Malware

Should I remove “Ulise.29524”?

Malware Removal

The Ulise.29524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.29524 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.virtualhardwares.com
s22.cnzz.com
ocsp.globalsign.com
crl.globalsign.net
ocsp2.globalsign.com
crl.globalsign.com
z1.cnzz.com
c.cnzz.com
cnzz.mmstat.com
www.bing.com
virtualhardwares.com
hardware.lanzous.com
s95.cnzz.com

How to determine Ulise.29524?


File Info:

crc32: 63060BEB
md5: 2735a30fe282127459f308457ad458fc
name: spoofer.exe
sha1: 6cd9c4a17486e8b1298a436d417ed8f268c52a4a
sha256: 97641af10c24c96257256d2c02175a112b51296252980ac0b48bdc84a0c24996
sha512: 100bb9562bc0646546fb4dcf296a39ecf8150b0ea748da597c9a2ebf3d5fc4fa61f1429dc329c65ccf7b548f0269baab2030c7dfc241efa3b4f0472b8d93611d
ssdeep: 49152:lsaazZ00Sqtqr6D486RmWD0ONqylqcS5KpYZyTYhlB:lsaazZfSqtqr6DiR/Ilyk9yyj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) caspue All Rights Reserved
InternalName: Caspue Spoofer.exe
FileVersion: 1, 0, 0, 0
CompanyName: caspue
ProductName: caspue
ProductVersion: 1, 0, 0, 0
FileDescription: caspue
OriginalFilename: caspue
Translation: 0x0409 0x04b0

Ulise.29524 also known as:

K7AntiVirusRiskware ( 0040eff71 )
MicroWorld-eScanGen:Variant.Ulise.29524
CAT-QuickHealTrojan.Occamy
ALYacGen:Variant.Ulise.29524
AegisLabTrojan.Win32.Ursu.4!c
BitDefenderGen:Variant.Ulise.29524
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Ulise.D7354
TrendMicroTROJ_GEN.R002C0PLK18
CyrenW32/Trojan.XZJE-4901
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PLK18
Paloaltogeneric.ml
GDataGen:Variant.Ulise.29524
TencentWin32.Trojan.Gen.Hprx
Ad-AwareGen:Variant.Ulise.29524
EmsisoftGen:Variant.Ulise.29524 (B)
ComodoMalware@#xft20g4szwz3
ZillyaTrojan.GenericKD.Win32.204329
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ramnit.tc
SophosGeneric PUA CJ (PUA)
IkarusTrojan.Rootkit
WebrootW32.Trojan.GenKD
Antiy-AVLTrojan/Win32.Fuerboos
Endgamemalicious (high confidence)
SUPERAntiSpywareTrojan.Agent/Gen-Ursu
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Unwanted/Win32.Agent.R239520
Acronissuspicious
McAfeeArtemis!2735A30FE282
MAXmalware (ai score=100)
VBA32BScope.Trojan.Rootkit
CylanceUnsafe
PandaTrj/CI.A
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.Rootkit!eBwlefqBTww
SentinelOnestatic engine – malicious
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.fe2821
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.2ac

How to remove Ulise.29524?

Ulise.29524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment