Malware

How to remove “Bulz.638077”?

Malware Removal

The Bulz.638077 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.638077 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.638077?


File Info:

crc32: 04ACBC4A
md5: 5280eee416fbb8fef2a0b4ef5628c428
name: 5280EEE416FBB8FEF2A0B4EF5628C428.mlw
sha1: 56ec6ffaa4fe49f8941aa6c8efb0894a7bd45f04
sha256: c72d36b0acc4578b43e6be5563e6fb365e7a559a6559811dbf5048fa2798fafe
sha512: f694a884b4ff1691ba302ca98ac3f5cb233a6e2199a64b51174479f2dac6aa623d595ef1134da5864124a590aeee163162cc3423e883ed7ce18015672a40aa27
ssdeep: 12288:3DKqn3W2F1IAr3fKPpGBuj+4jLEg4uCqKx9lQWH9SFqKe61G/iGJorsQaPclOxR:3+8GQ1isui4jLxaqqSqK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (C) Xavier Roche and other contributors
Assembly Version: 5.0.7.0
InternalName: yoju.exe
FileVersion: 5.0.7.0
CompanyName:
LegalTrademarks:
Comments: WinHTTrack Website Copier, Copy Websites to Your Computer
ProductName: WinHTTrack
ProductVersion: 5.0.7.0
FileDescription: WinHTTrack
OriginalFilename: yoju.exe

Bulz.638077 also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Troj.BJU.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ACNS
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderGen:Variant.Bulz.638077
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34088.Tm0@aqsA8@e
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.5280eee416fbb8fe
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataMSIL.Trojan-Stealer.AgentTesla.UWDRFD
McAfeeArtemis!5280EEE416FB
VBA32CIL.HeapOverride.Heur
MalwarebytesMalware.AI.776618224
TrendMicro-HouseCallTROJ_GEN.F0D1C00HN21
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ABZB!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Bulz.638077?

Bulz.638077 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment