Categories: Malware

What is “Bulz.77744”?

The Bulz.77744 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.77744 virus can do?

  • Sample contains Overlay data
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.77744?


File Info:

name: 1D3FAB6C280A02ABD20D.mlwpath: /opt/CAPEv2/storage/binaries/1f32bf46519997b20eb7a052a2f24d839bf020d04de43d513fbd752777b574ddcrc32: 77DF7710md5: 1d3fab6c280a02abd20d692f49df2485sha1: f4b04451a8b616372aefae9a4eccc678c98d7a13sha256: 1f32bf46519997b20eb7a052a2f24d839bf020d04de43d513fbd752777b574ddsha512: eb137ce657dca905b61b0fc361e6e54140c1ad6229e93eeb3e5445eb79d07ad284aecfc8f17e6bc70f883de782d6eb9e9b864d0910aeced227fe43f0a85142cessdeep: 49152:GFl8BtlGHEwWHgln/4MnYYJ2ZhqSGLHkJEMy:Y2m1lwIDQytype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T15DA52903D7539177FD5620308C2A6B5416A3AFB46F22D2F7EE437609B9327C3257226Asha3_384: 32ecdb2c28a4779c3ee7336c35deb8ede67a822ce00b86981039a4579323f2171dac819c6e9d1b7e5531db6f14134a24ep_bytes: 6a706870170001e8b602000033ff57fftimestamp: 2001-08-17 20:51:15

Version Info:

CompanyName: Microsoft CorporationFileDescription: System InformationFileVersion: 5.1.2600.0 (XPClient.010817-1148)InternalName: msinfo32.exeLegalCopyright: © Microsoft Corporation. All rights reserved.OriginalFilename: msinfo32.exeProductName: Microsoft® Windows® Operating SystemProductVersion: 5.1.2600.0Translation: 0x0409 0x04b0

Bulz.77744 also known as:

Bkav W32.AIDetect.malware1
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Bulz.77744
FireEye Gen:Variant.Bulz.77744
McAfee Artemis!1D3FAB6C280A
Cylance Unsafe
Zillya Trojan.GenericKD.Win32.154658
Sangfor [NULLSOFT PIMP INSTALL SYSTEM2]
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Cybereason malicious.c280a0
Cyren W32/Patched.CJ.gen!Eldorado
Elastic malicious (high confidence)
APEX Malicious
ClamAV Win.Worm.Mabezat-5431
Kaspersky UDS:Trojan.Win32.Generic
BitDefender Gen:Variant.Bulz.77744
Avast Win32:Malware-gen
Ad-Aware Gen:Variant.Bulz.77744
Sophos Generic ML PUA (PUA)
VIPRE Gen:Variant.Bulz.77744
McAfee-GW-Edition BehavesLike.Win32.Virut.vh
Emsisoft Gen:Variant.Bulz.77744 (B)
SentinelOne Static AI – Malicious PE
GData Gen:Variant.Bulz.77744
Avira HEUR/AGEN.1244252
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
Acronis suspicious
ALYac Gen:Variant.Bulz.77744
MAX malware (ai score=84)
Malwarebytes Malware.AI.3732625001
Rising Trojan.Generic!8.C3 (RDMK:cmRtazruP35geLgoBIzGQnvl/4Uw)
Ikarus Virus.Win32.Fakefire
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Ipamor.7AD6!tr
AVG Win32:Malware-gen
CrowdStrike win/malicious_confidence_70% (W)

How to remove Bulz.77744?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32/Agent.AFBR information

The Win32/Agent.AFBR is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Barys.385087 removal guide

The Barys.385087 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

PWS:Win32/Chyup.B malicious file

The PWS:Win32/Chyup.B is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

Trojan.Win32.Agent.xboakk removal

The Trojan.Win32.Agent.xboakk is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

About “Worm.Win32.Vobfus.efoh” infection

The Worm.Win32.Vobfus.efoh is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Generic.Malware.Lco.500CC679 removal tips

The Generic.Malware.Lco.500CC679 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago