Malware

Bulz.801065 removal instruction

Malware Removal

The Bulz.801065 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.801065 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Bulz.801065?


File Info:

name: 1D8562C0ADCAEE734D63.mlw
path: /opt/CAPEv2/storage/binaries/92730427321a1c4ccfc0d0580834daef98121efa9bb8963da332bfd6cf1fda8a
crc32: 3178C2EB
md5: 1d8562c0adcaee734d63f7baaca02f7c
sha1: be138820e72435043b065fbf3a786be274b147ab
sha256: 92730427321a1c4ccfc0d0580834daef98121efa9bb8963da332bfd6cf1fda8a
sha512: b3b6ffcec5cd79fcfc647956845f3ae59af1a9bf1d12896d8d8512d4728c894f87760954b5a46df282fd5d7b067f7a8455cd1bd4a54e276402c6849ad50f2c23
ssdeep: 192:BR5KeZxKpjjHo3ugzjOkRKbyWkU7gwDR2FGV7E5pz67VSNI:BjqVH8uejrkbhkP5FGV78N
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DF428D03F6D00FB1DF240579303796A5C0BBB2516EE197236BD214850E762E2F43316E
sha3_384: 2f86e78374618ca00e09aacaa50ed460d0789598f822b5665df2568f215842d1e9144b304860b85fc26998557edf7f70
ep_bytes: e8c4030000e974feffff558bec6a00ff
timestamp: 2021-09-04 18:11:12

Version Info:

0: [No Data]

Bulz.801065 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.1d8562c0adcaee73
McAfeeArtemis!1D8562C0ADCA
CylanceUnsafe
VIPREGen:Variant.Bulz.801065
SangforTrojan.Win32.SelfDel.Vv0z
AlibabaTrojan:Win32/SelfDel.8551fe3c
Cybereasonmalicious.0e7243
CyrenW32/ABRisk.WXPJ-7017
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.BKM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.SelfDel.gen
BitDefenderGen:Variant.Bulz.801065
MicroWorld-eScanGen:Variant.Bulz.801065
AvastWin32:Malware-gen
TencentWin32.Trojan.Selfdel.Eaxp
Ad-AwareGen:Variant.Bulz.801065
EmsisoftGen:Variant.Bulz.801065 (B)
DrWebTrojan.MulDrop19.15754
ZillyaDownloader.Small.Win32.140841
TrendMicroTROJ_GEN.R002C0WHH22
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Bulz.801065
JiangminTrojan.Jobutyve.i
AviraTR/DelFiles.vdmja
Antiy-AVLTrojan/Generic.ASMalwS.2162
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Bulz.DC3929
ZoneAlarmHEUR:Trojan.Win32.SelfDel.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4738248
ALYacGen:Variant.Bulz.801065
MAXmalware (ai score=84)
VBA32Trojan.SelfDel
MalwarebytesTrojan.SelfDelete
TrendMicro-HouseCallTROJ_GEN.R002C0WHH22
RisingTrojan.Generic@AI.82 (RDMK:NbK1GIYed+0Rno9WCH4TSQ)
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.801065?

Bulz.801065 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment