Malware

Bulz.110613 removal guide

Malware Removal

The Bulz.110613 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.110613 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Detects Avast Antivirus through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system

How to determine Bulz.110613?


File Info:

crc32: 66D3F559
md5: 9bb4cda11f060935e4708b9e082e1a61
name: 9BB4CDA11F060935E4708B9E082E1A61.mlw
sha1: 8531e513bc881c30e2e25192493866a528a70596
sha256: 1b34eb8148662e0e7c52c0e316f01fd396e72a115d143868bc3cdc474b8ae01e
sha512: 693897aa879a7da719cd012b543a7911485c65388e1197ec504cfca77c86606324d8b2991cb2951a72f63ff78c874abcc3024b9b0229f46ae5fcab25f0acf64e
ssdeep: 1536:80OiqhF9YA8JbVQt6lP+H24iL91SL3WJvI:ciqhbYAYBQcfxL9cLGJw
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: mana.exe.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: mana.exe.exe

Bulz.110613 also known as:

K7AntiVirusTrojan ( 0050f87b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.9031
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.110613
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:MSIL/PasGen.fc49b387
K7GWTrojan ( 0050f87b1 )
Cybereasonmalicious.11f060
CyrenW32/MSIL_Agent.BOZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.AEUM
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Generickdz-6766483-0
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Bulz.110613
MicroWorld-eScanGen:Variant.Bulz.110613
Ad-AwareGen:Variant.Bulz.110613
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34670.gm0@aO34Y9c
TrendMicroTROJ_GEN.R014C0DCH21
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.9bb4cda11f060935
EmsisoftGen:Variant.Bulz.110613 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129530
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/PasGen.YA!MTB
ArcabitTrojan.Bulz.D1B015
AegisLabTrojan.MSIL.Bladabindi.m!c
GDataGen:Variant.Bulz.110613
AhnLab-V3Trojan/Win32.RL_Generic.C4145529
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=85)
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0DCH21
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bladabindi.AEUM!tr.bdr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NjRAT.HwMAi3sA

How to remove Bulz.110613?

Bulz.110613 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment