Malware

Bulz.272856 removal tips

Malware Removal

The Bulz.272856 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.272856 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Bulz.272856?


File Info:

crc32: C1DDDC97
md5: 5c3391abe27b8b9d695b1b2721216c47
name: 5C3391ABE27B8B9D695B1B2721216C47.mlw
sha1: 01ba7621bae41caac8dcd6a1eb8bbe781c85ba50
sha256: 1263343e981ec96605ec6b87e96b8cbdaec754f5ca1feef592c74e187e00f981
sha512: 94aac6a1e873dfc1f045383c9169e606f8be89843dfe53398c1c6e94c75829d4e8e820de5d86e9a05d7c2700cb0895e83f09564f2c60fa9a9bc03343fd750daf
ssdeep: 24576:bax7fTvjterhbiPYe46TnGgZhOSW35He1t7:w7fTZelIGKhOSsQ7
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: xa9 1997-2013,2014, Thomas E. Dickey
InternalName: setup-Lynx-2.8.8rel.2.exe
FileVersion: 2.8.8rel.2
CompanyName: http://lynx.isc.org
Comments: This installer was built with NSIS and cross-compiling to MinGW.
ProductName: Lynx
ProductVersion: 2.8.8rel.2
FileDescription: Lynx Installer (MinGW)
Translation: 0x0409 0x04b0

Bulz.272856 also known as:

K7AntiVirusTrojan ( 0055e4081 )
LionicTrojan.Win32.Shade.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.272856
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e4081 )
Cybereasonmalicious.be27b8
SymantecRansom.Troldesh
ESET-NOD32NSIS/Injector.IP
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Shade.lba
BitDefenderGen:Variant.Bulz.272856
NANO-AntivirusTrojan.Win32.Encoder.eikqdn
MicroWorld-eScanGen:Variant.Bulz.272856
TencentWin32.Trojan.Shade.Swkx
Ad-AwareGen:Variant.Bulz.272856
SophosMal/Generic-R + Mal/Miuref-L
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_NSISRansom.SM001
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.5c3391abe27b8b9d
EmsisoftGen:Variant.Bulz.272856 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Ransom
AviraTR/Dropper.Gen
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Ranscrape
SUPERAntiSpywareRansom.FIleCryptor/Variant
GDataGen:Variant.Bulz.272856
AhnLab-V3Trojan/Win32.Cerber.R189810
McAfeeArtemis!5C3391ABE27B
MAXmalware (ai score=88)
PandaTrj/CI.A
TrendMicro-HouseCallRansom_NSISRansom.SM001
FortinetW32/Injector.IP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.272856?

Bulz.272856 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment