Malware

Bulz.784185 removal guide

Malware Removal

The Bulz.784185 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.784185 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.784185?


File Info:

crc32: C51C49EC
md5: f54492900ddd4a6cff83b5d0cc4ff920
name: F54492900DDD4A6CFF83B5D0CC4FF920.mlw
sha1: 0f3e5e53088f7e15874ba651ad3c0531098715f1
sha256: b93c891093f9206cd1eaa63bb7af51c8cdf43ce5d8a40ca89ca0205290913376
sha512: 7b02472b2bc91fd5173fce5c7f7bf0f0712d2c04a1799fd16952704e9b9cb3740552bb8036ffafb5bc49ac38d517efb752375fac5d9c7e97e5bd18f35f6e3524
ssdeep: 98304:uLZrxLIopDbhHFvWwLh6YcSTOK0crJQosNyaMDSGe0Je2U2LxCxmyj:uLZ1rRdWkh6YPCK5iosNyaM2PMXUwRyj
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) ESET, spol. s r.o. 1992-2021. All rights reserved.
InternalName: Bootstrapper.exe
FileVersion: 10.24.13.0
CompanyName: ESET
LegalTrademarks: NOD, NOD32, AMON, ESET are registered trademarks of ESET.
ProductName: ESET Security
ProductVersion: 15.0.5.2
FileDescription: ESET Live Installer
OriginalFilename: Bootstrapper.exe
Translation: 0x0409 0x04e4

Bulz.784185 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.784185
CylanceUnsafe
Cybereasonmalicious.3088f7
AvastFileRepMetagen [Malware]
BitDefenderGen:Variant.Bulz.784185
MicroWorld-eScanGen:Variant.Bulz.784185
Ad-AwareGen:Variant.Bulz.784185
BitDefenderThetaGen:NN.ZexaF.34266.@B3@a48KRiki
FireEyeGeneric.mg.f54492900ddd4a6c
EmsisoftGen:Variant.Bulz.784185 (B)
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Bulz.DBF739
GDataGen:Variant.Bulz.784185
AhnLab-V3HackTool/Win32.Agent.R342140
MAXmalware (ai score=86)
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazpUVGOBKvESUa7F3/pDjj9J)
YandexTrojan.GenAsa!u0gH+a0TujA
IkarusTrojan.Win32.VMProtect
FortinetW32/VMProtect.JG!tr
AVGFileRepMetagen [Malware]

How to remove Bulz.784185?

Bulz.784185 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment