Malware

Bulz.581070 removal guide

Malware Removal

The Bulz.581070 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.581070 virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Bulz.581070?


File Info:

name: 5BCAFF686B75185902DA.mlw
path: /opt/CAPEv2/storage/binaries/6134c653bc93da301c51b8b1de12f61b8d7d39457f9c7bf2a1dd0c0b32d72df1
crc32: C6D0E02C
md5: 5bcaff686b75185902da89471682d94c
sha1: 4f34e634602c44d9435bcb19e655a6b66222a549
sha256: 6134c653bc93da301c51b8b1de12f61b8d7d39457f9c7bf2a1dd0c0b32d72df1
sha512: e89e0efd5c8754f10b351c552e6c2aa5d777b4ebbb2dbf8bf0075396da72c71eeebcc3ef28f6425034abab2f59d341b49f3533939d4cd768acf233a02af91bc1
ssdeep: 3072:/u0anFTbWcXzEC11AMZDRxdzFpGpuDa9u7a/ThxEzwCIbRdNfZ:/ebaBcWhxVCIJf
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T13804294D0B94E98EC2205C3E37E6D618C97C85A54DAFC1835DA725C5FDBAFCC79022A8
sha3_384: c6f778b143d53d77dd7656c2ea855f7dcd1c70b078b7e7535f6804a7c17e7b5cfb1e568cf02a4971ee35c0a35da9529a
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2055-01-02 05:14:08

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsFormsApp1
FileVersion: 1.0.0.0
InternalName: WindowsFormsApp1.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: WindowsFormsApp1.exe
ProductName: WindowsFormsApp1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.581070 also known as:

LionicTrojan.Win32.Bulz.4!c
DrWebTrojan.Siggen15.60762
MicroWorld-eScanGen:Variant.Bulz.581070
FireEyeGen:Variant.Bulz.581070
McAfeeArtemis!5BCAFF686B75
AlibabaTrojanSpy:MSIL/Bobik.30559188
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.MRNEXLS
TrendMicro-HouseCallTROJ_GEN.R002H09L321
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Bobik.gen
BitDefenderGen:Variant.Bulz.581070
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Bulz.581070
EmsisoftGen:Variant.Bulz.581070 (B)
F-SecureTrojan.TR/Spy.Bobik.igrde
McAfee-GW-EditionArtemis
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataGen:Variant.Bulz.581070
AviraTR/Spy.Bobik.igrde
ArcabitTrojan.Bulz.D8DDCE
MicrosoftRansom:MSIL/HiddenTear.TH!MTB
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.581070
MAXmalware (ai score=88)
FortinetW32/Malicious_Behavior.VEX
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Bulz.581070?

Bulz.581070 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment