Malware

Should I remove “Ulise.98428”?

Malware Removal

The Ulise.98428 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.98428 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

How to determine Ulise.98428?


File Info:

crc32: AE965E33
md5: bb49d3fbd4cb3fdc2bb2256463275826
name: 2d7zk7ka25996259808.exe
sha1: ee7ad5be4550845f3cac328d2ece58b7225e900e
sha256: 65c97fcbc4483c7dbd4692342ce8c7089573603677f917e40b45cea43a30abab
sha512: 28d330283830844c13b2680e2569e2d686ff86b5d71b678e6dd24c17e42ec59517c3b032e5e9596340ddceaa7e7a08928a0e124a6bb8796091f0c4557a87fe99
ssdeep: 12288:L7seycbncWlgxDb3qhmic7zziD5ap/LeDeqwyx:cey8lgR31iFapSqqn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: GridCtrlDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: GridCtrlDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: GridCtrlDemo MFC Application
OriginalFilename: GridCtrlDemo.EXE
Translation: 0x0409 0x04b0

Ulise.98428 also known as:

DrWebTrojan.DownLoader32.59360
MicroWorld-eScanGen:Variant.Ulise.98428
FireEyeGen:Variant.Ulise.98428
Qihoo-360Generic/Trojan.288
McAfeeEmotet-FQC!BB49D3FBD4CB
ALYacTrojan.Agent.Emotet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ulise.98428
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojanSpy.Win32.EMOTET.SML.hp
BitDefenderThetaGen:NN.ZexaE.34084.Eq1@aqkauBai
F-ProtW32/Emotet.AGQ.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HAVX
APEXMalicious
AvastWin32:Dropper-gen [Drp]
GDataGen:Variant.Ulise.98428
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/Emotet.7ae2c951
NANO-AntivirusTrojan.Win32.Ursu.gyxusp
ViRobotTrojan.Win32.Emotet.487489
AegisLabTrojan.Win32.Ursu.4!c
Endgamemalicious (high confidence)
SophosMal/Encpk-APE
F-SecureTrojan.TR/AD.Emotet.rxqen
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
Trapminemalicious.high.ml.score
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.AGQ.gen!Eldorado
JiangminTrojan.Agent.coed
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.rxqen
MAXmalware (ai score=81)
ArcabitTrojan.Ulise.D1807C
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Malware/Win32.Generic.C3980535
Acronissuspicious
VBA32Trojan.Downloader
Ad-AwareGen:Variant.Ulise.98428
MalwarebytesTrojan.Emotet
PandaTrj/Emotet.A
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SML.hp
RisingTrojan.Generic@ML.98 (RDML:0m3Cri8wviD+vOkJ2wrMNw)
FortinetW32/Dloader.5890!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Ulise.98428?

Ulise.98428 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment