B) also known as:

LionicTrojan.Win32.Bulz.4!c
MicroWorld-eScanGen:Variant.Bulz.723900
FireEyeGen:Variant.Bulz.723900
ALYacGen:Variant.Bulz.723900
BitDefenderGen:Variant.Bulz.723900
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Bulz.723900
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.Bulz.723900 (B)
GDataGen:Variant.Bulz.723900
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Bulz.DB0BBC
MicrosoftProgram:Win32/Uwamson.A!ml
McAfeeArtemis!B47618861BDC
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R002H09L721
FortinetPossibleThreat
AVGWin32:Malware-gen

How to remove Bulz.723900 (B)?

Bulz.723900 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment