Malware

How to remove “Bulz.637531”?

Malware Removal

The Bulz.637531 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.637531 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Bulz.637531?


File Info:

name: 96A57994DAC844201DA0.mlw
path: /opt/CAPEv2/storage/binaries/9353cf6347377bf1194349bff4001485fac99a5cd3ee03781e81c157452dae68
crc32: 8785F7EF
md5: 96a57994dac844201da03003ee2183ae
sha1: e7cd1448b9b33c928b25451a9f72de71b2dbc7bf
sha256: 9353cf6347377bf1194349bff4001485fac99a5cd3ee03781e81c157452dae68
sha512: 5f82aa92a1f15287884bc7fcb26f7b0bcf2db0444417c678e613c46f0c9da0833845ca1fefc10ea35ec58ad6d7c9c627081bdf94915e41f136b6abdf3e6cf6de
ssdeep: 196608:wnHdJmVsyb49UuImXz1neX38DXDQ9/tbYPvbJQlHPrO2SvMTvN8CTJ+iGydotQa1:wnHdJmVsU4izm10MDTQ9/kJQlvrJTLxG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131C6333FF6624462C0E3173EB9B4D4765829AD346B39296B4FC83CF668734D1E638A05
sha3_384: f837f29202543d3686518e913cd758d15e62133382f965d97d0354b56aebc9711b24c723626edcc0e9288eefe636e947
ep_bytes: e8a0040000e97afeffff558bec6a00ff
timestamp: 2021-08-01 04:40:34

Version Info:

0: [No Data]

Bulz.637531 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.637531
McAfeeArtemis!96A57994DAC8
CylanceUnsafe
ZillyaTrojan.Disco.Win64.61
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 00561f361 )
BitDefenderGen:Variant.Bulz.637531
K7GWTrojan ( 00561f361 )
Cybereasonmalicious.4dac84
ArcabitTrojan.Bulz.D9BA5B
CyrenPYC/Filecoder.A.gen!Camelot
SymantecRansom.Raasnet
ESET-NOD32Python/Filecoder.DM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Almi_Filecoder.f
RisingRansom.Agent!1.D430 (CLASSIC)
Ad-AwareGen:Variant.Bulz.637531
EmsisoftGen:Variant.Bulz.637531 (B)
ComodoMalware@#3ay1gal83fejv
VIPREGen:Variant.Bulz.637531
TrendMicroTROJ_GEN.R002C0PHL21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.96a57994dac84420
SophosMal/Generic-S
WebrootW32.Malware.Gen
AviraTR/Ransom.bimvh
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GDataWin32.Trojan.PSE.11JYQR4
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.InfoStealer.C4605050
BitDefenderThetaGen:NN.ZexaF.34582.@xZ@aOtRAOb
ALYacTrojan.Ransom.Python
MAXmalware (ai score=85)
VBA32Trojan.Sabsik.FL
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PHL21
TencentWin32.Trojan.Generic.Huph
YandexTrojan.Agent!LVBNgczB/WU
MaxSecureTrojan.Malware.7164915.susgen
FortinetPython/Filecoder.DM!tr.ransom
AVGMulti:Filecoder-H [Trj]
AvastMulti:Filecoder-H [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.637531?

Bulz.637531 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment