Malware

Bulz.2198 removal

Malware Removal

The Bulz.2198 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.2198 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • The sample wrote data to the system hosts file.

How to determine Bulz.2198?


File Info:

crc32: F0F6B6B6
md5: 1e85b89546a20fff16d6e5818e41398e
name: 1E85B89546A20FFF16D6E5818E41398E.mlw
sha1: 7dc656475cb874b7167b33c75df026cef2f71439
sha256: 8ac08ae42fea37a638a391efa77dc5c1a78107e3704149df30ebc46fc43c609f
sha512: b618f27f344895f3a4b22be1b08f4e861d0e77cbc8ed48f320b1545ac9373a166861dd4df8a9daea8d17d6f7cec8fc143f2bb456871e79c636a9a6661d2ca8fe
ssdeep: 6144:01775Ox3h2E807XF+IRsFiN+wz9IfHkoIoi:CH5OH2EN7X1RsFigK9IPkg
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: installer_installcube.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: installer_installcube.exe

Bulz.2198 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.Starter.4385
CynetMalicious (score: 90)
ALYacGen:Variant.Bulz.2198
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Torwofun.2bb28b59
K7GWTrojan ( 700000121 )
Cybereasonmalicious.546a20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.QCZ
APEXMalicious
AvastWin32:Dropper-gen [Drp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.2198
NANO-AntivirusTrojan.Win32.Blocker.dscqgo
MicroWorld-eScanGen:Variant.Bulz.2198
TencentWin32.Trojan.Blocker.Ebhl
Ad-AwareGen:Variant.Bulz.2198
SophosMal/Generic-S
ComodoMalware@#123y4t9xa3za3
BitDefenderThetaGen:NN.ZemsilF.34608.qm0@aayRQcj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXAL-SO!1E85B89546A2
FireEyeGeneric.mg.1e85b89546a20fff
EmsisoftGen:Variant.Bulz.2198 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129525
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Blocker
ArcabitTrojan.Bulz.D896
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.2198
AhnLab-V3Trojan/Win32.Agent.R137323
McAfeeGenericRXAL-SO!1E85B89546A2
MAXmalware (ai score=86)
PandaTrj/CI.A
RisingBackdoor.Torwofun!8.E91 (CLOUD)
YandexTrojan.Blocker!f9bl02hzVKQ
IkarusTrojan.MSIL.Agent
FortinetMSIL/Agent.QCZ!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOoA

How to remove Bulz.2198?

Bulz.2198 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment