Malware

About “Bulz.876520” infection

Malware Removal

The Bulz.876520 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.876520 virus can do?

  • Presents an Authenticode digital signature
  • Anomalous binary characteristics

How to determine Bulz.876520?


File Info:

crc32: 3B0A6E1E
md5: 498d55d266f2070ab8fdfa9e074683c5
name: 498D55D266F2070AB8FDFA9E074683C5.mlw
sha1: 61e42b4afee8d74a4825e8300a2e53ffd6d0df5c
sha256: 7863c6c66947557488a5794879bf918a8130573e6387a5450b41b2cc5419da0d
sha512: 7c54457a42a79bb3afe5f00bc23a473a9e1a4c77a7c3daf644c4a0a6c778d674b679fa2cda45ebf1b5aed8845a74548cd59a41688ad3c787d758ef18574f7ba1
ssdeep: 24576:LRE9RnN+BNRTUN+BNRTMQRljwo4/izRXTOkMtrIceMaFPjkjD29lSz:9uN+DA+DY4takOElMaFLkT
type: PE32+ executable (native) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CSRSS.Exe
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17134.1
FileDescription: Client Server Runtime Process
OriginalFilename: CSRSS.Exe
Translation: 0x0409 0x04b0

Bulz.876520 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.547
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.876520
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaVirus:Win32/Ipamor.ca2b7d26
Cybereasonmalicious.266f20
CyrenW64/Ipamor.CZ.gen!Eldorado
SymantecTrojan.Gen.MBT
AvastWin32:VB-FBX
ClamAVWin.Trojan.Blackie-9838731-0
BitDefenderGen:Variant.Bulz.876520
MicroWorld-eScanGen:Variant.Bulz.876520
Ad-AwareGen:Variant.Bulz.876520
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.DFF53E5D1C
McAfee-GW-EditionBehavesLike.Win64.Pate.tm
FireEyeGen:Variant.Bulz.876520
EmsisoftGen:Variant.Bulz.876520 (B)
JiangminPacked.Krap.gvtl
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Bulz.DD5FE8
GDataGen:Variant.Bulz.876520
McAfeeArtemis!498D55D266F2
MAXmalware (ai score=85)
RisingWorm.VB!1.DA41 (CLASSIC)
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Bulz.6330!tr
AVGWin32:VB-FBX

How to remove Bulz.876520?

Bulz.876520 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment