Malware

How to remove “Bulz.870197”?

Malware Removal

The Bulz.870197 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.870197 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Bulz.870197?


File Info:

crc32: FECD3B59
md5: ae3a70426fe59245eafa1fc46fd499e3
name: AE3A70426FE59245EAFA1FC46FD499E3.mlw
sha1: 24afe01140f8dd3b45037164681a605340caf8bf
sha256: 854df4d6bdfc4c1b38a3dddd3c767af9abe809192f4840bffe5cea9ca8b7b89d
sha512: 7f0cc247155d4d1a1dc8fa1e34da256b2f3f328ca4a65f2cb5fbca6d3f4c73abd9dab52b7e529ed2e0a9b748754ddbc0f457f7e8004e7c1e1c23dd282f03de5a
ssdeep: 24576:RDWHSb4N2c7f2DWHSb4Nc07M0t18D87Z3k6kEBP5gT:484PJ84K0fOgZTB6T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.870197 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.38291
ALYacGen:Variant.Bulz.870197
ZillyaTrojan.Agent.Win32.2205396
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.140f8d
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.870197
MicroWorld-eScanGen:Variant.Bulz.870197
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.ae3a70426fe59245
EmsisoftGen:Variant.Bulz.870197 (B)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Bulz.DD4735
GDataGen:Variant.Bulz.870197
MAXmalware (ai score=83)
MalwarebytesTrojan.Dropper.Script
AVGWin32:Malware-gen

How to remove Bulz.870197?

Bulz.870197 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment