Malware

What is “Bulz.881971”?

Malware Removal

The Bulz.881971 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.881971 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Bulz.881971?


File Info:

name: 72E6B7D0B6DD118A9579.mlw
path: /opt/CAPEv2/storage/binaries/ed24ad75cfd58f626e7d6bf9d5ac014cbf30507475c24003b91bddf1809ae186
crc32: BFBAB4B6
md5: 72e6b7d0b6dd118a95791b5eae001045
sha1: 08c4b4005848425067faf54299307bcd1d08c805
sha256: ed24ad75cfd58f626e7d6bf9d5ac014cbf30507475c24003b91bddf1809ae186
sha512: 0a2dbe47f50d0782f977d5940e66a0dacffabe6d7ed6d11bc472ebc533605ab3cb4b5d4492ba4bc7d20aa92241d72fbd5d2132c33e0f4fd633e64f6127c008fb
ssdeep: 384:rizoSa44luUciNYEf8eEaeFCySWsc+bD3WypriNY2luUKzoSa4:rikluUXcJSWscAJpeTuUKk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109533A12B00CF215E66982F21863C5F811767E7BA9503A9B6ECFBF4A5CB76D32580707
sha3_384: aed350b357956e1ad9637e3b9680c77313951ac1ba0b1bbee28b9dc08820d19da40bee17973c7f25bd150aa53708067d
ep_bytes: 682c5f4000e8eeffffff000000000000
timestamp: 2014-01-17 01:26:51

Version Info:

Translation: 0x0804 0x04b0
Comments: GameToos Hide Run Play.bat
CompanyName: Duck
FileDescription: GameToos Hide Run Play.bat
LegalCopyright: Duck
LegalTrademarks: Duck
ProductName: GameToos Hide Run Play.bat
FileVersion: 1.00.0005
ProductVersion: 1.00.0005
InternalName: Play
OriginalFilename: Play.exe

Bulz.881971 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.881971
ALYacGen:Variant.Bulz.881971
CylanceUnsafe
VIPREGen:Variant.Bulz.881971
CrowdStrikewin/malicious_confidence_70% (W)
VirITTrojan.Win32.VBCrypt.JQ
CyrenW32/S-7d108e31!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
ClamAVWin.Malware.Generic-7603104-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Bulz.881971
NANO-AntivirusTrojan.Win32.VB.dxuqrs
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b14c5a
Ad-AwareGen:Variant.Bulz.881971
EmsisoftGen:Variant.Bulz.881971 (B)
DrWebTrojan.VbCrypt.250
ZillyaAdware.OutBrowse.Win32.86733
McAfee-GW-EditionGenericR-CXD!72E6B7D0B6DD
FireEyeGen:Variant.Bulz.881971
SophosML/PE-A
GDataGen:Variant.Bulz.881971
AviraHEUR/AGEN.1239216
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.7A
ArcabitTrojan.Bulz.DD7533
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeGenericR-CXD!72E6B7D0B6DD
VBA32Trojan.VBKrypt
RisingTrojan.Win32.Generic.18A3E1ED (C64:YzY0On4XkkiN5H5A)
YandexTrojan.VbCrypt!dZvcC6+ie5Q
FortinetW32/Generic.AC.B0CB!tr
BitDefenderThetaAI:Packer.170DEB4420
AVGWin32:Malware-gen
Cybereasonmalicious.0b6dd1
PandaTrj/CI.A

How to remove Bulz.881971?

Bulz.881971 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment