Malware

How to remove “Bulz.7314”?

Malware Removal

The Bulz.7314 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.7314 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Bulz.7314?


File Info:

crc32: 930DFDB6
md5: 9ac0929054718a43a48ea2be5f3e38c3
name: loader110.exe
sha1: ae17677d743f39df5f39d4f0b9c095458d3581fe
sha256: fd7c8cc25828e6f3bc1df46b7d6e9b5dc74a68c413071f65cadceeb13c306189
sha512: 68bdb6caa05ed2f8dfc672a82fbbe35f77c34cb49ceb19882f4c74becbdde86ae1d2ab578443c6b32357050545d6f79adb6fc62bae963ee903a50cf1ef3783a7
ssdeep: 196608:B3J9w01SV/YJG+m1W8rkzwtyj79ntUh4aXQcV45M1WSMIwd2nY:Bs00KWzAz/FntUh4RhSRY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020 waterhack.blue
InternalName: waterhack loader
FileVersion: 1.1.0.0
CompanyName: waterhack
ProductName: waterhack loader
ProductVersion: 1.1.0.0
FileDescription: waterhack loader
OriginalFilename: loader.exe
Translation: 0x0409 0x04b0

Bulz.7314 also known as:

MicroWorld-eScanGen:Variant.Bulz.7314
FireEyeGeneric.mg.9ac0929054718a43
McAfeeArtemis!9AC092905471
BitDefenderGen:Variant.Bulz.7314
Cybereasonmalicious.d743f3
BitDefenderThetaGen:NN.ZexaF.34138.@70@aKGLlVhi
TrendMicro-HouseCallTROJ_GEN.R002H0CGQ20
GDataGen:Variant.Bulz.7314
KasperskyTrojan.Win32.Khalesi.aqjx
AlibabaTrojan:Win32/Khalesi.fe51f0b2
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AegisLabTrojan.Win32.Generic.4!c
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazoLAXgBvMmNz+Yp3X5jQQZS)
Endgamemalicious (high confidence)
SophosGeneric PUA KO (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
Invinceaheuristic
EmsisoftGen:Variant.Bulz.7314 (B)
APEXMalicious
AviraTR/Crypt.XPACK.Gen2
ZoneAlarmTrojan.Win32.Khalesi.aqjx
MicrosoftPUA:Win32/Caypnamer.A!ml
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Bulz.7314
Ad-AwareGen:Variant.Bulz.7314
TencentWin32.Trojan.Khalesi.Hwwe
MAXmalware (ai score=88)
FortinetRiskware/Khalesi
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM19.1.CF5B.Malware.Gen

How to remove Bulz.7314?

Bulz.7314 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment