Malware

Bulz.69204 (file analysis)

Malware Removal

The Bulz.69204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.69204 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Bulz.69204?


File Info:

crc32: 47B44775
md5: 4039d391fedab68be8d28337b76001ac
name: 4039D391FEDAB68BE8D28337B76001AC.mlw
sha1: 99b3b1b17f658fe757c7a47cc393200a16dea7d4
sha256: 1a2ca9a6319ffabd74fac11ad0b8c6ab4b362b804757e9e3eee4a4736ff3e5de
sha512: 018f63734cb2671a26a47a262142f764a51dc139d1b37a0e6bcd68cca38c7a94fdcc6f2a00f4cf652881f9363b8abd3396c3358499d20e900df3783eb875783b
ssdeep: 384:uSE8KLi1Zw5SHN8WYPycG3QREgG/WQnL:pE8KL4ZwcYqnQRERnL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.6768.29078
InternalName: WinCalendar.exe
FileVersion: 1.0.6768.29078
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.6768.29078
FileDescription:
OriginalFilename: WinCalendar.exe

Bulz.69204 also known as:

K7AntiVirusTrojan ( 0051feaa1 )
LionicTrojan.Win32.Generic.4!c
ALYacGen:Variant.Bulz.69204
CylanceUnsafe
K7GWTrojan ( 0051feaa1 )
Cybereasonmalicious.1fedab
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/CoinMiner.AFA
APEXMalicious
AvastWin32:Malware-gen
KasperskyVHO:Trojan.MSIL.Starter.gen
BitDefenderGen:Variant.Bulz.69204
NANO-AntivirusTrojan.Win32.CoinMiner.iwsknd
MicroWorld-eScanGen:Variant.Bulz.69204
TencentWin32.Trojan.Razy.Oyyj
Ad-AwareGen:Variant.Bulz.69204
SophosMal/Generic-S
ComodoMalware@#39vk3asr9ohw0
BitDefenderThetaGen:NN.ZemsilF.34236.am0@ayiLszl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXJT-MJ!4039D391FEDA
FireEyeGen:Variant.Bulz.69204
EmsisoftGen:Variant.Bulz.69204 (B)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Win32.Azden
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Bulz.D10E54
GDataGen:Variant.Bulz.69204
AhnLab-V3Malware/Win32.RL_Generic.C4024810
McAfeeGenericRXJT-MJ!4039D391FEDA
MAXmalware (ai score=99)
VBA32Trojan.MSIL.gen.m
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
YandexTrojan.CoinMiner!BBviToSOInQ
IkarusTrojan.MSIL.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.69204?

Bulz.69204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment