Malware

Bulz.147420 (file analysis)

Malware Removal

The Bulz.147420 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.147420 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Bulz.147420?


File Info:

crc32: 88B2537A
md5: 560cda92545b3b41c229fdeb855634db
name: upload_file
sha1: e23e81427f8a6d036984be899b6ef1620c56b32b
sha256: 25bfba7555f3b542adc0b1384711da8e2e44b5fa8141866eae52a3e81efb6954
sha512: 0a824514feae64fc2f75dfee86cf3637cb5b3149b16b49b0767a19bd5217aff7dbdcfae31e32d84a8609b047071a0daf50b73c52513b1d6ba646747e3cd0f272
ssdeep: 12288:dXRJzIo5X1BdbwCLRtTnxkUpcuIyGLphIcOJr5iWfLVhQFFSXnK:LTdbwCvrxJhIvhIcUkWHQFFf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Valts Silaputnins (c) 2002-2017 All Rights Reserved
Assembly Version: 6.4.0.7666
InternalName: arinzex.exe
FileVersion: 6.4.0.7666
CompanyName: Proxy Switcher
Comments: Proxy Switcher
ProductName: Proxy Switcher
ProductVersion: 6.4.0.7666
FileDescription: Proxy Switcher
OriginalFilename: arinzex.exe

Bulz.147420 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.147420
FireEyeGeneric.mg.560cda92545b3b41
CAT-QuickHealTrojanpws.Msil
McAfeeRDN/Emotet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Azorult.i!c
K7AntiVirusTrojan ( 0057226f1 )
BitDefenderGen:Variant.Bulz.147420
K7GWTrojan ( 0057226f1 )
Cybereasonmalicious.27f8a6
TrendMicroTROJ_GEN.R002C0DK420
BitDefenderThetaGen:NN.ZemsilF.34590.7m0@a0F@KQn
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Azorult.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
ViRobotTrojan.Win32.Z.Bulz.968704
TencentMsil.Trojan-qqpass.Qqrob.Staq
Ad-AwareGen:Variant.Bulz.147420
EmsisoftGen:Variant.Bulz.147420 (B)
F-SecureTrojan.TR/BAS.Spy.yyrqa
DrWebTrojan.PWS.Siggen2.58419
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/Emotet
SophosMal/Generic-S
IkarusTrojan.Inject
JiangminTrojan.PSW.MSIL.awrv
AviraTR/BAS.Spy.yyrqa
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Skeeyah.B!rfn
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Bulz.D23FDC
AhnLab-V3Trojan/Win32.Kryptik.C4217978
ZoneAlarmHEUR:Trojan-PSW.MSIL.Azorult.gen
GDataGen:Variant.Bulz.147420
CynetMalicious (score: 100)
ESET-NOD32a variant of MSIL/GenKryptik.EVOJ
ALYacGen:Variant.Bulz.147420
MalwarebytesSpyware.AzorUlt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK420
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Azorult.EVNY!tr.pws
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.PSW.a72

How to remove Bulz.147420?

Bulz.147420 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment