Malware

What is “Bulz.546307”?

Malware Removal

The Bulz.546307 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.546307 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Bulz.546307?


File Info:

crc32: 13CF3D9C
md5: 5101dd8570be3323cac97dbe6a102fd8
name: 5101DD8570BE3323CAC97DBE6A102FD8.mlw
sha1: 916643998253b88fb55e5e3ae619e0adc57e82fe
sha256: 2393fe8156f1487062c000d3be72fb90261835a4cdf0feaf44d6704ccd7b6a26
sha512: 27b1d46c94a8d6b57245cc3dc745616d290352e8d5e81a18cc56da5ff016d922c045b08255ebb5c8113514ce277e1d624cb42337843d3bab453c976051b05ff1
ssdeep: 768:6PmrXgett2Af2TNjMTfJ+0IxK/xtbYSIiWeEcfwg/nPe254mu5:9bggkpTNQ74lM/3I7rg/n2zmu5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: ems.exe
FileVersion: 1.0.0.0
ProductName: ems
ProductVersion: 1.0.0.0
FileDescription: ems
OriginalFilename: ems.exe

Bulz.546307 also known as:

K7AntiVirusTrojan ( 0052551c1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.546307
CylanceUnsafe
SangforTrojan.MSIL.OKZ.ed
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052551c1 )
Cybereasonmalicious.570be3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.OKZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.MSIL.Bladabindi.aldj
BitDefenderGen:Variant.Bulz.546307
NANO-AntivirusTrojan.Win32.Bladabindi.exouad
MicroWorld-eScanGen:Variant.Bulz.546307
TencentMsil.Backdoor.Bladabindi.Srcz
Ad-AwareGen:Variant.Bulz.546307
SophosMal/Generic-S
ComodoMalware@#3ajbxf9o999rh
BitDefenderThetaGen:NN.ZemsilF.34294.cm0@amnEAmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.czf
FireEyeGeneric.mg.5101dd8570be3323
EmsisoftGen:Variant.Bulz.546307 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1124765
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Bulz.546307
AhnLab-V3Trojan/Win32.RL_Bladabindi.C3598989
McAfeeGeneric.czf
MAXmalware (ai score=89)
VBA32Backdoor.MSIL.Bladabindi
PandaTrj/GdSda.A
YandexBackdoor.Bladabindi!k25Mfpi6FbU
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.BNOI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.546307?

Bulz.546307 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment