Malware

How to remove “Bulz.49339 (B)”?

Malware Removal

The Bulz.49339 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.49339 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
discord.com
cdn.discordapp.com

How to determine Bulz.49339 (B)?


File Info:

crc32: F4B6F437
md5: fe5446b7bad5ccddc411dd35a9607d77
name: FE5446B7BAD5CCDDC411DD35A9607D77.mlw
sha1: 1c487b3d275a1e931cb3d10bd9a345a09dc35340
sha256: 1e91dc39314361fd45321a8adc28435467ad1167ee0cc646f77946b522b9efe3
sha512: 803bb99fa256d1e932993f6f671d22bf927e0e6fa3ad412401cb52542775c8370f7d3f4a4a74d1e8f89b7642882e0bd0c0d3392af834421cd835d2f333953e9a
ssdeep: 49152:LR/ovVcOM1pJTYBzQ0DZVhlZfyiSCyiSV/CznFw9:LRmi/YBzZDZVLpi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Bulz.49339 (B) also known as:

MicroWorld-eScanGen:Variant.Bulz.49339
McAfeeFareit-FZO!FE5446B7BAD5
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Variant.Bulz.49339
K7GWVirus ( 7000000f1 )
K7AntiVirusVirus ( 7000000f1 )
ArcabitTrojan.Bulz.DC0BB
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Injects.gen
AlibabaTrojanDownloader:Win32/Fareit.5a478533
AvastWin32:RATX-gen [Trj]
RisingDownloader.Delf!8.16F (TFE:2:23m1oTwB2LE)
Ad-AwareGen:Variant.Bulz.49339
EmsisoftGen:Variant.Bulz.49339 (B)
TrendMicroTrojanSpy.Win32.WACATAC.USMANKP20
McAfee-GW-EditionFareit-FZO!FE5446B7BAD5
FireEyeGeneric.mg.fe5446b7bad5ccdd
SophosMal/Generic-S
IkarusWin32.Outbreak
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Injects.gen
GDataGen:Variant.Bulz.49339
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R347077
ALYacGen:Variant.Bulz.49339
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack.SMY.Generic
ESET-NOD32Win32/TrojanDownloader.Delf.DCE
TrendMicro-HouseCallTrojanSpy.Win32.WACATAC.USMANKP20
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_94%
FortinetW32/Delf.DCE!tr.dldr
BitDefenderThetaGen:NN.ZelphiCO.34658.jI3@aGLArXfi
AVGWin32:RATX-gen [Trj]
PandaTrj/RnkBend.A
Qihoo-360Generic/Trojan.b75

How to remove Bulz.49339 (B)?

Bulz.49339 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment