Malware

How to remove “Bulz.286147 (B)”?

Malware Removal

The Bulz.286147 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.286147 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

How to determine Bulz.286147 (B)?


File Info:

crc32: B0FA162F
md5: 19667f4cc5fc80d491c64fc02f8f8fcf
name: 19667F4CC5FC80D491C64FC02F8F8FCF.mlw
sha1: c449d8bd83c366f4962c67faa581b54cd8383889
sha256: 2e0b2ea44ab74e096f88b8297834c717d9c10d2e979208c8df2f5480650b69b5
sha512: 7aac48c037c3a1190ce781e0d5a423120d48bcad85bf62545ea5090798270cfdec7d80ce9e6589a2ced863071f39dfcd2a12fb8149fe482d41525298abbb36df
ssdeep: 393216:QZql83icvzbw8Q2OGu+j2ExhWh071bEHwsCIfD1xp:Qy4tuMZBbEHwCBxp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.0.0.1
CompanyName: PrpVision
Comments: This installation was built with Inno Setup.
ProductName: Ideoclipmaker
ProductVersion: 7.22.0.4588
FileDescription: Ideoclipmaker Setup
Translation: 0x0000 0x04b0

Bulz.286147 (B) also known as:

K7AntiVirusTrojan ( 005722f11 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1661
ALYacGen:Variant.Bulz.286147
CylanceUnsafe
SangforTrojan.Win32.Ekstak.ahvdl
AlibabaTrojanDropper:Win32/Ekstak.2221e44d
K7GWTrojan ( 005722f11 )
Cybereasonmalicious.cc5fc8
CyrenW32/Agent.CUA.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyTrojan.Win32.Ekstak.ahvdl
BitDefenderGen:Variant.Bulz.286147
MicroWorld-eScanGen:Variant.Bulz.286147
TencentWin32.Trojan.Ekstak.Dyqo
Ad-AwareGen:Variant.Bulz.286147
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGen:Variant.Bulz.286147
EmsisoftGen:Variant.Bulz.286147 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Ekstak.bodx
AviraTR/Drop.Agent.cxjud
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D45DC3
GDataGen:Variant.Bulz.286147
AhnLab-V3PUP/Win32.InstallCore.R360970
McAfeeArtemis!19667F4CC5FC
MAXmalware (ai score=80)
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.111475395.susgen
FortinetRiskware/Agent
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Bulz.286147 (B)?

Bulz.286147 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment