Malware

Bulz.286147 removal tips

Malware Removal

The Bulz.286147 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.286147 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.286147?


File Info:

crc32: 984B8E01
md5: d5ba29d546b06f8ce0f88667102e2f22
name: D5BA29D546B06F8CE0F88667102E2F22.mlw
sha1: ee22dec388b05dc12980f6f4832aa069c3da38a3
sha256: 682d74d577b68f6ab71df65de1a18b52d39dad61c25740f8f2e6785615f63a68
sha512: 664383b95a79ad0d78406e1aba7715245aad0dd68932ea998c35c3af81808eb0d53098ef2179a8745e974ddcd7d3551d1d0792a3ec2bf54fcb67f09c5531f6b0
ssdeep: 393216:ytdMaLYDWWfJmcw/9OLKeRQsiVGGSFR3HZE:+SasKWbEuH9ZE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.0.0.1
CompanyName: PrpVision
Comments: This installation was built with Inno Setup.
ProductName: Ideoclipmaker
ProductVersion: 7.22.0.4588
FileDescription: Ideoclipmaker Setup
Translation: 0x0000 0x04b0

Bulz.286147 also known as:

K7AntiVirusTrojan ( 005722f11 )
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1661
ALYacGen:Variant.Bulz.286147
CylanceUnsafe
SangforTrojan.Win32.Woreflint.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.41b00255
K7GWTrojan ( 005722f11 )
Cybereasonmalicious.546b06
CyrenW32/Trojan.CIPG-7339
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyTrojan.Win32.Ekstak.ahvbu
BitDefenderGen:Variant.Bulz.286147
MicroWorld-eScanGen:Variant.Bulz.286147
TencentWin32.Trojan.Ekstak.Wsjy
Ad-AwareGen:Variant.Bulz.286147
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGen:Variant.Bulz.286147
EmsisoftGen:Variant.Bulz.286147 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Ekstak.bodx
AviraTR/Drop.Agent.uqvur
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Bulz.286147
AhnLab-V3PUP/Win32.InstallCore.R360970
McAfeeArtemis!D5BA29D546B0
MAXmalware (ai score=86)
VBA32Trojan.Zadved
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
YandexTrojan.Ekstak!cFgNxGrP33Y
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Ekstak
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Bulz.286147?

Bulz.286147 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment