Malware

Ulise.89280 (B) malicious file

Malware Removal

The Ulise.89280 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.89280 (B) virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
doc-0c-cc-docs.googleusercontent.com
a.tomx.xyz

How to determine Ulise.89280 (B)?


File Info:

crc32: B90F5F77
md5: 53fd8591f715eeee9fd530ab1a0bf46d
name: thai2.exe
sha1: 843d68dc8680a4d4955a42fb4ec0b80fb59f3843
sha256: b289ae9dfb8d2986801dfd9667b72d1d49fb61d8c44e6d00dc9af43f8db9872c
sha512: 81f8a1dabbd853bbfe883c5882c5ffb609d857e8964f764827994dc77419d2144468c68d405bc885cb102b6c65ac08aaf844bc791ec65075e8fe67b61f2055f5
ssdeep: 12288:gPviKuS4AZjzNGmydnkdXFxpgUpITyrUXZWsRSwDRq1g+:gPvWSXjzNNydnktppUcs5Rq13
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ulise.89280 (B) also known as:

DrWebTrojan.PWS.Stealer.27488
MicroWorld-eScanGen:Variant.Ulise.89280
FireEyeGeneric.mg.53fd8591f715eeee
CAT-QuickHealTrojanpws.Racealer
McAfeeGenericRXJD-MC!53FD8591F715
MalwarebytesSpyware.PasswordStealer
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 0054b83d1 )
BitDefenderGen:Variant.Ulise.89280
K7GWSpyware ( 0054b83d1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.32519.HqW@aq9L8Od
SymantecTrojan Horse
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Ulise-7344017-0
GDataGen:Variant.Ulise.89280
KasperskyTrojan-PSW.Win32.Racealer.bky
AlibabaTrojanSpy:Win32/Generic.b3a98eed
NANO-AntivirusTrojan.Win32.Stealer.gjocps
ViRobotTrojan.Win32.Z.Ulise.553472.A
AegisLabTrojan.Win32.Racealer.i!c
RisingStealer.Raccoon!1.BD9D (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.89280 (B)
ComodoMalware@#2s0lruoekzcwj
F-SecureHeuristic.HEUR/AGEN.1044721
ZillyaTrojan.Agent.Win32.1190982
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
CyrenW32/Trojan.MHFI-7793
JiangminTrojan.PSW.Racealer.ol
AviraHEUR/AGEN.1044721
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Racealer
ArcabitTrojan.Ulise.D15CC0
ZoneAlarmTrojan-PSW.Win32.Racealer.bky
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Raccoon.C3365665
Acronissuspicious
ALYacGen:Variant.Ulise.89280
VBA32BScope.TrojanSpy.MSIL.Stealer
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Spy.Agent.PQZ
TrendMicro-HouseCallTROJ_GEN.R002C0PL219
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74709358.susgen
FortinetW32/Agent.PQZ!tr
Ad-AwareGen:Variant.Ulise.89280
AVGWin32:Trojan-gen
Cybereasonmalicious.c8680a
Qihoo-360Win32/Trojan.PSW.442

How to remove Ulise.89280 (B)?

Ulise.89280 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment