Trojan

Should I remove “Trojan:Win32/Ulise.AMS!MTB”?

Malware Removal

The Trojan:Win32/Ulise.AMS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ulise.AMS!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Ulise.AMS!MTB?


File Info:

name: E8491BD963D2CCF39303.mlw
path: /opt/CAPEv2/storage/binaries/6bf537f1e32e5663ac0d8b7ac8c0bd934b9039a5c59fc6c1ef16ecffd0872d5e
crc32: 1279328F
md5: e8491bd963d2ccf393035b0c9cf66a99
sha1: e7f914b95ef1a98e4e33f27e37bdb18d94b21ee7
sha256: 6bf537f1e32e5663ac0d8b7ac8c0bd934b9039a5c59fc6c1ef16ecffd0872d5e
sha512: 43e570b0dd1d0ec7e71b1b720ea3dd4aaecf3e1db4177eadd523bd4e28de17fa46a9db1df485b212bd7ea2a436eda421b6f09f834109d8bc00eb0f5288c75f18
ssdeep: 12288:kGzhQ3QLhA1Cm0XtCoHhvpNN9TYRn0m1G/BGZbfM3Mc9k6idfWw6MgkT:kWhYpGXXn9TYRn0m1G/BGZbfM3Mc9k6c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DA48E6FF3451373C28202B2364E96C6FB3D947B636A89E0655CC01D2367E6C877B686
sha3_384: b2894815f0ece95a2ebd134c6de6b21d752bd27c422c0817c0c47e54e4edbb2c1626a3654811a128dd832ceba3a5d7cc
ep_bytes: 68000000005a5381c11e13defe5809c9
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Ulise.AMS!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103953
ClamAVWin.Packed.Lazy-10001745-0
FireEyeGeneric.mg.e8491bd963d2ccf3
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGlupteba-FTTQ!E8491BD963D2
MalwarebytesMalware.AI.4019538534
VIPRETrojan.GenericKDZ.103953
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058e60a1 )
K7GWTrojan ( 0058e60a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D19611
BitDefenderThetaGen:NN.ZexaF.36792.DCZ@a04YKBl
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTKQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Khalesi.nwcv
BitDefenderTrojan.GenericKDZ.103953
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.fg
EmsisoftTrojan.GenericKDZ.103953 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Ulise.AMS!MTB
ZoneAlarmUDS:Trojan.Win32.Khalesi.nwcv
GDataTrojan.GenericKDZ.103953
VaristW32/Khalesi.K.gen!Eldorado
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKDZ.103953
Cylanceunsafe
RisingTrojan.Injector!1.CD26 (CLASSIC)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.95ef1a

How to remove Trojan:Win32/Ulise.AMS!MTB?

Trojan:Win32/Ulise.AMS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment