Malware

Bulz.395192 malicious file

Malware Removal

The Bulz.395192 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.395192 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
mchitifiha.ddns.net

How to determine Bulz.395192?


File Info:

crc32: 1DB9619A
md5: fd90327114f38621137f1acee66e1b67
name: FD90327114F38621137F1ACEE66E1B67.mlw
sha1: b7da580391381ebd6dd5cc8d94cf95ae666faaed
sha256: 217e279e70fe6ab97c0042a03656fc805f1c6e6bda12b8ab65a2a34c791b3f13
sha512: c38b73bce1efeab82636b6e8bc1d2313d28b99383f3c8d270370699cfc451f5aaae132965e6a94be309dabcbf93ab1ff64d2291e4eabf93bae55207fa98e5e9c
ssdeep: 1536:yRFVWc6697TQrlirBhVSn4YFZbkkgWbNDqN:YfFQABPSn4YFZbPgW5O
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Bulz.395192 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader13.31211
ClamAVWin.Packed.Bladabindi-7086597-0
ALYacGen:Variant.Bulz.395192
MalwarebytesMalware.AI.147828623
ZillyaTrojan.Generic.Win32.184062
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaBackdoor:MSIL/Bladabindi.254ee08a
K7GWTrojan ( 700000121 )
Cybereasonmalicious.114f38
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.DG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
AvastMSIL:GenMalicious-ADD [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.395192
NANO-AntivirusTrojan.Win32.Bladabindi.fiqatj
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicroWorld-eScanGen:Variant.Bulz.395192
TencentWin32.Trojan.Generic.Egnw
Ad-AwareGen:Variant.Bulz.395192
SophosMal/Generic-R + Mal/Bbindi-G
ComodoBackdoor.MSIL.Bladabindi.AI@7q5fnl
BitDefenderThetaGen:NN.ZemsilF.34294.eqW@aqXYsXi
VIPREBackdoor.MSIL.Bladabindi.a (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.km
FireEyeGeneric.mg.fd90327114f38621
EmsisoftGen:Variant.Bulz.395192 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.285BEA6
MicrosoftBackdoor:MSIL/Bladabindi.AL
GDataGen:Variant.Bulz.395192
AhnLab-V3Trojan/Win32.Llac.C63023
Acronissuspicious
McAfeeBackDoor-FDNN!FD90327114F3
MAXmalware (ai score=100)
VBA32Trojan.Downloader
PandaTrj/Genetic.gen
RisingBackdoor.Bot!1.6675 (CLASSIC)
YandexTrojan.Agent!0TqzhKMqAc4
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.Q!tr
AVGMSIL:GenMalicious-ADD [Trj]
Paloaltogeneric.ml

How to remove Bulz.395192?

Bulz.395192 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment