Malware

Should I remove “Bulz.201626”?

Malware Removal

The Bulz.201626 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.201626 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.201626?


File Info:

crc32: E4F44AA4
md5: 1d2d1ee1b9e7eef3866d812576659dd8
name: 1D2D1EE1B9E7EEF3866D812576659DD8.mlw
sha1: 1817aff5f613015eb5254d1b16d6546331698f09
sha256: 1a31e09a2a982a0fedd8e398228918b17e1bde6b20f1faf291316e00d4a89c61
sha512: add5fbb47be29ea390372924dc81302dae65782daf8aa5cb050a74f7a450e1ed208db7dc688cdff8fe5e42a5c871d1477f7b6395027da1fbe7c3b18313d87117
ssdeep: 49152:xlfBY7uTOQhyEekhGmNyJSagAJdZvwyXoAHmS:xl5sSyEekImNYSeKgVGS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017 Mozilla Corporation All rights reserved.
InternalName: Kingsoft Install Tool
FileVersion: 2.1.4.4
CompanyName: Mozilla Corporation
ProductName: Kingsoft Install Tool
ProductVersion: 2.1.4.4
FileDescription: Kingsoft Install Tool
OriginalFilename: Kingsoft Install Tool
Translation: 0x0409 0x04b0

Bulz.201626 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0052de311 )
LionicTrojan.Win32.Bugor.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5254986
ALYacTrojan.PWS.Agent
CylanceUnsafe
ZillyaTrojan.Agent.Win32.997374
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/MalwareX.ca7f1f72
K7GWSpyware ( 0052de311 )
Cybereasonmalicious.1b9e7e
CyrenW32/S-cf835bfc!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Spy.Agent.PKE
APEXMalicious
AvastWin32:JbossMiner-B [Trj]
ClamAVWin.Malware.Bugor-9836077-0
KasperskyHEUR:Trojan.Win32.Xbash.gen
BitDefenderGen:Variant.Bulz.201626
NANO-AntivirusTrojan.Win32.Bugor.fanxwf
MicroWorld-eScanGen:Variant.Bulz.201626
TencentMalware.Win32.Gencirc.114919c8
Ad-AwareGen:Variant.Bulz.201626
SophosMal/Generic-S
ComodoTrojWare.Win32.Spy.Delpem.A@7mkvv5
BitDefenderThetaGen:NN.ZexaF.34236.Gz1@amFPV1fj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OG921
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.1d2d1ee1b9e7eef3
EmsisoftGen:Variant.Bulz.201626 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gxzkn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1105094
Antiy-AVLTrojan/Generic.ASMalwS.25B8AB8
MicrosoftTrojan:Win32/Occamy.C1A
ArcabitTrojan.Bulz.D3139A
ZoneAlarmHEUR:Trojan.Win32.Xbash.gen
GDataGen:Variant.Bulz.201626
AhnLab-V3Trojan/Win32.Agent.R313295
Acronissuspicious
McAfeeGeneric Trojan.fd
MAXmalware (ai score=99)
VBA32BScope.Trojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OG921
RisingWorm.Xbash!1.B438 (CLASSIC)
YandexTrojan.GenAsa!d9grjAxrhxs
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.PKE!tr
AVGWin32:JbossMiner-B [Trj]
Paloaltogeneric.ml

How to remove Bulz.201626?

Bulz.201626 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment