Home
Terms & Definitions
Parasites List
Categories
Threat Level
Contact Us
Spyware Information
Name: Bulla
Threat Level:
Category: Adware
Aliases: IEPlugin, from the filename of the BHO DLL. This is a generic name; Bulla has nothing to do with the parasite known as IEPlugin

Spyware Characteristics
Description: Bulla is a Browser Helper Object for Internet Explorer. It tries to search all pages you view in IE and replaces banner adverts from the page with adverts from its controlling servers.

Properties:
  • Stays resident in background.
  • Stealth: hides itself from user.
  • Show advertisements.
  • Makes changes to browser settings.

What it does?
Advertising: Yes, Whenever a new page is displayed, Bulla connects to its servers and downloads a piece of JavaScript that searches a document for <iframe>s sized at 468x60 (the typical banner ad size), and replaces them with ads served from ad.bulla.com.

Bulla also sets your home page to 'startpage.ms' the first time it is run.

Privacy violation: Yes, Each connection includes the URL of the page being viewed and a unique ID to allow Bulla to track sites being viewed.

Security issues: None known.
Stability problems: Sometime, The JavaScript currently being served is incompatible with IE4. This might cause JavaScript on targeted pages to stop working and/or spurious error messages to appear.

Method of infection
Some (unconfirmed) reports of Bulla installing through ActiveX drive-by-download on pop-up ad windows.

Removal Instructions
bulletproofsoft.com "Spyware Remover" is the best tool for the removal of this spyware.

Links
Site: http://www.bulla.com/