Malware

About “Bulz.944070” infection

Malware Removal

The Bulz.944070 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.944070 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Bulz.944070?


File Info:

name: 1FBBF9D3F384E9DCDE54.mlw
path: /opt/CAPEv2/storage/binaries/db1443ad419589a058e9b9ad3461a74f0411df27e40cb1c21b82b26bb2cb2b66
crc32: 0B73732E
md5: 1fbbf9d3f384e9dcde5420da204f5ee0
sha1: a085bea368095edd4bdc4e1678cd5d59d28fbb34
sha256: db1443ad419589a058e9b9ad3461a74f0411df27e40cb1c21b82b26bb2cb2b66
sha512: 2188bfe95bfbc9d4fe88023bcb43803175e4a94dbc562b875e55a5fd0779ea1718f72ed559d6e4c22c83098b25686e226350ff2dbf8c871c01c727d52e458bd7
ssdeep: 3072:ZkkqFyPdxjeTTzZ7wkgnosXCewK8Rx7MOMKz0ggCTV:ZkRwgTzpbgnDwYOMKp5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146E301C177EAD227C2C95BBA09323241027AA74B3752DF4B0DA8147D6E5339EFA18F51
sha3_384: 653d49fcc086594c8c0ac21483efaec7b69813c29214fec86311a5e87f33c1d41a03e7cc88171dada2c047ed9ac65192
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-04-11 19:09:52

Version Info:

Translation: 0x0000 0x04b0
Comments: 4oIFMusoXd%nt
CompanyName: VmDAGrpmPd4lq
FileDescription: VmDAGrpmPd4lq
FileVersion: 4.1.5.​0
InternalName: 1.exe
LegalCopyright: VmDAGrpmPd4lq
LegalTrademarks: 4oIFMusoXd%nt
OriginalFilename: 1.exe
ProductName: 4oIFMusoXd%nt
ProductVersion: 4.1.5.​0
Assembly Version: 4.2.4.5

Bulz.944070 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Disfa.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.19183
MicroWorld-eScanGen:Variant.Bulz.944070
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FDWX!1FBBF9D3F384
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaTrojanSpy:MSIL/Kryptik.e39d1c60
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Bulz.DE67C6
BitDefenderThetaGen:NN.ZemsilF.36680.im0@aWiB47n
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.PM
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
BitDefenderGen:Variant.Bulz.944070
NANO-AntivirusTrojan.Win32.Disfa.dmklun
AvastMSIL:GenMalicious-EJ [Trj]
TencentMsil.Trojan-Spy.Agent.Gmnw
EmsisoftGen:Variant.Bulz.944070 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Bulz.944070
SophosML/PE-A
IkarusTrojan-Dropper.Win32.FrauDrop
VaristW32/MSIL_Bladabindi.AJ.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/MSIL.Disfa
Kingsoftmalware.kb.c.1000
XcitiumMalware@#3edfcfuxy0geo
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
GDataGen:Variant.Bulz.944070
GoogleDetected
PandaGeneric Malware
RisingMalware.Obfus/MSIL@AI.96 (RDM.MSIL2:4Ia5RN92nOwLTGhZyoMeJg)
YandexTrojan.Disfa!72l9RvZnPR0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7043709.susgen
FortinetW32/Generic.RG!tr
AVGMSIL:GenMalicious-EJ [Trj]
Cybereasonmalicious.368095
DeepInstinctMALICIOUS

How to remove Bulz.944070?

Bulz.944070 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment