Malware

Should I remove “Bulz.639589”?

Malware Removal

The Bulz.639589 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.639589 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Bulz.639589?


File Info:

name: 97CB066CD2FF8FADDF9B.mlw
path: /opt/CAPEv2/storage/binaries/d80a5dabb65513ebac365a865fc294dbc9e548b15d2dd514b70851ed1bed19a4
crc32: B310B8FF
md5: 97cb066cd2ff8faddf9bc138b4ff338e
sha1: c7d52b3c7908517cddb827ebf25e61a16a834154
sha256: d80a5dabb65513ebac365a865fc294dbc9e548b15d2dd514b70851ed1bed19a4
sha512: 6af81275ee6d09ad3b8d056ecbfe5573a711e6b1940af50b396e18f43643b80d09bf0575131c1e09ed121277e9b3fdbba9b3dda66eddb2740366a623b846ccf5
ssdeep: 768:uNBjNOYjRrR9w5W5m/kd7cl7IkrY6M+rIjKV4y5:6YYlwU5G4707Y6M+rIO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D9431A9873E79CD7E612163D75DBE379263CE5B04A4747037BF0BE3A4B126C42A89602
sha3_384: 19037a64133ebe0bfb15775f326a40a2ef9dd5ada2f60e9bffbd6e587aa19eda6de51ccd02f751a830c0bae2f0ee9c08
ep_bytes: 5589e557565383ec1c8b5d0c8b75088b
timestamp: 2015-01-05 11:27:09

Version Info:

0: [No Data]

Bulz.639589 also known as:

LionicTrojan.Win32.Inject.4!c
MicroWorld-eScanGen:Variant.Bulz.639589
FireEyeGen:Variant.Bulz.639589
SkyhighBehavesLike.Win32.Infected.qm
McAfeeArtemis!97CB066CD2FF
Cylanceunsafe
VIPREGen:Variant.Bulz.639589
SangforTrojan.Win32.Inject.8
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.BSSK
KasperskyTrojan.Win32.Inject.sbkm
BitDefenderGen:Variant.Bulz.639589
NANO-AntivirusTrojan.Win32.Inject.dlwzoe
AvastWin32:Injector-CJL [Trj]
TencentMalware.Win32.Gencirc.13bbc8a2
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.A.13578
ZillyaTrojan.Inject.Win32.179634
EmsisoftGen:Variant.Bulz.639589 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Inject.ed
GoogleDetected
AviraTR/Dropper.A.13578
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumMalware@#1jtyvgmw3mjxh
ArcabitTrojan.Bulz.D9C265
ZoneAlarmTrojan.Win32.Inject.sbkm
GDataGen:Variant.Bulz.639589
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Gen
ALYacGen:Variant.Bulz.639589
MAXmalware (ai score=88)
VBA32Trojan.Inject
RisingTrojan.Inject!8.103 (TFE:1:jyZMQvgs1xV)
YandexTrojan.GenAsa!8gB6PTzYbmw
MaxSecureTrojan.Malware.7956961.susgen
FortinetW32/Inject.BSSK!tr
AVGWin32:Injector-CJL [Trj]
DeepInstinctMALICIOUS

How to remove Bulz.639589?

Bulz.639589 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment