Malware

Bulz.416128 removal instruction

Malware Removal

The Bulz.416128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.416128 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • The executable used a known stolen/malicious Authenticode signature
  • Anomalous binary characteristics

How to determine Bulz.416128?


File Info:

name: 44B21AF75880AF21BAD9.mlw
path: /opt/CAPEv2/storage/binaries/ea19736c8e89e871974aabdc0d52ad0f0948159d4cf41d2889f49448cbe5e705
crc32: E5487C5B
md5: 44b21af75880af21bad9fda1dd953815
sha1: c60d0ed7872f33fec07fcd42ccc4f21d512ab3ff
sha256: ea19736c8e89e871974aabdc0d52ad0f0948159d4cf41d2889f49448cbe5e705
sha512: 345641547c938929f7eac5108cbb9969b75eee5389d1acfd8a68faff0adce01e92158900869894617818c97055cf0c6512e07af2508ed4a196e825126cd440fd
ssdeep: 3072:Q2i8kiFiQ1t8ZjuSv7ItLrNEcqi8Fe7Di9Rl3jy7R3Lk984i1ECB/qjlE+EqCu+y:XfkcELsjq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12375613E29BD233BC9A8D2E9CFD68427F058E46B3951AC6294D787654783A4335C313E
sha3_384: c25f6777e11af37434b6c3eaa2824d1125db93166049fcb4dfd8c497e85431ee812da7fa49c6ace4780990ed75b7117b
ep_bytes: 68641c4000e8f0ffffff000000000000
timestamp: 2019-11-03 11:32:44

Version Info:

Translation: 0x0409 0x04b0
ProductName: Image Viewer
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Image Viewer
OriginalFilename: Image Viewer.exe

Bulz.416128 also known as:

LionicTrojan.Win32.Maze.j!c
MicroWorld-eScanGen:Variant.Bulz.416128
CAT-QuickHealRansom.Maze.VB3
ALYacTrojan.Skeeyah
ZillyaTrojan.GenKryptik.Win32.38659
K7AntiVirusTrojan ( 0055aeca1 )
AlibabaRansom:Win32/Injector.2b97f9de
K7GWTrojan ( 0055aeca1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Bulz.D65980
CyrenW32/Zbot.AAN.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Injector.EJNG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Agent-7761820-0
KasperskyTrojan-Ransom.Win32.Maze.fc
BitDefenderGen:Variant.Bulz.416128
NANO-AntivirusTrojan.Win32.Zbot.ghnaez
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Bulz.416128
TACHYONRansom/W32.VB-Maze.1554960
EmsisoftGen:Variant.Bulz.416128 (B)
ComodoMalware@#1j4nlsoms30sj
F-SecureTrojan.TR/Kryptik.pxjtu
DrWebTrojan.Encoder.30073
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MAZE.AC
McAfee-GW-EditionGeneric VB.fl
FireEyeGeneric.mg.44b21af75880af21
SophosMal/Generic-R + Mal/VBCheMan-C
IkarusTrojan-Ransom.Maze
JiangminTrojanSpy.MSIL.ajeu
WebrootW32.Malware.Gen
AviraTR/Kryptik.pxjtu
Antiy-AVLTrojan/Generic.ASMalwS.2CDC43F
MicrosoftPWS:Win32/Zbot!MTB
ViRobotTrojan.Win32.S.MazeRansom.1554960
GDataGen:Variant.Bulz.416128
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Skeeyah.C3549368
McAfeeGeneric VB.fl
MAXmalware (ai score=100)
VBA32BScope.Trojan.Occamy
TrendMicro-HouseCallRansom.Win32.MAZE.AC
TencentMsil.Trojan-spy.Zbot.Pdmg
YandexTrojan.VBInject.Gen.8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Bifrose.NKY!tr
AVGWin32:Malware-gen
Cybereasonmalicious.75880a
PandaTrj/GdSda.A

How to remove Bulz.416128?

Bulz.416128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment