Malware

Bulz.140122 removal

Malware Removal

The Bulz.140122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.140122 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Bulz.140122?


File Info:

crc32: 4C455F44
md5: 71b3c446827ce8c000c833f9e5e60b03
name: 71B3C446827CE8C000C833F9E5E60B03.mlw
sha1: ec47f9f47a87206ba85a6aa50bcde9e6546da5be
sha256: 59e2db8debcafdcd224dc0a0f345deecbffdba80c9131c2c42737467305a1dac
sha512: e835ee19b621184e3e409ff1da5be952ba8127e36630c288c7dc158d8b37cc458ee50d5616e4dc378a6db170b9015f49ab1de7dc7edc7c615cd77b5ad9852a76
ssdeep: 6144:zu+A8MtohLrlIiU6h/RJrSU6JkJBVg5cyB6dN0dp5lU:WtERZJrSCHVZq6kdfK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.140122 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.HmBlocker.j!c
DrWebTrojan.MulDrop.65386
ALYacGen:Variant.Bulz.140122
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.4153
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/HmBlocker.c689359e
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
ESET-NOD32a variant of Win32/Kryptik.MIV
APEXMalicious
AvastWin32:Mystic
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.HmBlocker.dhm
BitDefenderGen:Variant.Bulz.140122
NANO-AntivirusTrojan.Win32.HmBlocker.dycke
ViRobotTrojan.Win32.A.HmBlocker.145408
MicroWorld-eScanGen:Variant.Bulz.140122
TencentWin32.Trojan.Hmblocker.Ahep
Ad-AwareGen:Variant.Bulz.140122
SophosML/PE-A + Mal/FakeAV-MR
ComodoMalware@#19crwbmskq9kw
BitDefenderThetaGen:NN.ZexaF.34126.mu0@aKwSEnfS
VIPRETrojan-Ransom.Win32.HmBlocker.dlk (v)
TrendMicroTROJ_FAKEAV.SMIJ
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.71b3c446827ce8c0
EmsisoftGen:Variant.Bulz.140122 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/HmBlocker.bzl
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwS.189322A
MicrosoftTrojan:Win32/Bulta!rfn
ZoneAlarmHEUR:Hoax.Win32.FlashApp.gen
GDataGen:Variant.Bulz.140122
McAfeeArtemis!71B3C446827C
MAXmalware (ai score=100)
VBA32BScope.Trojan.Jorik
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.SMIJ
RisingTrojan.Generic@ML.100 (RDMK:Cm/1OPo3GsQSck2aZojzCA)
IkarusTrojan.Win32.Crypt
FortinetW32/BrowHost.KP!tr
AVGWin32:Mystic
Paloaltogeneric.ml

How to remove Bulz.140122?

Bulz.140122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment