Malware

Bulz.38965 removal guide

Malware Removal

The Bulz.38965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.38965 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Bulz.38965?


File Info:

name: 24F63FAEC4C15173532F.mlw
path: /opt/CAPEv2/storage/binaries/6d887b00c16e98f2c6420a6b745c7ba7c4eaa906dd822b50dcbf2df58d394a2e
crc32: 036E2708
md5: 24f63faec4c15173532f67623165034e
sha1: 480ecf873543995c13d2ac8f6fc5ecea44e5cccc
sha256: 6d887b00c16e98f2c6420a6b745c7ba7c4eaa906dd822b50dcbf2df58d394a2e
sha512: 8d3becc976393bb90137e3f4f8b62fc224c88fd7e37d10e249a560cb15fe8b8c0289268cd358dca4ae5a2683bb8923bf5978cede74eaa9c57c55bc05e9de70b5
ssdeep: 12288:Rn955P1Q8+y0VXTpZRV5sNAYuEXv7dW5W9:J2y0VjpZJOtuqZW5W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9C4AD3575A8BE72C17E83B6C6851410C7F0E917CB12D649FDB61AAA0E51ACBC83F139
sha3_384: 830cae22124afd62c2d334b9e6ec3e2675dc8f11b4d1e6e8666c69d371426261453a95b87477c859bb4e02302708d0e6
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-10-06 09:38:59

Version Info:

0: [No Data]

Bulz.38965 also known as:

MicroWorld-eScanGen:Variant.Bulz.38965
FireEyeGeneric.mg.24f63faec4c15173
ALYacGen:Variant.Bulz.38965
CylanceUnsafe
SangforTrojan.Win32.Occamy.C6D
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:MSIL/Generic.bdb5eac7
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZemsilF.34638.Km0@auroCIf
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-5474415-0
BitDefenderGen:Variant.Bulz.38965
NANO-AntivirusTrojan.Win32.Crypt.emubec
TencentMsil.Trojan.Crypt.Htco
Ad-AwareGen:Variant.Bulz.38965
SophosMal/Generic-R
ZillyaAdware.BrowseFox.Win32.139947
McAfee-GW-EditionGenericRXOL-AQ!24F63FAEC4C1
EmsisoftGen:Variant.Bulz.38965 (B)
IkarusTrojan.Crypt
JiangminTrojan/Generic.bhurk
WebrootW32.Adware.Gen
KingsoftWin32.Troj.Crypt.cz.(kcloud)
MicrosoftTrojan:Win32/Occamy.C6D
GDataGen:Variant.Bulz.38965
CynetMalicious (score: 100)
McAfeeGenericRXOL-AQ!24F63FAEC4C1
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Crypt
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.ec4c15
PandaTrj/CI.A

How to remove Bulz.38965?

Bulz.38965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment