Malware

Bulz.785086 removal

Malware Removal

The Bulz.785086 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.785086 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings

How to determine Bulz.785086?


File Info:

name: 9C797237DDD8C80CD88D.mlw
path: /opt/CAPEv2/storage/binaries/d6c9cb771e8550df8e3217d9220763f1d1dae2b11619765c29ab0632fe62b6f2
crc32: 0ED7B56B
md5: 9c797237ddd8c80cd88de466accc4b44
sha1: b6cad6c38f16795b4126d6a9b21a84be9c3e6055
sha256: d6c9cb771e8550df8e3217d9220763f1d1dae2b11619765c29ab0632fe62b6f2
sha512: 7bee69b13dcfb79bce201ba107a899bc308dfb97b999d7167ad38e30e84b8aeacb96d7eab0d9171116adaf4eb3ef413ce819ffeefbd80a86762d9813468842cf
ssdeep: 49152:Zv++H1tfhUdH52SP7dSsLBaH1OdQKuJrxaRyOJB0Y5yM6jR/vTkTjTX2tM2MY+x:V++HylBwNKuyjD0wiEbiN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195165C32B684523AD07B4E375937E65CDC3B7A712A25CC5B2BE4094C8F39A407A3A717
sha3_384: e910257ab76b1d416b757f228771ef05a8658ce8db4fcd62c39386c34539d3b98d7f93ec52ad49776e2586389e05b447
ep_bytes: 558bec83c4f0b8f04f7700e850d7c8ff
timestamp: 2021-10-03 18:42:12

Version Info:

CompanyName: ZagaFact
FileDescription: ZagaFact
FileVersion: 28.5.4.7
InternalName: ZagaFact
LegalCopyright: Copyright (C) ZagaFact
LegalTrademarks: ZagaFact
OriginalFilename: ZagaFact
ProgramID: ZagaFact
ProductName: ZagaFact
ProductVersion: 28.5.4.7
Translation: 0x0409 0x04e4

Bulz.785086 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.BestaFera.7!c
MicroWorld-eScanGen:Variant.Bulz.785086
FireEyeGeneric.mg.9c797237ddd8c80c
ALYacGen:Variant.Bulz.785086
Cylanceunsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0057dc251 )
AlibabaTrojanBanker:Win32/BestaFera.9c938957
K7GWTrojan-Downloader ( 0057dc251 )
BitDefenderThetaGen:NN.ZelphiF.36350.@V0@aubNOKpk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DFQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderGen:Variant.Bulz.785086
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan-Banker.Bestafera.Wimw
EmsisoftGen:Variant.Bulz.785086 (B)
F-SecureHeuristic.HEUR/AGEN.1326455
VIPREGen:Variant.Bulz.785086
TrendMicroTROJ_GEN.R002C0WHD23
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SophosMal/Generic-S
AviraHEUR/AGEN.1326455
Antiy-AVLTrojan[Banker]/Win32.BestaFera
ArcabitTrojan.Bulz.DBFABE
ZoneAlarmHEUR:Trojan-Banker.Win32.BestaFera.gen
GDataGen:Variant.Bulz.785086
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4678008
McAfeeArtemis!9C797237DDD8
MAXmalware (ai score=87)
VBA32BScope.Adware.Downware
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WHD23
RisingTrojan.Generic@AI.100 (RDML:fuboPiFgWSWEnj5LazDtZQ)
IkarusTrojan-Downloader.Win32.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.DFQ!tr.dldr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.785086?

Bulz.785086 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment