Malware

Bulz.49339 removal guide

Malware Removal

The Bulz.49339 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.49339 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.49339?


File Info:

crc32: 3D847D33
md5: e9fd90017f32d76d7fb88b795dc9e125
name: Bfcgnzc_Signed_.exe
sha1: 0b532ff1a932d81ec643a25bde660b05d4cd38b5
sha256: 426a7d5241a207054d695ea06f8133260c2684c5598420954f0fde91a03fe059
sha512: 08fa5a758ca42f6855905aa01ef0b00bd51c63dda50ca328b9935300b351db774e900811726522d97837fdea9c3dbe5ae9d39b073a2fcb2f9d06abe473f3436b
ssdeep: 24576:6vhqvvRCiHXqXK6tDbUKZgMlXIqOUArsqmyiSCyiSVUJEq7zvVJf9w9:60v4iaxTZVhlZfyiSCyiSV/CznFw9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Bulz.49339 also known as:

MicroWorld-eScanGen:Variant.Bulz.49339
CAT-QuickHealTrojan.Wacatac
ALYacGen:Variant.Bulz.49339
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ca9c1 )
BitDefenderGen:Variant.Bulz.49339
K7GWTrojan-Downloader ( 0056ca9c1 )
TrendMicroTROJ_GEN.R03BC0PHN20
BitDefenderThetaGen:NN.ZelphiF.34196.FL3@ae6zzlli
CyrenW32/Trojan.UIUK-5654
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.CZO
APEXMalicious
AlibabaTrojan:Win32/Fareit.fff87dee
NANO-AntivirusTrojan.Win32.Delf.hsnxzl
TencentMalware.Win32.Gencirc.11ace68f
Ad-AwareGen:Variant.Bulz.49339
EmsisoftGen:Variant.Bulz.49339 (B)
ComodoTrojWare.Win32.Genome.yiros@0
F-SecureHeuristic.HEUR/AGEN.1104233
FireEyeGeneric.mg.e9fd90017f32d76d
SophosMal/Generic-S
IkarusTrojan.Inject
AviraHEUR/AGEN.1104233
Antiy-AVLTrojan[Downloader]/Win32.Delf
MicrosoftTrojan:Win32/Ymacco.AA42
ArcabitTrojan.Bulz.DC0BB
ViRobotTrojan.Win32.Z.Delf.1561200
GDataGen:Variant.Bulz.49339
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.R347077
McAfeeFareit-FVP!E9FD90017F32
MAXmalware (ai score=88)
MalwarebytesTrojan.Downloader.DLF
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0PHN20
RisingDownloader.Delf!8.16F (TFE:5:HFvwBZg1xWB)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.DOUH!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/Trojan.b75

How to remove Bulz.49339?

Bulz.49339 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment