Malware

Ulise.327840 (B) removal

Malware Removal

The Ulise.327840 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.327840 (B) virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings

How to determine Ulise.327840 (B)?


File Info:

name: C64730FBC14453B65E6C.mlw
path: /opt/CAPEv2/storage/binaries/5bd5e527467a5f2222e7281092933f3a3aa9fc434af159ed49dd757890bd883c
crc32: 2332183F
md5: c64730fbc14453b65e6cddb90ce67e0d
sha1: aa62698726684c959a8517a430e6f2608536c12f
sha256: 5bd5e527467a5f2222e7281092933f3a3aa9fc434af159ed49dd757890bd883c
sha512: 18033ea727e8b8b9c1f082b2fab91a67fa0fd64f142d1e774b3784d19d27e553b5933961060e2d214ac91227df2ccc967c781808c0413676c4c89ab839808cb6
ssdeep: 49152:Ik0H7EkueeZthISA0VL7O6A9BHCPddzfoWpJdBm8e2YeLw/bqcsQHgXr1TYTTEx2:Ik0H7EPgtMffo8SdbqcBAXrAEI9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B467C12B684943BD07B0E36886F9760593B7E312E21DD1B6BB41A4C4F3D640B93D7AB
sha3_384: bd10eb33754e4fd9b88829398cad2961e0db7357103fe2ca0a52b0a80a5ce6829a3fe3a6733449cbe753fae6f86911f6
ep_bytes: 558bec83c4f0b824798800e87088b7ff
timestamp: 2021-12-08 14:12:01

Version Info:

CompanyName: Sector Dingles
FileDescription: Sector Dingles
FileVersion: 1548.474.477.2552
InternalName: Sector Dingles
LegalCopyright: Sector Dingles
LegalTrademarks: Sector Dingles
OriginalFilename: Sector Dingles
ProgramID: Sector Dingles
ProductName: Sector Dingles
ProductVersion: 3424.33.2342.12
Comments: Sector Dingles
Translation: 0x0409 0x04e4

Ulise.327840 (B) also known as:

LionicTrojan.Win32.BestaFera.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.327840
FireEyeGeneric.mg.c64730fbc14453b6
McAfeeArtemis!C64730FBC144
CylanceUnsafe
SangforTrojan.Win32.BestaFera.gen
K7AntiVirusTrojan-Downloader ( 0058a49f1 )
AlibabaTrojanBanker:Win32/BestaFera.9f640334
K7GWTrojan-Downloader ( 0058a49f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DJA
TrendMicro-HouseCallTROJ_GEN.R002C0WLB21
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderGen:Variant.Ulise.327840
TencentWin32.Trojan-downloader.Delf.Sxed
Ad-AwareGen:Variant.Ulise.327840
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WLB21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftGen:Variant.Ulise.327840 (B)
Paloaltogeneric.ml
GDataGen:Variant.Ulise.327840
AviraTR/Dldr.Delf.faqsc
Antiy-AVLTrojan/Generic.ASMalwS.34EC8D2
ArcabitTrojan.Ulise.D500A0
ViRobotTrojan.Win32.Z.Delf.5797376
ZoneAlarmHEUR:Trojan-Banker.Win32.BestaFera.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4839925
ALYacGen:Variant.Ulise.327840
MAXmalware (ai score=81)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Crypt
RisingDownloader.Delf!8.16F (CLOUD)
MaxSecureTrojan.Malware.73698876.susgen
FortinetW32/Delf.DFQ!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Ulise.327840 (B)?

Ulise.327840 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment