Malware

How to remove “Bulz.226944”?

Malware Removal

The Bulz.226944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.226944 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Detects VirtualBox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file

How to determine Bulz.226944?


File Info:

name: 26F29DED53271AFB4C5F.mlw
path: /opt/CAPEv2/storage/binaries/889aabb478b15e82d54a1139ea2d425d1845f5184c11dcf90ae1d32a02a12810
crc32: AA605E87
md5: 26f29ded53271afb4c5f58133e58de58
sha1: 9236b43142f56715681f67f113fef8eba4058ced
sha256: 889aabb478b15e82d54a1139ea2d425d1845f5184c11dcf90ae1d32a02a12810
sha512: 9e976414eb4096ac03ae20d050997e892970a201ee193d3d7142f93dc76f9880cac83e77d5317f27e7a97e922ac234635b7f9b6f4fb055caebfed34e0388121a
ssdeep: 24576:1JdEI9mejJ93mrSuHKvYj3qhexkakk+iqDEl340Yyc06y:1JdEI9melcdqE3WexkR1DEl340nl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19545AF01F6017936E9A60430DDBAE37A8A287E30171545DBB7C81DDBEB790D0AA7533B
sha3_384: 0e069fc0923a94fce6eb36b7844bdd90638efd446da1b609608e40b8ff3d409a4b8549ffb76bdacc4a37c73ddf5a3271
ep_bytes: e8e7060000e97afeffff558bec5de959
timestamp: 2020-11-15 20:47:11

Version Info:

0: [No Data]

Bulz.226944 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Bulz.226944
FireEyeGeneric.mg.26f29ded53271afb
ALYacGen:Variant.Bulz.226944
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Wacatac.D8
ArcabitTrojan.Bulz.D37680
BitDefenderThetaGen:NN.ZexaE.34212.mvW@aORf7kek
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.226944
Ad-AwareGen:Variant.Bulz.226944
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Bulz.226944 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/AntiVM
MicrosoftTrojan:Win32/Zpevdo.B
GDataGen:Variant.Bulz.226944
McAfeeArtemis!26F29DED5327
MAXmalware (ai score=84)
VBA32BScope.Adware.SpeedBit
APEXMalicious
MaxSecureTrojan.Malware.110073591.susgen
Cybereasonmalicious.d53271

How to remove Bulz.226944?

Bulz.226944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment