Malware

Should I remove “Bulz.823874”?

Malware Removal

The Bulz.823874 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.823874 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Bulz.823874?


File Info:

name: EDC445680B158A2D413A.mlw
path: /opt/CAPEv2/storage/binaries/8b4f5918f0da8a0eccfd8299ee3a14eb372e8db0b2960eca6ccf34078aa74a5b
crc32: 80E485B8
md5: edc445680b158a2d413a112ba50ef7a9
sha1: 8034d46422409c5c5e40c9b7f2c516099befe0af
sha256: 8b4f5918f0da8a0eccfd8299ee3a14eb372e8db0b2960eca6ccf34078aa74a5b
sha512: 82f148ae87c002ec3e0a078d110c3a6e01f1dc6834191dcb114e89cfcd705520cde529c7586471cdb9df4e8df04d08290b94a129046e27c9b50a21278aa596fa
ssdeep: 6144:wJluxEm5RrG/soB/icOQ0OyZJ9WFRJKorwVrnHtESjYw:wJax5ROsoJXpoJ9WDJrwtNEO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0242204822E3256EDBB613D26E1C89E27E61BF052BC4E4B951099F78C345CB3ADB5F4
sha3_384: 507943ab0e25f90717c2bd5a46e8e7976c95107bae051d33c39c4517815c7ac93d83195b06ce9bf6c12dcd71af0a6b45
ep_bytes: 60be00f055008dbe0020eaff57eb0b90
timestamp: 2021-06-28 19:04:05

Version Info:

Translation: 0x0409 0x04b0
CompanyName: MEGAMILLONES
FileDescription: Programa para el juego de Euromillones
LegalCopyright: www.quiniwin.com
ProductName: MEGAMILLONES
FileVersion: 3.00.0001
ProductVersion: 3.00.0001
InternalName: MEGAMILLONES3.1
OriginalFilename: MEGAMILLONES3.1.exe

Bulz.823874 also known as:

LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
FireEyeGen:Variant.Bulz.823874
SkyhighBehavesLike.Win32.BadFile.dc
McAfeeArtemis!EDC445680B15
Cylanceunsafe
CrowdStrikewin/malicious_confidence_70% (W)
APEXMalicious
BitDefenderGen:Variant.Bulz.823874
MicroWorld-eScanGen:Variant.Bulz.823874
VIPREGen:Variant.Bulz.823874
EmsisoftGen:Variant.Bulz.823874 (B)
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Bulz.DC9242
GDataGen:Variant.Bulz.823874
ALYacGen:Variant.Bulz.823874
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.94%
TrendMicro-HouseCallTROJ_GEN.R011H09HF23
MaxSecureTrojan.Malware.218692441.susgen
DeepInstinctMALICIOUS

How to remove Bulz.823874?

Bulz.823874 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment