Malware

Bulz.441106 (file analysis)

Malware Removal

The Bulz.441106 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.441106 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Anomalous binary characteristics

Related domains:

smtp.163.com

How to determine Bulz.441106?


File Info:

crc32: 08AA9873
md5: d0c5982822de7f778ff6f9d98ca8eac2
name: D0C5982822DE7F778FF6F9D98CA8EAC2.mlw
sha1: 23babf559a7ea265ab249b96375a0c45a0f49de4
sha256: 4c8882a6dc8b6f8987a3a32b229ec871769fa5ddee5ad9f6061ab58548e08dff
sha512: 3dca4fb801166886f014f5dbd50548a8fd9fa1552c4135a26a6615ab3ce64d34fba252d4239d33a55e5f3693df82db7c8a90843a92186c0b0c099eb597f30852
ssdeep: 384:yIYeZS19qC3v/YGviozx/qqJtj6kao1wPMp:yqC4UiooqJtj6k5H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: x952ex76d8x8bb0x5f55x5668123333333333333333434653333333333333333333333333333333333333333365
FileVersion: 1.00
CompanyName: FREE
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: x952ex76d8x8bb0x5f55x5668123333333333333333434653333333333333333333333333333333333333333365.exe

Bulz.441106 also known as:

ALYacGen:Variant.Bulz.441106
CylanceUnsafe
ZillyaTrojan.VB.Win32.476760
SangforTrojan.Win32.Save.a
K7GWTrojan ( 004531911 )
K7AntiVirusTrojan ( 004531911 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.VB.OIA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Dropper.MSIL.Blocker.e
BitDefenderGen:Variant.Bulz.441106
NANO-AntivirusTrojan.Win32.Blocker.cbwvze
MicroWorld-eScanGen:Variant.Bulz.441106
TencentMsil.Trojan-dropper.Blocker.Wqwj
Ad-AwareGen:Variant.Bulz.441106
SophosMal/Generic-R + Mal/Keylog-A
ComodoMalware@#ffl99tr4zvlb
BitDefenderThetaGen:NN.ZevbaF.34690.bm0@aKcxhdib
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mt
FireEyeGeneric.mg.d0c5982822de7f77
EmsisoftGen:Variant.Bulz.441106 (B)
JiangminTrojanDropper.MSIL.avqr
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Malagent
ArcabitTrojan.Bulz.D6BB12
ZoneAlarmTrojan-Dropper.MSIL.Blocker.e
GDataGen:Variant.Bulz.441106
McAfeeArtemis!D0C5982822DE
MAXmalware (ai score=86)
VBA32TrojanDropper.MSIL.Blocker
PandaGeneric Malware
RisingDropper.Blocker!8.5461 (CLOUD)
YandexTrojan.GenAsa!9N+LZacFhtQ
FortinetW32/Blocker.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.441106?

Bulz.441106 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment