Malware

How to remove “Bulz.538831”?

Malware Removal

The Bulz.538831 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.538831 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Bulz.538831?


File Info:

name: 59B2EFC585B589716C8C.mlw
path: /opt/CAPEv2/storage/binaries/b2beb71ddc94840a7bfa7a3b77b2ec6062d9a02ba917bb7c6d370540df0671c1
crc32: 4A22EFD2
md5: 59b2efc585b589716c8c53562a1ddb92
sha1: b0b59c729199ac1a4b048981d8dd2f33c9a07f74
sha256: b2beb71ddc94840a7bfa7a3b77b2ec6062d9a02ba917bb7c6d370540df0671c1
sha512: 032513bebb022464f1354542da9beecd8394cc46af173933d3f6bce4b61e395e7d4b94a54e5a588585a0ea59e76e9e153ce16d7ea8f00a173b23feb8e85a750b
ssdeep: 1536:wcg14RkiRT+ZURnOAbt6BEKJQ5wsKMZZpcIY1zJlE9QFCjk6YSXMgH5:wcRVRTlnzcEKqWAcI4JlkQFCjk6qgZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D642C11D344A8A4E32309FA886E97DA3F0967C8CF64D6E7A7C1D7F110B1DE2749391A
sha3_384: 5c3c28ee2c32f11d9478f6f334e62b183cf80224759b631a661d80062a84a57e4792fb2f6c311532885bfbc5b29b8133
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-23 14:00:33

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Nishant Sivakumar
FileDescription: TypeDescriptionProviderDemo
FileVersion: 5.66.0.7716
InternalName: visa-application1.exe
LegalCopyright: Copyright © 2008
OriginalFilename: visa-application1.exe
ProductName: TypeDescriptionProviderDemo
ProductVersion: 5.66.0.7716
Assembly Version: 0.0.0.0

Bulz.538831 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.538831
CAT-QuickHealBackdoor.MsilFC.S23216835
ALYacGen:Variant.Bulz.538831
Cybereasonmalicious.585b58
CyrenW32/MSIL_Kryptik.AYJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.XBC
APEXMalicious
ClamAVWin.Packed.Razy-9863149-0
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderGen:Variant.Bulz.538831
Ad-AwareGen:Variant.Bulz.538831
SophosML/PE-A
DrWebTrojan.DownLoader33.58755
McAfee-GW-EditionPWS-FCRS!59B2EFC585B5
FireEyeGeneric.mg.59b2efc585b58971
EmsisoftTrojan-Spy.Agent (A)
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Bulz.538831
AviraTR/Dropper.MSIL.Gen
ArcabitTrojan.Bulz.D838CF
MicrosoftBackdoor:MSIL/Bladabindi.RKC!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Korat.R341547
McAfeePWS-FCRS!59B2EFC585B5
MalwarebytesTrojan.MalPack
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/CoinMiner.ESXT!tr
BitDefenderThetaGen:NN.ZemsilF.34294.tm0@aq00XC
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.538831?

Bulz.538831 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment