Malware

Bulz.92355 removal instruction

Malware Removal

The Bulz.92355 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.92355 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Bulz.92355?


File Info:

name: 27A958E94731FFEFE78F.mlw
path: /opt/CAPEv2/storage/binaries/070da5cdd5849d75a88ec3bad67c3aed0fbfad2cf2c0aed8513bf7cddb9e36fd
crc32: F37AB9B5
md5: 27a958e94731ffefe78f642322a52605
sha1: 27e9106bb9b4a87497bfd08ca17d3eb70dfbedfd
sha256: 070da5cdd5849d75a88ec3bad67c3aed0fbfad2cf2c0aed8513bf7cddb9e36fd
sha512: 7bb3312d3d60dd4a8f506c08e8a35c2fb2d64176724187eab7841f0068163d0bb99bca4567bf4d9525a45c60f43804b49389a1cd8911c6ee8a42c6043facae65
ssdeep: 12288:5lqku21xKVc0wBtMkRu53We+0CnfFzMam:bq8KVc0vOof8nfCp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BB4E10A3899B119D3D9773DAF95C83443328E866C1BDA3B35E93E073AFE2C70145669
sha3_384: d146ea234bda1c1cac9fefeacc9e5f7d604f73c93a448803fcf160f7007119ebfc7284462966f01a55a8db7e947e4fa7
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-09-08 23:00:45

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: exQ.exe
LegalCopyright:
OriginalFilename: exQ.exe
ProductName: VideoLAN
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.92355 also known as:

BkavW32.Common.F24F2788
LionicTrojan.MSIL.Quasar.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!27A958E94731
MalwarebytesTrojan.MalPack.VL
ZillyaTrojan.Quasar.Win32.3882
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056e23b1 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0056e23b1 )
Cybereasonmalicious.bb9b4a
BitDefenderThetaGen:NN.ZemsilF.36722.Gm0@auNU@nb
VirITTrojan.Win32.Dnldr34.CEGO
CyrenW32/MSIL_Kryptik.BWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Generik.HOYPBWX
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Quasar.gen
BitDefenderGen:Variant.Bulz.92355
NANO-AntivirusTrojan.Win32.Quasar.hwrbdg
MicroWorld-eScanGen:Variant.Bulz.92355
AvastWin32:RATX-gen [Trj]
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Quasar.orctt
DrWebTrojan.DownLoader34.38026
VIPREGen:Variant.Bulz.92355
TrendMicroTROJ_GEN.R002C0GHE23
McAfee-GW-EditionBehavesLike.Win32.Infected.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.27a958e94731ffef
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataGen:Variant.Bulz.92355
JiangminTrojan.MSIL.aopgb
AviraTR/Quasar.orctt
Antiy-AVLTrojan/MSIL.Quasar
XcitiumMalware@#1knjrapdaqbd0
ArcabitTrojan.Bulz.D168C3
ZoneAlarmHEUR:Trojan.MSIL.Quasar.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Bulz.92355
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0GHE23
RisingMalware.Obfus/MSIL@AI.94 (RDM.MSIL2:xfcFY3hkQL658pKnjrOQHg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Quasar!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.92355?

Bulz.92355 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment