Trojan

Trojan.Heur.bu0bsu6yu7db (B) removal instruction

Malware Removal

The Trojan.Heur.bu0bsu6yu7db (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.bu0bsu6yu7db (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Trojan.Heur.bu0bsu6yu7db (B)?


File Info:

crc32: 02EB2B88
md5: c59c8cc5c9c7da8d20d53a1c4a7161b9
name: C59C8CC5C9C7DA8D20D53A1C4A7161B9.mlw
sha1: 19f32411619c89c9ed9d120df46ae52008613b58
sha256: 5cdc5c5ac9c8dab85aa6c1fc0c085fd12aa542b9cf21dd30060982e9b0c7b597
sha512: 90f57eb316ef87d3b88aacc72d81575393b1e03dc3093a8d6a653ffd4e4d6a390ddb4da905cb6eef14d0614da2797f98463fce83cae6387d36d3c56b7f1e8876
ssdeep: 12288:YgBFNnXgEEAwSfxL/2Dc3jDLLmt0LDQewsAjRd:7ZQEZaewsAj
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: AddInProcess.exe
FileVersion: 3.5.21022.8 built by: RTM
CompanyName: Microsoft Corporation
PrivateBuild: DDBLD634
Comments: Flavor=Retail
ProductName: Microsoftxae .NET Framework
ProductVersion: 3.5.21022.8
FileDescription: AddInProcess.exe
OriginalFilename: AddInProcess.exe
Translation: 0x0409 0x04b0

Trojan.Heur.bu0bsu6yu7db (B) also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebWin32.HLLW.Autoruner.547
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.bu0bsu6yu7db
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaWorm:Win32/Ransomware.c7c60842
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5c9c7d
CyrenW32/Patched.FC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:VB-FBX
ClamAVWin.Ransomware.WannaCry-9856297-0
BitDefenderGen:Trojan.Heur.bu0bsu6yu7db
MicroWorld-eScanGen:Trojan.Heur.bu0bsu6yu7db
SophosML/PE-A
BitDefenderThetaAI:Packer.DFF53E5D1C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fujacks.jh
FireEyeGeneric.mg.c59c8cc5c9c7da8d
EmsisoftGen:Trojan.Heur.bu0bsu6yu7db (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.Win32.Autorun.4!c
GDataGen:Trojan.Heur.bu0bsu6yu7db
McAfeeRDN/Autorun.worm.gen
MAXmalware (ai score=89)
VBA32Worm.AutoRun
MalwarebytesGeneric.Trojan.Malicious.DDS
IkarusTrojan.Msil
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.FF47!tr
AVGWin32:VB-FBX
Paloaltogeneric.ml
Qihoo-360Win32/Worm.AutoRun.HgIASWcA

How to remove Trojan.Heur.bu0bsu6yu7db (B)?

Trojan.Heur.bu0bsu6yu7db (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment