Malware

What is “Bulz.390903”?

Malware Removal

The Bulz.390903 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.390903 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Bulz.390903?


File Info:

crc32: C0CA4100
md5: 6fe8ab0b7d714c54ffb4c724aeb6d18d
name: 6FE8AB0B7D714C54FFB4C724AEB6D18D.mlw
sha1: b227e11160d82add7bcd173c18683016a71fc75e
sha256: ba0bc680cff76f569d94608ec973a70100e7de49988fbe640e52173655b4374d
sha512: 4ec5e9e30e50de434d32e4881912f1e5a7e51d7bc72f4667efd5d20d44bd1a3629c942fb1c0fb0833febc0153afdd91ce37bc9d3f2e55ef147adb872f5d8cf8e
ssdeep: 49152:tkRDUwzMO/aYfjoe9wu04MYs89HcKrZ2Q:mRD+OiYfjoe9JMYsA8GZ2Q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 - 2021
Assembly Version: 1.0.0.0
InternalName: Ntx644x632x9996EGx6a9qo.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Restaurant Manager
ProductVersion: 1.0.0.0
FileDescription: Restaurant Manager
OriginalFilename: Ntx644x632x9996EGx6a9qo.exe

Bulz.390903 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.InjectNET.14
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.390903
CylanceUnsafe
SangforTrojan.Win32.Save.a
ESET-NOD32a variant of MSIL/Kryptik.ZXP
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Bulz.390903
MicroWorld-eScanGen:Variant.Bulz.390903
Ad-AwareGen:Variant.Bulz.390903
SophosML/PE-A
TrendMicroTROJ_GEN.R06CC0DCB21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.6fe8ab0b7d714c54
EmsisoftGen:Variant.Bulz.390903 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:MSIL/AgentTesla.MXB!MTB
ArcabitTrojan.Bulz.D5F6F7
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
GDataGen:Variant.Bulz.390903
AhnLab-V3Malware/Win32.RL_Generic.C4368059
McAfeePWS-FCWJ!6FE8AB0B7D71
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R06CC0DCB21
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ZXG!tr
AVGWin32:RATX-gen [Trj]
Qihoo-360HEUR/QVM03.0.E09F.Malware.Gen

How to remove Bulz.390903?

Bulz.390903 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment