Malware

How to remove “Bulz.358817”?

Malware Removal

The Bulz.358817 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.358817 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.358817?


File Info:

name: 186FF16E9B15AAF89DC5.mlw
path: /opt/CAPEv2/storage/binaries/6b2dba3dcde0b7ef81766ed2132d2a35c8a164be5143eee3943e959daccd88b6
crc32: 48138CF9
md5: 186ff16e9b15aaf89dc55c8ea3ecaf36
sha1: 51ba0aab1b58f577ec44d289bda8310f9ab18b24
sha256: 6b2dba3dcde0b7ef81766ed2132d2a35c8a164be5143eee3943e959daccd88b6
sha512: 4011114fd38a66f9ee0d4f40fb8f8a4422de0f427b3b758924eee226feee8057dc7b8dd491e614b6439064fcffbe3758d9d0acf1a7ccc3c676e5a309901dc372
ssdeep: 1536:ksaXrszFppXkgmuLGa50zZEoXOSramL6sQa:ksaXrszFpp0g7KaazTn2tsQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB43BF43BE982FE9D1720E33483749C257F7926B9D6E15926AACD71CC8F22C85DA3D10
sha3_384: 1fd9e423c766ac1c0015d62a10b5463bbf1f5757f959373633ff4896f20b71c315e5d17077b8bd94074a88bd4e26e038
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-02-07 19:35:59

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: WindowsFormsApplication174.exe
LegalCopyright:
OriginalFilename: WindowsFormsApplication174.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.358817 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Dnoper.4!c
MicroWorld-eScanGen:Variant.Bulz.358817
SkyhighArtemis!Trojan
McAfeeArtemis!186FF16E9B15
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.73930
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577cc11 )
AlibabaTrojan:MSIL/GenKryptik.bdbe1b5a
K7GWTrojan ( 00577cc11 )
ArcabitTrojan.Bulz.D579A1
BitDefenderThetaGen:NN.ZemsilF.36680.dm0@am8v65k
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.FALR
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
BitDefenderGen:Variant.Bulz.358817
AvastWin32:Trojan-gen
TencentMsil.Trojan.Dnoper.Ckjl
EmsisoftGen:Variant.Bulz.358817 (B)
F-SecureTrojan.TR/Kryptik.xyaaz
VIPREGen:Variant.Bulz.358817
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Tiny
JiangminTrojan.MSIL.yxem
AviraTR/Kryptik.xyaaz
Antiy-AVLTrojan/MSIL.Dnoper
Kingsoftmalware.kb.c.996
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Dnoper.gen
GDataGen:Variant.Bulz.358817
GoogleDetected
AhnLab-V3Backdoor/Win32.RL_SpyGate.C4335202
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.Dnoper!cMoLrp+wk1Y
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74328497.susgen
FortinetW32/Dnoper.FALR!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.358817?

Bulz.358817 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment