Malware

Bulz.441721 removal

Malware Removal

The Bulz.441721 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.441721 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Bulz.441721?


File Info:

name: 0F18964CAAB11344D138.mlw
path: /opt/CAPEv2/storage/binaries/49e9c04d7e4c97361e96839ed4885e967fc2bda959366a8eadca92802a93282d
crc32: B1B0B373
md5: 0f18964caab11344d1386ff8c2e3059f
sha1: 23b11f58e7e5e20c549192cef17dcae3b1557384
sha256: 49e9c04d7e4c97361e96839ed4885e967fc2bda959366a8eadca92802a93282d
sha512: 8440cb673ef55dfa974262787e4502c069e7a7db663e73fb35b06130949cacacf8429b4cc727fe25b4e403aaf39e37f70aa28c12589fd18c3f50c0e04877b5ee
ssdeep: 49152:wwIm7bvAP2tI6pd6ixfFkBxNjtDOl+tWlXSWDr2eQ:b7bAP2+PixNqj9OYkXxDP
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1E0B5230567978549CF8A207A86CF921143E39F8F03FDD7563EFCF968BA005B636825A1
sha3_384: 0291cb3897b26822ff54b8789b5fece21a4cb6c917b149639e051ff1ffcd54757edcd1382d1a0eb9abe07800252fc95f
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-04-17 11:48:14

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: easy.exe
LegalCopyright:
OriginalFilename: easy.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.441721 also known as:

LionicTrojan.MSIL.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.441721
FireEyeGeneric.mg.0f18964caab11344
ALYacGen:Variant.Bulz.441721
CylanceUnsafe
K7AntiVirusTrojan ( 0057b1151 )
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWTrojan ( 0057b1151 )
Cybereasonmalicious.8e7e5e
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FFE
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Bulz.441721
Ad-AwareGen:Variant.Bulz.441721
SophosMal/Generic-S
ZillyaTrojan.CoinMiner.Win32.34069
McAfee-GW-EditionBehavesLike.Win64.Dropper.vc
EmsisoftGen:Variant.Bulz.441721 (B)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1145035
MicrosoftTrojan:MSIL/CoinMinerInj!MTB
GDataGen:Variant.Bulz.441721
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4452674
McAfeeArtemis!0F18964CAAB1
MAXmalware (ai score=87)
VBA32Trojan.MSIL.Miner
MalwarebytesTrojan.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002H0CKM21
TencentMalware.Win32.Gencirc.11d8fe4d
IkarusTrojan.MSIL.TrojanClicker
FortinetMSIL/Agent.FFE!tr
AVGWin64:Trojan-gen
AvastWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Bulz.441721?

Bulz.441721 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment