Malware

Should I remove “Bulz.58245”?

Malware Removal

The Bulz.58245 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.58245 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Bulz.58245?


File Info:

crc32: F15C2575
md5: bf060265a3a752dc0e804c529af8a310
name: BF060265A3A752DC0E804C529AF8A310.mlw
sha1: a6ad38377a6006f15d39ec537f37b830a39ef6c1
sha256: 8c29823a0921ee9f24b4d4ff25f132a18e710848e7f3390bc7b33b30e8245805
sha512: 7117cf734342903b1f89a595b8690fefeaccf47d5db310817b7bccec389240b9c408aa48457498f485970c54d0f4e4f4505418cfb084cfb5963e465522ece283
ssdeep: 192:Yd4daMUPYYmkuZmlZhFsRQieATFK8SYDjr0:WYHku+FsRsAKcXr
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: BTC Clipper.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: svchost.exe
ProductVersion: 1.0.0.0
FileDescription: svchost.exe
OriginalFilename: BTC Clipper.exe

Bulz.58245 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.7
MicroWorld-eScanGen:Variant.Bulz.58245
FireEyeGeneric.mg.bf060265a3a752dc
ALYacGen:Variant.Bulz.58245
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Bulz.58245
K7GWTrojan ( 700000121 )
Cybereasonmalicious.5a3a75
BitDefenderThetaGen:NN.ZemsilF.34590.am0@aGtgf!o
CyrenW32/MSIL_Troj.AGP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
AlibabaTrojanBanker:MSIL/ClipBanker.e2a54be2
NANO-AntivirusTrojan.Win32.ClipBanker.ilqfyv
TencentMsil.Trojan-banker.Clipbanker.Pgcs
Ad-AwareGen:Variant.Bulz.58245
EmsisoftGen:Variant.Bulz.58245 (B)
F-SecureHeuristic.HEUR/AGEN.1137599
TrendMicroTrojanSpy.MSIL.CLIPBANKER.SM
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.MSIL.drf
eGambitUnsafe.AI_Score_94%
AviraHEUR/AGEN.1137599
MAXmalware (ai score=88)
Antiy-AVLTrojan[Banker]/MSIL.ClipBanker
MicrosoftTrojan:MSIL/ClipBanker.GD!MTB
ArcabitTrojan.Bulz.DE385
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataMSIL.Trojan-Stealer.ClipBanker.I
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Trojanspy.C4222445
McAfeeArtemis!BF060265A3A7
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.ClipBanker
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/ClipBanker.RC
TrendMicro-HouseCallTrojanSpy.MSIL.CLIPBANKER.SM
RisingTrojan.ClipBanker!8.5FB (CLOUD)
IkarusTrojan.MSIL.ClipBanker
FortinetMSIL/ClipBanker.RC!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/TrojanSpy.ClipBanker.HgIASOsA

How to remove Bulz.58245?

Bulz.58245 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment