Malware

About “Bulz.420115” infection

Malware Removal

The Bulz.420115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.420115 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking

How to determine Bulz.420115?


File Info:

crc32: B7765EB5
md5: 8a06781c34523cb81e87fd673ad1406f
name: 8A06781C34523CB81E87FD673AD1406F.mlw
sha1: b48b51c7ad3e8ebc761ba81dd06f383bd56c395d
sha256: b4f3e4e4944feec650a867bf81338829c21a170f174681d36cdd980dabbee1f3
sha512: 960cac31a8822f6aa569674b8576115c3580cc4107c77fccad27744db558158ec784eed44fd68cc8d2ad82c894c229da526a63048ab49aac1153762fbb8a3a10
ssdeep: 12288:vgbFFGBqpJjv0aM+2qKbsOwlXAiRjBtsG580WEa6GchSUrXuGdqetlx5:vgbFIBqpGT+23oOwh8VEabsuGdqulx5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 1.0.0.0
InternalName: RSlx516c.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SqlFormatter
ProductVersion: 1.0.0.0
FileDescription: SqlFormatter
OriginalFilename: RSlx516c.exe

Bulz.420115 also known as:

K7AntiVirusTrojan ( 0057a3361 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.628
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.420115
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0057a3361 )
Cybereasonmalicious.7ad3e8
CyrenW32/MSIL_Kryptik.BYC.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.AAHD
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderGen:Variant.Bulz.420115
MicroWorld-eScanGen:Variant.Bulz.420115
Ad-AwareGen:Variant.Bulz.420115
SophosML/PE-A + Troj/Kryptik-VP
ComodoTrojWare.Script.UMal.xhnlh@0
BitDefenderThetaGen:NN.ZemsilF.34670.3m0@ae5ujRd
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8a06781c34523cb8
EmsisoftGen:Variant.Bulz.420115 (B)
AviraTR/Kryptik.tksyy
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:MSIL/AgentTesla.BK!MTB
ArcabitTrojan.Bulz.D66913
AegisLabTrojan.MSIL.Noon.l!c
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataGen:Variant.Bulz.420115
AhnLab-V3Malware/Win.Reputation.C4405018
McAfeePWS-FCXP!8A06781C3452
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2222509812
PandaTrj/GdSda.A
RisingSpyware.Noon!8.E7C9 (CLOUD)
IkarusTrojan.MSIL.Crypt
FortinetMSIL/GenKryptik.FDRV!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Noon.HgIASSMA

How to remove Bulz.420115?

Bulz.420115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment