Malware

About “Bulz.141157” infection

Malware Removal

The Bulz.141157 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.141157 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

Related domains:

mone1.ddns.net

How to determine Bulz.141157?


File Info:

crc32: 343C7E35
md5: b4bcd218354ac5694214e8194916eea0
name: B4BCD218354AC5694214E8194916EEA0.mlw
sha1: ff4c3d3ff15e34d969c95dda48fed93d3ec27d59
sha256: dfb1266e2ac8286d5a8a01b58e73fe74bc6c9534f582c078bdd0a002f712d809
sha512: 26b3b5c6015269ee2915b8b967c026b1764f54a4882bdea4e175f8be22aa35facbbf1d4e1d36f21459159267b7587c155e4a7bdcb6549eec00e2be5c956b5cfd
ssdeep: 768:vj3C6c7iLCSnF4r6O49CxwlFJU2XPgBb+38YcRz0:vjy6cik6x9jlE2fgBq3Ez0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Elan Service
Assembly Version: 2.1.1.5
InternalName: H4oGo6zA4.exe
FileVersion: 2.1.1.5
CompanyName: Elan Service
Comments: Elan Service
ProductName: Elan Service
ProductVersion: 2.1.1.5
FileDescription: Elan Service
OriginalFilename: H4oGo6zA4.exe

Bulz.141157 also known as:

LionicTrojan.Win32.Miner.4!c
ALYacTrojan.Downloader.49664B
SangforTrojan.Win32.Small.8
K7GWTrojan-Downloader ( 0052044a1 )
K7AntiVirusTrojan-Downloader ( 0052044a1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.BJO
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.141157
NANO-AntivirusTrojan.Win32.Miner.ewlfnu
ViRobotTrojan.Win32.Agent.49664.DQ
MicroWorld-eScanGen:Variant.Bulz.141157
TencentWin32.Trojan.Miner.Pgcy
Ad-AwareGen:Variant.Bulz.141157
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34170.dq0@a0Q8QYm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXDP-ED!B4BCD218354A
FireEyeGeneric.mg.b4bcd218354ac569
EmsisoftGen:Variant.Bulz.141157 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Miner.ang
AviraTR/Dldr.Small.hglxx
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.238FB3E
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.141157
AhnLab-V3Trojan/Win32.Agent.C2307306
McAfeeGenericRXDP-ED!B4BCD218354A
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
YandexTrojan.Miner!0M+4VjDAHd4
IkarusTrojan-Downloader.MSIL.Small
FortinetMSIL/Small.BJO!tr.dldr
AVGWin32:Malware-gen

How to remove Bulz.141157?

Bulz.141157 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment