Malware

Should I remove “Bulz.811603”?

Malware Removal

The Bulz.811603 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.811603 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Bulz.811603?


File Info:

name: D06AC53BA772B356F2D9.mlw
path: /opt/CAPEv2/storage/binaries/210d512d9d7a0e57cdf166d895d600a10582e4e02e5bf33468ada4396b6ad894
crc32: FA470FDD
md5: d06ac53ba772b356f2d9090ebf06aceb
sha1: 5986e2a732acea88ba1cb1780f3e29a96e20fbc4
sha256: 210d512d9d7a0e57cdf166d895d600a10582e4e02e5bf33468ada4396b6ad894
sha512: 49355575f63f26333969288eb7a93cc1e57c62d5aa3e13fc418efa9b7b3a6b390cc2865ef075f7a76ea191f96804054bef9be3cfd742de2df544904d1a7f6c46
ssdeep: 384:GabZb6HW4AVgPN1QyzYfXCS2dqCEXAXMkzFJaDdS5v9Uo0NS0G1Hx:Jbp6HtPF1QycgqCGyRJaUv9UnS7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE24017B7F69A54F5F75B715CBA076A1A37BC51AF368A0E2200311D2C72E618CA1B33
sha3_384: f9e2adea7a3b82f6ba5ac821d8b8423c2bdfe2d5c1e4ed0e68206de9ed5e748079b4fb94841589526c9d2074ee571855
ep_bytes: 68b8154000e8eeffffff000000000000
timestamp: 2017-10-12 20:13:59

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Sc00bz
ProductName: BACalculator
FileVersion: 3.01
ProductVersion: 3.01
InternalName: capi
OriginalFilename: capi.exe

Bulz.811603 also known as:

LionicTrojan.Win32.Bulz.4!c
MicroWorld-eScanGen:Variant.Bulz.811603
FireEyeGen:Variant.Bulz.811603
ALYacGen:Variant.Bulz.811603
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Skeeyah.A
K7AntiVirusTrojan ( 005114a31 )
AlibabaTrojan:Win32/Generic.30a14c89
K7GWTrojan ( 005114a31 )
Cybereasonmalicious.ba772b
BitDefenderThetaGen:NN.ZevbaF.34062.cm0@aaIdT0hi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Indiloadz.F
TrendMicro-HouseCallTROJ_GEN.R002C0DKS21
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-7600837-0
BitDefenderGen:Variant.Bulz.811603
NANO-AntivirusTrojan.Win32.Yarwi.eunwex
AvastWin32:Malware-gen
TencentWin32.Trojan.Ursu.Wopm
Ad-AwareGen:Variant.Bulz.811603
SophosMal/Generic-S
ComodoMalware@#3efpnanvp2i44
ZillyaTrojan.Indiloadz.Win32.259
TrendMicroTROJ_GEN.R002C0DKS21
McAfee-GW-EditionBehavesLike.Win32.Generic.nz
EmsisoftGen:Variant.Bulz.811603 (B)
GDataGen:Variant.Bulz.811603
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1127064
MAXmalware (ai score=99)
GridinsoftRansom.Win32.Skeeyah.sa
ArcabitTrojan.Bulz.DC6253
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.VB.R224802
McAfeeGenericRXAA-AA!D06AC53BA772
MalwarebytesMalware.AI.3559703280
APEXMalicious
YandexTrojan.GenAsa!cjChLoki5bg
IkarusTrojan.Win32.Indiloadz
FortinetW32/Indiloadz.F!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.811603?

Bulz.811603 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment