Malware

Bulz.496638 removal

Malware Removal

The Bulz.496638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.496638 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.496638?


File Info:

name: 158008BE4FE6123F20FE.mlw
path: /opt/CAPEv2/storage/binaries/0f915db127a9db73005cacd8a8389ac4a6b22eaadaca830279830bd13b966f9e
crc32: CE06B517
md5: 158008be4fe6123f20fe44dc7599b61c
sha1: 9f24a0ce92bc20e5b3b4a7217e8aa3a5406cfebc
sha256: 0f915db127a9db73005cacd8a8389ac4a6b22eaadaca830279830bd13b966f9e
sha512: eee66a028204f907fbdab4882b1cb2f1c9ea448f5c43814e6a8bba0e0008c034edacbf885e35057982d9372dd7cb4a93d3fa0b36da70b2ddad2f26b5c9bce522
ssdeep: 1536:8U9lawm6OH2NsjTaArpaRNP6Pgq31ucL79oerhqi:RXZIjfrpaRNP6PgqLLCerhqi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19893F88D538F710BC602E67D0607CBCE9BBF250288CEA54B54D94A7BFC0649966887DF
sha3_384: 99c6451bd050ee24b9fea7815c8bfd3eafe3ecf0a893e34b77d30ace0bb72a80cfa1e0819aa7d3a11a21f0d3b4c996ea
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-02-15 20:13:52

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: EnCrypted.exe
LegalCopyright:
OriginalFilename: EnCrypted.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.496638 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Gorgon.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.158008be4fe6123f
SkyhighBehavesLike.Win32.Generic.nh
McAfeeArtemis!158008BE4FE6
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Gorgon.b57c04bf
K7GWTrojan ( 004c53df1 )
K7AntiVirusTrojan ( 004c53df1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CHR
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Gorgon.gen
BitDefenderGen:Variant.Bulz.496638
NANO-AntivirusTrojan.Win32.Gorgon.hbzqzb
MicroWorld-eScanGen:Variant.Bulz.496638
AvastWin32:DropperX-gen [Drp]
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:8abYFGkt7kF28g5WKUPagA)
EmsisoftGen:Variant.Bulz.496638 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
VIPREGen:Variant.Bulz.496638
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GoogleDetected
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/MSIL.Gorgon
Kingsoftmalware.kb.c.1000
XcitiumMalware@#2xhk2i7u4rdpc
ArcabitTrojan.Bulz.D793FE
ZoneAlarmHEUR:Trojan.MSIL.Gorgon.gen
GDataGen:Variant.Bulz.496638
VaristW32/MSIL_Troj.RH.gen!Eldorado
AhnLab-V3Trojan/Win32.Bladabindi.C3274537
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Bulz.496638
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.PGen
PandaTrj/GdSda.A
TencentMsil.Trojan.Gorgon.Edhl
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Gorgon.CHR!tr
BitDefenderThetaGen:NN.ZemsilF.36802.fm0@aO8zE9p
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.e4fe61
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:MSIL/Kryptik.TSE

How to remove Bulz.496638?

Bulz.496638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment