Malware

Should I remove “Bulz.395929 (B)”?

Malware Removal

The Bulz.395929 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.395929 (B) virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Bulz.395929 (B)?


File Info:

name: F107929F66BD584A5D4A.mlw
path: /opt/CAPEv2/storage/binaries/6854547f58394201709b1b790693b218e0898a6c965140cacd80041f8b5dc965
crc32: B9F00DFA
md5: f107929f66bd584a5d4a0453b3b0d40f
sha1: 3cc09ab6fd32470aed3c6399af5eb2259508d58a
sha256: 6854547f58394201709b1b790693b218e0898a6c965140cacd80041f8b5dc965
sha512: f26543083d2c9f0727dd79b88182b4143fbafa09d39f791b873aba102a8714cb9268dd64bc553c84ca3e7613cc658a858a8dc582276b6733130b099766581a25
ssdeep: 96:dg2OH+PWpl4x4LX63FgPMpdabjW1CHzKgOJXmTIoDyLWwOgzNt:dg2OH3QU6CPMnAK1CzOy0LWu
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1FDF1D701B3ECC215F4FE4B751872AB015635FB939953CBAF29C480291D32E548E62FB2
sha3_384: c6b3a0c5cefc055c663ab181edc7a7e28b2787b1a57ac0f37a411e890dd3f22f96e1897fd5eaeea2e817d4bf7b1fa030
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-04 18:03:46

Version Info:

Translation: 0x0000 0x04b0
Comments: Shell Infrastructure Host
FileDescription: Shell Infrastructure Host
FileVersion: 10.0.19041.746
InternalName: 123123123-watchdog.exe
LegalCopyright: © Microsoft Corporation. All Rights Reserved.
OriginalFilename: 123123123-watchdog.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.746
Assembly Version: 0.0.0.0

Bulz.395929 (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MinerNET.20
MicroWorld-eScanGen:Variant.Bulz.395929
FireEyeGeneric.mg.f107929f66bd584a
CAT-QuickHealTrojan.WacatacFC.S20328146
McAfeeGenericRXOH-VM!F107929F66BD
Cybereasonmalicious.f66bd5
CyrenW64/MSIL_Coinminer.C.gen!Eldorado
ESET-NOD32a variant of MSIL/CoinMiner.BIP
ClamAVWin.Trojan.Bulz-9879448-0
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Bulz.395929
AvastWin64:CoinminerX-gen [Trj]
Ad-AwareGen:Variant.Bulz.395929
EmsisoftGen:Variant.Bulz.395929 (B)
McAfee-GW-EditionGenericRXOH-VM!F107929F66BD
SophosTroj/Miner-ABI
IkarusTrojan.MSIL.CoinMiner
GDataGen:Variant.Bulz.395929
eGambitUnsafe.AI_Score_98%
AviraHEUR/AGEN.1143071
MicrosoftTrojan:Win64/CoinMiner.GA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4404809
ALYacGen:Variant.Bulz.395929
MAXmalware (ai score=81)
MalwarebytesTrojan.BitCoinMiner.MSIL.Generic
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetMSIL/CoinMiner.BIP!tr
AVGWin64:CoinminerX-gen [Trj]

How to remove Bulz.395929 (B)?

Bulz.395929 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment