Malware

Bulz.769188 (B) malicious file

Malware Removal

The Bulz.769188 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.769188 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Bulz.769188 (B)?


File Info:

name: 6972BE5EFAE8094F12D4.mlw
path: /opt/CAPEv2/storage/binaries/54adbd744e05e185317e80e7060925f7591a07b1e12b608f2217e3c9e62e899b
crc32: E8A0D708
md5: 6972be5efae8094f12d47e136ba26073
sha1: 8c319d0dcf6a1d4a7cf71300b71cf93deb60b27c
sha256: 54adbd744e05e185317e80e7060925f7591a07b1e12b608f2217e3c9e62e899b
sha512: 248f13f032ca595b05e4c6da50d549e5eda63273916a5e272ca1f1cc78b6cfb06e13b938c4a7026be44dd1a569063f178c6eb70160008061a512e195202f081d
ssdeep: 6144:VZ7c6RRC7aEG7oRC7aEG7oUdOwQhyfSAzJLAA3WjRBiXc35f1wZQg14:VZwARqNRqfUdsYfSAzJLAA3WjRBiXc3V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E15495BC3294BAEFC95BD832AD941C54A7B4A5BB471BD207A85305EC9E4D847CF240F2
sha3_384: 7b22770d7bba37620f6105ae90ad943121f6bc537bee31002075648c2b700dc0ee23c3a9079a3d9bc55cb022fb3780d9
ep_bytes: ff250020400000000000000000000000
timestamp: 2085-12-05 17:42:04

Version Info:

Translation: 0x0000 0x04b0
Comments: Using this program, you can search informations on Bosch Engine Control Unit
CompanyName: Dav
FileDescription: Bosch ECU Ultimate Tool by Dav
FileVersion: 1.7.0.0
InternalName: BoschEcuUltimateToolbyDav.exe
LegalCopyright: Dav
LegalTrademarks: BEUT
OriginalFilename: BoschEcuUltimateToolbyDav.exe
ProductName: BEUT
ProductVersion: 1.7.0.0
Assembly Version: 1.7.0.0

Bulz.769188 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.769188
FireEyeGen:Variant.Bulz.769188
ALYacGen:Variant.Bulz.769188
CylanceUnsafe
BitDefenderThetaGen:NN.ZemsilF.34062.sm0@aWQ@!ag
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09KT21
Kasperskynot-a-virus:HEUR:RiskTool.MSIL.BEUT.gen
BitDefenderGen:Variant.Bulz.769188
Ad-AwareGen:Variant.Bulz.769188
EmsisoftGen:Variant.Bulz.769188 (B)
McAfee-GW-EditionRDN/Generic.grp
SophosGeneric ML PUA (PUA)
JiangminRiskTool.MSIL.cqin
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Bulz.296448.C
GDataGen:Variant.Bulz.769188
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4702811
McAfeeRDN/Generic.grp
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
PandaTrj/GdSda.A

How to remove Bulz.769188 (B)?

Bulz.769188 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment