Malware

Bulz.510591 removal instruction

Malware Removal

The Bulz.510591 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.510591 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Bulz.510591?


File Info:

name: D288B2CCF9BCBB5C4D82.mlw
path: /opt/CAPEv2/storage/binaries/74993b5b3a3ab4d3f173e847eeb169fe9cb1f0cbd2a697f3a2b0bf812946e96d
crc32: D6576158
md5: d288b2ccf9bcbb5c4d821b8f139ee0cc
sha1: 037c2e96b7cd593e8c32ab2339ef4ada9200c857
sha256: 74993b5b3a3ab4d3f173e847eeb169fe9cb1f0cbd2a697f3a2b0bf812946e96d
sha512: f909c473c2ac1e3d7bc98d909a33851d5d563871eb62a88c200b2636578cc319eaf5857e8a0a384692c2e3d3e379959118d6cd8d05ab94ebc3d908509a9dacb0
ssdeep: 196608:0Yb9g+fI9vOMdP0Zmx3YUuIk1x2bsoUBj+:0YblCWMdP0ZmxozIOUjU8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147662318BD445055E245343228CFAF4DFFBDAE5A0820858671F7B33EFEB9686A581E1C
sha3_384: 815352d7bccca7a7efa8d3d0669470473ef905c2043e8e5c7949f5e7c2b03ccb36bbc99f60f0f4f05b1d23f9e6c2b124
ep_bytes: 60be00d04a008dbe0040f5ff57eb0b90
timestamp: 2020-04-20 08:27:23

Version Info:

CompanyName: Ghisler Software GmbH
FileDescription: Total Commander 32-64 bit
FileVersion: 10.0
InternalName: TOTALCMD
LegalCopyright: Copyright ⓒ 1993-2021 Christian Ghisler
OriginalFilename: totalcmd.exe
ProductName: Total Commander
ProductVersion: 10.0
040904e4: Ghisler Software GmbH
040c04e4: Ghisler Software GmbH

Bulz.510591 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.510591
CAT-QuickHealPUA.ViguaRI.S14012143
ALYacGen:Variant.Bulz.510591
ZillyaTool.KMSAuto.Win32.1750
K7AntiVirusAdware ( 005071f51 )
K7GWAdware ( 005071f51 )
ClamAVWin.Malware.Wacatac-9818389-0
BitDefenderGen:Variant.Bulz.510591
Ad-AwareGen:Variant.Bulz.510591
EmsisoftGen:Variant.Bulz.510591 (B)
McAfee-GW-EditionGenericRXKE-TZ!B98B87ABF1B1
FireEyeGeneric.mg.d288b2ccf9bcbb5c
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.Upatre
GDataGen:Variant.Bulz.510591
JiangminTrojan.Agent.cocc
Antiy-AVLTrojan/Generic.ASMalwS.3069C19
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.CoinMiner.R335459
McAfeeGenericRXKE-TZ!B98B87ABF1B1
MAXmalware (ai score=80)
VBA32Trojan.Convagent
MalwarebytesMalware.AI.4123723563
SentinelOneStatic AI – Suspicious PE
FortinetW32/CoinMiner.858453!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.cf9bcb
AvastWin32:TrojanX-gen [Trj]

How to remove Bulz.510591?

Bulz.510591 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment