Malware

Bulz.394170 removal tips

Malware Removal

The Bulz.394170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.394170 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:13651
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Bulz.394170?


File Info:

crc32: 741B625A
md5: a3a7aa117fea76bc34e9e05cc00c0597
name: A3A7AA117FEA76BC34E9E05CC00C0597.mlw
sha1: d1e798912683f2dd05db353e93cd9008bbef538b
sha256: c0d32e4b0c557b0f1cbab9071fa404f0e7bf31ac4067192483d5102e585fa7c1
sha512: 5abe6eff88d96c853055a7e5d8f61af1337921d87261322dd173b197564db1f9c2ba9bb733cf38abeda6b25d29e221fc826c5de5952dd84a24f6aa2043687346
ssdeep: 98304:px2M4HhElld3c0D5pMKzKM37H9oHYDigQNqtpHARBI9rjWOQB3ICxmSUgDqGSMM:pmIlDM4KM37H9oHsQzM+aCxdDL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimatimodunador.exe
FileVersions: 7.0.2.54
LegalCopyrights: Vsekdar
ProductVersions: 7.0.21.45
Translation: 0x0129 0x04f4

Bulz.394170 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.12683f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Bulz.394170
MicroWorld-eScanGen:Variant.Bulz.394170
Ad-AwareGen:Variant.Bulz.394170
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34608.@x0@ayvf@4aG
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.a3a7aa117fea76bc
SentinelOneStatic AI – Suspicious PE
AviraADWARE/Lollipop.Gen4
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Glupteba!ml
GDataGen:Variant.Bulz.394170
Acronissuspicious
McAfeeArtemis!A3A7AA117FEA
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazq1A1pi2FJyn8ZCc1RqhiVU)
AVGWin32:BotX-gen [Trj]
Qihoo-360HEUR/QVM10.1.E958.Malware.Gen

How to remove Bulz.394170?

Bulz.394170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment