Malware

Should I remove “Bulz.653113”?

Malware Removal

The Bulz.653113 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.653113 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Bulz.653113?


File Info:

name: 128208543D5DB8846D4D.mlw
path: /opt/CAPEv2/storage/binaries/8c1202b37d39aa5e2ee6bb07a439bccf946e24b7e67668f99af34863cd9f1126
crc32: AF61811A
md5: 128208543d5db8846d4dc16b499ab365
sha1: 6fc8f59c43be8111f956a0406aca01867d96ee19
sha256: 8c1202b37d39aa5e2ee6bb07a439bccf946e24b7e67668f99af34863cd9f1126
sha512: d1286cc91cc9f46092faff346b943a442d4c02e908e03061fa22ee324751d68e27ba72b1cf22c933a189719f5f3cbab555d24a5bf693ad86ef8a413c6b1c8928
ssdeep: 196608:ggyud1UVERj/KkHLhsaoLdLzl/Eqn5Z7Gn3fOxUgOsmjpglj8:ggyubBRbKOtdoL5l/Eqn5o3fOmnu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138C63374DB42E844F3125E326B3E6CD929C6ECBE01641B6D2742753F5AB7CB1822C7A4
sha3_384: 48b2eaea09abca55d7edb389ca4bbac9a1fde61c1c0d6bfc20f0f3aebf5937a20b1469836fe3b0c60eb937b42fe05725
ep_bytes: 68232ee31be8ef400800cd016823e67e
timestamp: 2013-03-29 05:26:44

Version Info:

FileVersion: 1.0.0.0
FileDescription: 湿
ProductName: 湿
ProductVersion: 1.0.0.0
CompanyName: 湿
LegalCopyright: 湿了
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Bulz.653113 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Bulz.653113
FireEyeGeneric.mg.128208543d5db884
SkyhighBehavesLike.Win32.Generic.wc
ALYacGen:Variant.Bulz.653113
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusAdware ( 004b942f1 )
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.c43be8
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Packed.F potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderGen:Variant.Bulz.653113
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Bulz.653113
EmsisoftGen:Variant.Bulz.653113 (B)
VaristW32/SuspPack.BQ.gen!Eldorado
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Bulz.D9F739
GDataGen:Variant.Bulz.653113
GoogleDetected
McAfeeGeneric FakeAV.iv
MAXmalware (ai score=88)
VBA32Trojan.Crypt
Cylanceunsafe
RisingTrojan.Generic@AI.94 (RDML:8FlpmyxrwAiRLqS0QDOJyQ)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
BitDefenderThetaGen:NN.ZexaF.36792.@J0@ayJUxolb
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Bulz.653113?

Bulz.653113 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment