Malware

How to remove “Bulz.891699”?

Malware Removal

The Bulz.891699 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.891699 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.891699?


File Info:

name: EBDD0A91C8F179A6B72E.mlw
path: /opt/CAPEv2/storage/binaries/98144d8fd982170fa8ae3d38205f74cd91690c1c38704e5378705697509c5de2
crc32: 554D9DE1
md5: ebdd0a91c8f179a6b72e6cffab22d7f7
sha1: 1cc1f0c33e996281d9c04001f864dd8deac63a7e
sha256: 98144d8fd982170fa8ae3d38205f74cd91690c1c38704e5378705697509c5de2
sha512: 3f64d6632d8b2e7f4dbf37243ac276f45b13b058b31297d0e038c187b64dd0dc0d8bd86a22769177ed44af55c593ac96597760c8b6975e79f225ad43bfd1ed16
ssdeep: 98304:paM+M6RkMkIM7zrRokZsNi9Xwgwfo2eUJF3noxD:pKhi9XwgwA232
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1E7068C02F680A072DD2E0E308A65B270F569BC7F7E1D764B6F587A1E2DB31C16925B13
sha3_384: 2a6510c4111c4404816c2b2393deb9b2f5c09f439bdba7ecb3191217f1a8eea4afb6144379b025a055068327d501aa4e
ep_bytes: 4883ec28e85b0200004883c428e97afe
timestamp: 2021-08-11 22:26:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge
FileVersion: 92.0.902.73
InternalName: cookie_exporter_exe
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
OriginalFilename: cookie_exporter.exe
ProductName: Microsoft Edge
ProductVersion: 92.0.902.73
CompanyShortName: Microsoft
ProductShortName: Microsoft Edge
LastChange: cad199e39220991414cd71868a619fff614880c7
Official Build: 1
Translation: 0x0409 0x04b0

Bulz.891699 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.891699
FireEyeGen:Variant.Bulz.891699
ALYacGen:Variant.Bulz.891699
CylanceUnsafe
CyrenW64/Bulz.BT.gen!Eldorado
ClamAVWin.Trojan.Blackie-9865437-0
BitDefenderGen:Variant.Bulz.891699
Ad-AwareGen:Variant.Bulz.891699
EmsisoftGen:Variant.Bulz.891699 (B)
McAfee-GW-EditionBehavesLike.Win64.BadFile.wm
SophosML/PE-A
IkarusTrojan-Dropper.Agent
GDataGen:Variant.Bulz.891699
JiangminPacked.Krap.gvuo
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.349521C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!EBDD0A91C8F1
TrendMicro-HouseCallTROJ_GEN.R03BH09L321
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/PossibleThreat

How to remove Bulz.891699?

Bulz.891699 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment