Malware

What is “Bulz.140494”?

Malware Removal

The Bulz.140494 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.140494 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.140494?


File Info:

crc32: A410DFEF
md5: da252617706d479129503affdb0bcd48
name: upload_file
sha1: df8de3a0894a18ab4740a2e3cda39f5cd36bb5a8
sha256: 2a44e9fb201ebfefa05303145def1f3b015495d5ab8190b8d711b50231c25d89
sha512: a12e8899821ca79fba610ced16a925a22c961fa778586d885037d677c51a866421cfd6e69ef06ee80776c791201dc75ccb7df2a0c4ebb350a0f936327cfc565b
ssdeep: 1536:gkRrvvrgzltFtFwjTcLLoZ801i+g6YCMFJbxtGS1645ZCD8ChZxnmZyG:pLcRLLAcLLu801hmfTE8ChZxnmgG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: ChillX
InternalName: FRIBILLET
FileVersion: 1.00
CompanyName: ChillX
LegalTrademarks: ChillX
Comments: ChillX
ProductName: ChillX
ProductVersion: 1.00
FileDescription: ChillX
OriginalFilename: FRIBILLET.exe

Bulz.140494 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.140494
FireEyeGeneric.mg.da252617706d4791
McAfeeArtemis!DA252617706D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00570fd31 )
BitDefenderGen:Variant.Bulz.140494
K7GWTrojan ( 00570fd31 )
Cybereasonmalicious.7706d4
CyrenW32/Trojan.OMXG-1669
SymantecW32.Rixobot
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.Win32.Vebzenpak.abax
AlibabaTrojan:Win32/Vebzenpak.44ddab16
AegisLabTrojan.Win32.Ursu.4!c
Ad-AwareGen:Variant.Bulz.140494
EmsisoftGen:Variant.Bulz.140494 (B)
ComodoMalware@#1jr2b1eqdl3pf
F-SecureTrojan.TR/AD.VBCryptor.juklp
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
SophosMal/Generic-S
AviraTR/AD.VBCryptor.juklp
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Bluteal!rfn
ArcabitTrojan.Bulz.D224CE
ZoneAlarmTrojan.Win32.Vebzenpak.abax
GDataGen:Variant.Bulz.140494
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZevbaCO.34570.km0@aW5oWdej
ALYacGen:Variant.Bulz.140494
MalwarebytesTrojan.VBCrypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ENQB
TrendMicro-HouseCallTROJ_GEN.R002H05JD20
TencentWin32.Trojan.Vebzenpak.Wqwj
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_86%
FortinetMalicious_Behavior.SB
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM03.0.90A7.Malware.Gen

How to remove Bulz.140494?

Bulz.140494 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment