Malware

Bulz.576570 information

Malware Removal

The Bulz.576570 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.576570 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Bulz.576570?


File Info:

crc32: 99D766A1
md5: 98242642602784762aae6bce60751bd8
name: 98242642602784762AAE6BCE60751BD8.mlw
sha1: 3148d3948010b7cfb865800f3f3b03118b9bb5d6
sha256: 1a127362f2bb3e8138398abe7957670acabf6ddec44b826227bde48120ca230f
sha512: 0fa82fc191b1281d47292635d089b15e1a75b5d39b84f9ba29b4e52e03ddc3c36ddc4914bbef0204d148a4592d166ee5730d2dcfbe5d065c5aa8b66f5eb64098
ssdeep: 6144:twu9veLLqxB3sBdig09vcyKOw99d5ba7QlUQmYdWCHvsX8mOGxM5VPjb8bg:Jk/oYdiHvb9wTLbIGUCouvucbb80
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: KIrv
FileVersion: 9.16.0003
CompanyName: CPNIGa AfKia HQ70Dzb
Comments: JN5r0Yf05 SaS EL8CRN
ProductName: JN5r0Yf05 SaS EL8CRN
ProductVersion: 9.16.0003
FileDescription: FNz WHt5bBl Ou
OriginalFilename: KIrv.exe

Bulz.576570 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusEmailWorm ( 003c363a1 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.576570
MalwarebytesMachineLearning/Anomalous.96%
ZillyaDropper.VB.Win32.52490
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.48010b
BitDefenderThetaGen:NN.ZevbaF.34236.Bm0@a4t3Hjki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.TRW
APEXMalicious
AvastWin32:VBCrypt-BCO [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.VB.drrk
BitDefenderGen:Variant.Bulz.576570
NANO-AntivirusTrojan.Win32.VB2.xxiog
MicroWorld-eScanGen:Variant.Bulz.576570
TencentWin32.Trojan-Dropper.Vb.cfqa
Ad-AwareGen:Variant.Bulz.576570
SophosMal/Generic-S
ComodoMalware@#3tmox4y80km69
DrWebTrojan.Siggen7.20605
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gc
FireEyeGeneric.mg.9824264260278476
EmsisoftGen:Variant.Bulz.576570 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2765A96
KingsoftWin32.Heur.KVM001.a.(kcloud)
SUPERAntiSpywareTrojan.Agent/Gen-FalDesc
ZoneAlarmTrojan-Dropper.Win32.VB.drrk
GDataGen:Variant.Bulz.576570
AhnLab-V3Trojan/Win32.VB.C2320961
Acronissuspicious
McAfeeArtemis!982426426027
MAXmalware (ai score=82)
VBA32TrojanDropper.VB
PandaGeneric Malware
YandexTrojan.DR.VB!s4Q6j0VbYJI
IkarusTrojan.Win32.Vilsel
FortinetW32/Vilsel.TET!tr
AVGWin32:VBCrypt-BCO [Trj]
Paloaltogeneric.ml

How to remove Bulz.576570?

Bulz.576570 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment