Malware

Application.Ulise.358678 (file analysis)

Malware Removal

The Application.Ulise.358678 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Ulise.358678 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Ulise.358678?


File Info:

name: 1D00A5D8A84473E0807F.mlw
path: /opt/CAPEv2/storage/binaries/b4cb46454db2d336b3988918e2dcb576e9d26ec9c5b65c1744d49152f4bcde52
crc32: AC2A7F6B
md5: 1d00a5d8a84473e0807f03190b038b5c
sha1: 7dbca45d3d9aaae1304a9dfe2391c8fe9be8a257
sha256: b4cb46454db2d336b3988918e2dcb576e9d26ec9c5b65c1744d49152f4bcde52
sha512: 50eace045219c21de8da170aac3d689d7ea7f1ae9c5721a2239159686ede238d500ae4121dce1fe05c75ab8b809f902d0113f963ff888ba51481c0654b2db84e
ssdeep: 6144:2017vY/DQW7pJ+d8x0NIEKSbITBRttIbLGU+EHZCUa7WIWGwC:2Cw/DQW7p52MT3a9VZBa7dWGwC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EB4171F97548332D16009375CEB83706C2E6D603AE37CF62D992E0F9BB9682B53D592
sha3_384: aa1118504db19f3d490efd0db2b776cadf7127372e6eff45b57ad87c89de5b43f33b34d89b16c52424d3a6cd6e570b1e
ep_bytes: 558bec83c4f0b824ca4400e89c98fbff
timestamp: 2017-11-15 20:15:43

Version Info:

CompanyName: TweakBit
FileDescription: PCRepairKit Setup
FileVersion: 1.8.3.1
InternalName: pc-repair-kit
LegalCopyright: Copyright © 2008-2017 Auslogics Labs Pty Ltd
LegalTrademarks: Copyright © 2008-2017 Auslogics Labs Pty Ltd
OriginalFilename: pcrepairkit_stub_installer.exe
ProductName: PCRepairKit
ProductVersion: 1.x
Comments: Part of TweakBit PC Repair Kit
Translation: 0x0409 0x04e4

Application.Ulise.358678 also known as:

BkavW32.Common.54F79C4F
MicroWorld-eScanGen:Variant.Application.Ulise.358678
FireEyeGeneric.mg.1d00a5d8a84473e0
McAfeeGenericRXSF-OQ!1D00A5D8A844
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Agent.Win32.347070
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005329171 )
K7GWTrojan ( 005329171 )
Cybereasonmalicious.d3d9aa
CyrenW32/Auslogics.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Auslogics.A potentially unwanted
APEXMalicious
Kasperskynot-a-virus:Downloader.Win32.Agent.kevm
BitDefenderGen:Variant.Application.Ulise.358678
AvastWin32:SilentInstaller-A [PUP]
RisingPUF.Auslogics!1.AC47 (CLASSIC)
EmsisoftApplication.Downloader (A)
F-SecurePotentialRisk.PUA/TweakBit.Gen7
DrWebProgram.Unwanted.2346
VIPREGen:Variant.Application.Ulise.358678
McAfee-GW-EditionGenericRXSF-OQ!1D00A5D8A844
SophosTweak Bit FixMyPC (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Application.Auslogics.C
JiangminDownloader.Agent.epc
WebrootPua.Downloadmanager
GoogleDetected
AviraPUA/TweakBit.Gen7
MAXmalware (ai score=77)
Antiy-AVLGrayWare/Win32.Auslogics.a
Kingsoftmalware.kb.a.995
XcitiumApplication.Win32.Auslogics.AB@80idad
ArcabitTrojan.Application.Ulise.D57916
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.kevm
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R214644
VBA32BScope.Downloader.Agent
ALYacGen:Variant.Application.Ulise.358678
Cylanceunsafe
PandaTrj/CI.A
TencentMalware.Win32.Gencirc.10bdc7b4
YandexTrojan.GenAsa!sc2SX+KfCU4
FortinetW32/Auslogics.A
AVGWin32:SilentInstaller-A [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Application.Ulise.358678?

Application.Ulise.358678 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment