Malware

Bulz.394170 (B) removal instruction

Malware Removal

The Bulz.394170 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.394170 (B) virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:19547
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Bulz.394170 (B)?


File Info:

crc32: F2D4CD72
md5: 31bd0390afd44c02d24143a7a2478496
name: 31BD0390AFD44C02D24143A7A2478496.mlw
sha1: a4bac42d0864ec4a4f784ed566b33a9e67757d61
sha256: b3fcc582003e5d14f0d98b042c3353b0a5946c3980dbd51c2236b9485071d5a5
sha512: 57432b0f274f5076cd0c0a2522113b9128bab009a2d31f1bd2fa434f59bd8ac215e0a701f5bb79ffe88e9de6f2225bea80eced698fee4267206e9cbcc4f92fc6
ssdeep: 98304:p72l4K52MZdd/jUMP+/EaST9wGuFrvs+cli0hEYo10WovTG0DlonVp6MMMMiMM:p72X524XoaCEaST9nuFrolN+YoBoa0D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimatimodunador.exe
FileVersions: 7.0.2.54
LegalCopyrights: Vsekdar
ProductVersions: 7.0.21.45
Translation: 0x0129 0x04f4

Bulz.394170 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d0864e
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Bulz.394170
MicroWorld-eScanGen:Variant.Bulz.394170
Ad-AwareGen:Variant.Bulz.394170
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34608.@x0@a05PhThG
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.31bd0390afd44c02
EmsisoftGen:Variant.Bulz.394170 (B)
SentinelOneStatic AI – Suspicious PE
AviraADWARE/Lollipop.Gen4
GDataGen:Variant.Bulz.394170
Acronissuspicious
McAfeeArtemis!31BD0390AFD4
MAXmalware (ai score=89)
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazoVq6+IFsv0c8UO/64xfqC2)
AVGWin32:BotX-gen [Trj]
Qihoo-360HEUR/QVM10.1.EA0A.Malware.Gen

How to remove Bulz.394170 (B)?

Bulz.394170 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment