Malware

Bulz.649656 removal

Malware Removal

The Bulz.649656 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.649656 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Bulz.649656?


File Info:

name: 450B9DA86856D080AC13.mlw
path: /opt/CAPEv2/storage/binaries/8307d20ec8952a0776d043330f7170f5dc5729520fab03c4f2fa6dd0b9a5fae1
crc32: 2ED79F5B
md5: 450b9da86856d080ac135db18dcf4182
sha1: b4fa02aa9ff681986c9b229db29413f2c53b55fc
sha256: 8307d20ec8952a0776d043330f7170f5dc5729520fab03c4f2fa6dd0b9a5fae1
sha512: e92890746fa2a9f03a2d45e0f2f2e4279b771a265b1cbf975f37a87f98fbfd6b0a059fc836528f22cc90027981f8c2554eec88f5f53eb7e87d5c70c773c1b698
ssdeep: 12288:nWnQZglim6FsLAajPPEgLYGv24ve/SSSSSSSSSSSSSSSSSgW7HiBv0JfElNd1CyN:nmxEgcGtwIHiBnlNd1Ca
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5352A192B56486DD80EA67D0EF865FCF73F6EC10450858D2A517F9B3CB6D888983B0E
sha3_384: ee3dd7a9f66218b14d101e3d7d87e924b0c4dfa64d8adb93065fa2b69524abb44e0b4b776906f5c4fb02368e4981ac0d
ep_bytes: 558bec6aff6820c8460068f8a1460064
timestamp: 2021-08-26 12:18:07

Version Info:

0: [No Data]

Bulz.649656 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.649656
FireEyeGeneric.mg.450b9da86856d080
ALYacGen:Variant.Bulz.649656
K7AntiVirusTrojan ( 0058214e1 )
K7GWTrojan ( 0058214e1 )
ArcabitTrojan.Bulz.D9E9B8
BitDefenderThetaGen:NN.ZexaF.34294.gzW@aioOe9oi
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HATU
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Bulz.649656
AvastWin32:CrypterX-gen [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Bulz.649656
EmsisoftGen:Variant.Bulz.649656 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1145346
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.13M60MZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R439366
McAfeeArtemis!450B9DA86856
MalwarebytesAdware.DownloadAssistant
APEXMalicious
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_76%
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.649656?

Bulz.649656 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment