Malware

Bulz.439674 (file analysis)

Malware Removal

The Bulz.439674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.439674 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

csdw.jia-si.cn
downdcdn.jia-si.cn
www.jia-si.cn

How to determine Bulz.439674?


File Info:

crc32: A6F5B08B
md5: 4dabc74465b56d30eca16813037f2a51
name: 4DABC74465B56D30ECA16813037F2A51.mlw
sha1: 4e64c97e494f7ba1298d2f9b0ba8c1b6bd0bf883
sha256: 1a55a595278aad673f295d8eee4a3c89256a540101bf33ed97bf997f07787da7
sha512: f619a5817b072ef6d12ae94a356fff3ad886367ba9da9fa34a02aeaf42ab0a9d295d235ca1000f114351b956847727dea125505eafac612d23232efe1b17a093
ssdeep: 49152:Z+mXVL16pEshaLy9CM+sdQ1AercwhHf5d93a15C3RrHrhaUeVumV:omXVL16pEsha2twAerBhpa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.439674 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00535f0d1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.439674
CAT-QuickHealTrojan.Skeeyah.S3293683
ALYacGen:Variant.Bulz.439674
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00535f0d1 )
Cybereasonmalicious.e494f7
CyrenW32/S-d2a266d3!Eldorado
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.439674
NANO-AntivirusTrojan.Win32.Softcnapp.fhrxrn
TencentTrojan.Win32.Generic.e
Ad-AwareGen:Variant.Bulz.439674
SophosSoftcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.O@80ok4p
DrWebAdware.Softcnapp.92
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Softcnapp.vh
FireEyeGeneric.mg.4dabc74465b56d30
EmsisoftGen:Variant.Bulz.439674 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cnqmd
AviraHEUR/AGEN.1142834
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27997BD
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Bulz.D6B57A
GDataGen:Variant.Bulz.439674
AhnLab-V3PUP/Win32.Helper.R233980
Acronissuspicious
McAfeeSoftcnapp
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Adload
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!BLwohnTxrUM
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AJ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Bulz.439674?

Bulz.439674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment