Malware

About “Bulz.783000” infection

Malware Removal

The Bulz.783000 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.783000 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.783000?


File Info:

name: 81C0DD29522DD5CB6814.mlw
path: /opt/CAPEv2/storage/binaries/a99debb77a9af28d0c8f7cff1e7a6b3125cf0a03832ee695304b475c2cea32bb
crc32: ED9DFDA1
md5: 81c0dd29522dd5cb68149d7589cedc3e
sha1: 1729ab98f94ad5450795d9484448ebcb17578b2d
sha256: a99debb77a9af28d0c8f7cff1e7a6b3125cf0a03832ee695304b475c2cea32bb
sha512: f1ecf6f21cdc817c4e5fb520d44928f64b86583237382791e75234a5b60155cdf14e8c8a6f30bd47acb929d9f2bf3a4010f5002b49a74721b7e7b1906b3162fb
ssdeep: 12288:twjIpwTIIMNid5wwCL4UP4w7oyXnZgS1MS:t0Ip+X5dlA0ynSHS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE94AE2963908876D7AB0330A4168D1DC7B5B9312B62D3CB7F8C61A91FB1BC199372D7
sha3_384: fc87afc6c518bbe9429bd5070cc3634203f2aafc9c65a3a2867d42abaff71e502debfab20b5efaa7c47b22091c3e4d5f
ep_bytes: e863060000e978feffffcccccccccccc
timestamp: 2021-02-24 21:27:00

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: AcroTextExtractor
FileVersion: 21.1.20142.424128
LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: AcroTextExtractor.exe
ProductName: Adobe Acrobat text extractor for non-PDF files
ProductVersion: 21.1.20142.424128
Translation: 0x0409 0x04b0

Bulz.783000 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.547
MicroWorld-eScanGen:Variant.Bulz.783000
FireEyeGen:Variant.Bulz.783000
McAfeeRDN/Autorun.worm.gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Fugrafa.AB.gen!Eldorado
TrendMicro-HouseCallWORM_AUTORUN.BGA
ClamAVWin.Worm.Vindor-9886047-0
BitDefenderGen:Variant.Bulz.783000
AvastWin32:VB-FBX
TrendMicroWORM_AUTORUN.BGA
McAfee-GW-EditionBehavesLike.Win32.Autorun.gh
EmsisoftGen:Variant.Bulz.783000 (B)
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.783000
CynetMalicious (score: 100)
VBA32Worm.VB
ALYacGen:Variant.Bulz.783000
MalwarebytesMalware.AI.3696146603
YandexTrojan.Agent!vGmSoUnC6tc
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Fugrafa.A069!tr
AVGWin32:VB-FBX
Cybereasonmalicious.9522dd

How to remove Bulz.783000?

Bulz.783000 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment