Malware

Bulz.911903 (B) removal instruction

Malware Removal

The Bulz.911903 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.911903 (B) virus can do?

  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Bulz.911903 (B)?


File Info:

name: 46328338391F634513F1.mlw
path: /opt/CAPEv2/storage/binaries/09edc1bb451e18f5be97d0ba57aa69e921f9eab38bd434a8f3ffdf857d7b2743
crc32: 9E4E8628
md5: 46328338391f634513f18bfd7abfabde
sha1: b1200e939b79d91216ca1efe3ada6c1845d4ca12
sha256: 09edc1bb451e18f5be97d0ba57aa69e921f9eab38bd434a8f3ffdf857d7b2743
sha512: 8319be8da24a1421ed266865a6243239e67e84d54e7ecddeeb2b985424ea3eb6d4615b25de60d01731a33bd7eb0dc1112a1171870f1f5fb0bbeaa1d430a91205
ssdeep: 1536:FKmGP2DbETxa9ExkF2uhSqSjyc3hl1jsLPhyt:rGODbUxH/uh2jyehsLPst
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1E9D34935B2856512E9860378C481F34BF737BCC96E66221644DE730D3EFAB94E58C2E9
sha3_384: 1cf58c9b549195dab69033b42e7e6e70d0ced2985e907b1b9eaa86419d3898e61a017a577481e72a1d7889c24c8c90f3
ep_bytes: 40534883ec20488bd9e88a050000488b
timestamp: 2100-03-02 06:33:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Client Server Runtime Process
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: CSRSS.Exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CSRSS.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Bulz.911903 (B) also known as:

LionicTrojan.Win32.Bulz.4!c
MicroWorld-eScanGen:Variant.Bulz.911903
FireEyeGen:Variant.Bulz.911903
ALYacGen:Variant.Bulz.911903
CylanceUnsafe
CyrenW64/Ipamor.CZ.gen!Eldorado
Paloaltogeneric.ml
ClamAVWin.Malware.Mepaow-6725393-0
BitDefenderGen:Variant.Bulz.911903
Ad-AwareGen:Variant.Bulz.911903
EmsisoftGen:Variant.Bulz.911903 (B)
McAfee-GW-EditionArtemis
GDataGen:Variant.Bulz.911903
Antiy-AVLTrojan/Generic.ASVirus.302
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!46328338391F
MAXmalware (ai score=80)
IkarusTrojan.Dropper
FortinetW64/Bulz.9212!tr
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Bulz.911903 (B)?

Bulz.911903 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment