Malware

Bulz.244526 (file analysis)

Malware Removal

The Bulz.244526 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.244526 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Bulz.244526?


File Info:

crc32: C06DA8EE
md5: fdd26bbb75c165d9b8ea6e7d82f3f76d
name: FDD26BBB75C165D9B8EA6E7D82F3F76D.mlw
sha1: 784b8aaa19d1ee82dd99c4e7f77341b6047087d7
sha256: 2291dcbce7e770d3bd011d4c766ef382d38f64b5a654199a0c493f4e1f77d156
sha512: a704a844ade1b0c708a66feb9d3f0041d55a7ddf22bb2b6c3fe942f6a12192d25f1a79698abfcb36d3bcc254cc543fab8949a8ed9ea04c1d51e937d53e657f99
ssdeep: 24576:vB4XwRBfx+pFzDNRwwqkykzLSH5741wK:vWgvfx+pFXNOayH5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 2.0.1.5
InternalName: InternalParseTypeE.exe
FileVersion: 0.3.0.6
CompanyName: x5c0fx773cx79d1x6280[QQ:2543280836]
LegalTrademarks: XiaoYan_Software
Comments: x5c0fx773cx79d1x6280xff1ax8be5x7248x672cx76eex524dx8fd8x662fx6d4bx8bd5x7248xff0cx53eax5305x542bx57fax7840x529fx80fdxff0cx540ex7eedx8fd8x4f1ax6709x66f4x65b0x3002
ProductName: x5c0fx773cx4e66x5c4b-x56fex4e66x7ba1x7406x7cfbx7edf
ProductVersion: 0.3.0.6
FileDescription: x5c0fx773cx79d1x6280xff1ax6d4bx8bd5x7248xff0cx540ex7eedx8fd8x4f1ax6709x66f4x65b0x3002
OriginalFilename: InternalParseTypeE.exe

Bulz.244526 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.244526
FireEyeGeneric.mg.fdd26bbb75c165d9
Qihoo-360Generic/Trojan.PSW.374
McAfeeArtemis!FDD26BBB75C1
CylanceUnsafe
AegisLabTrojan.MSIL.Agensla.i!c
BitDefenderGen:Variant.Bulz.244526
K7GWTrojan ( 005740041 )
Cybereasonmalicious.a19d1e
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Agensla.84f957e1
ViRobotTrojan.Win32.Z.Agent.989696.AI
Ad-AwareGen:Variant.Bulz.244526
SophosMal/Generic-S
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Kryptik.ktafj
DrWebBackDoor.SpyBotNET.25
McAfee-GW-EditionBehavesLike.Win32.Packed.dc
EmsisoftGen:Variant.Bulz.244526 (B)
IkarusTrojan-Spy.Keylogger.AgentTesla
WebrootW32.Trojan.Gen
AviraTR/Kryptik.ktafj
MAXmalware (ai score=83)
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftVirTool:MSIL/SharPersist
GridinsoftTrojan.Heur!.03013681
ArcabitTrojan.Bulz.D3BB2E
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataGen:Variant.Bulz.244526
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34670.8u0@aSXNIGj
ALYacGen:Variant.Bulz.244526
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.MalPack.MSIL
ESET-NOD32a variant of MSIL/GenKryptik.EXPO
YandexTrojan.AvsArher.bUx2VN
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetPossibleThreat.PALLAS.H
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.244526?

Bulz.244526 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment