Malware

Ulise.89379 removal instruction

Malware Removal

The Ulise.89379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.89379 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ulise.89379?


File Info:

crc32: 63E53CCE
md5: e17adc9a793a5fc7f9cfb90c8cc7ee62
name: kings.exe
sha1: 9590e26cf7fb9036197db2d26d3676469fd58913
sha256: 5d8bbc5a71ec101d233e45d3c1d0443c57df8629bfca5347d000d58db4355764
sha512: 3c2321a164c4c45bd05bf5a7ee3ca51dc0b210b51900511fd36575f9f75f0d8e498626ffb2f4b556c2b5c35da286542032b26a5a57d264c91b6ac1a0f942ab7d
ssdeep: 24576:H7Hb5x5Qz1lVlTxOxzTxDq064fpEm9ro7TGjiV/gjFOjf+:H7HbiDzxwtT+gh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ulise.89379 also known as:

DrWebTrojan.Siggen8.58042
MicroWorld-eScanGen:Variant.Ulise.89379
CAT-QuickHealTrojanpws.Agensla
McAfeeFareit-FQC!E17ADC9A793A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ulise.89379
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.cf7fb9
ArcabitTrojan.Ulise.D15D23
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.32515.bHW@aq8VfFai
CyrenW32/Injector.NFRJ-3836
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EJDW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
AlibabaTrojanPSW:Win32/Injector.d775ce74
SUPERAntiSpywareTrojan.Agent/Gen-Injector
RisingTrojan.Generic@ML.84 (RDMK:z45zL3qcfrHJoF9vBQl7nA)
Ad-AwareGen:Variant.Ulise.89379
F-SecureTrojan.TR/Kryptik.amdlt
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
FortinetW32/Agent.AJFK!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.e17adc9a793a5fc7
SophosMal/Fareit-V
F-ProtW32/Kryptik.AMU
WebrootW32.Gen.BT
AviraTR/Kryptik.amdlt
MAXmalware (ai score=89)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Lokibot.E!MTB
ZoneAlarmHEUR:Trojan-PSW.Win32.Agensla.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacSpyware.AgentTesla
MalwarebytesBackdoor.NanoCore
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
GDataGen:Variant.Ulise.89379
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.PSW.086

How to remove Ulise.89379?

Ulise.89379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment