Malware

Ulise.104673 information

Malware Removal

The Ulise.104673 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.104673 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
modcloudserver.eu

How to determine Ulise.104673?


File Info:

crc32: CD8626D0
md5: 197a10dc9feb7b70b63245d3417e34d7
name: frankjoe.exe
sha1: 78e444f01899c99312f4f0b6621d991bb00e3ded
sha256: f3f3a911c2dfd92ffb02c1d34c112a6f4c960221ca9732089e419b1e567726ff
sha512: cfd4cf52daf096852519535452946a33ec21980771d19da621627dd26d239580ab084b61f4e98688765c4ef60fd9b66def7868ee2880df0e6a39713976729373
ssdeep: 12288:Y/ZOEdD6/JyFWtjVg5J06ANkQ1kVKJEIS9dY2Tl:mlIByFWTg5F3Q1kVThY2Tl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 20on
InternalName: m4
FileVersion: 1.4.7
License: This programmnu.org/copyleft/lesser.html.
CompanyName: Gnwnet>
LegalTrademarks: GnuWinxae, m4xae
WWW: http://wwsware/m4
ProductName: M
ProductVersion: 1227
FileDescription: M4: moorocessor
OriginalFilename: m.2e
Translation: 0x0409 0x04e4

Ulise.104673 also known as:

MicroWorld-eScanGen:Variant.Ulise.104673
FireEyeGeneric.mg.197a10dc9feb7b70
Qihoo-360HEUR/QVM05.1.9057.Malware.Gen
ALYacGen:Variant.Strictor.243726
BitDefenderGen:Variant.Ulise.104673
K7GWTrojan ( 005646a41 )
Cybereasonmalicious.01899c
BitDefenderThetaGen:NN.ZelphiF.34106.QG0@aOCtw0ci
F-ProtW32/Delf.AFV
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ulise.104673
KasperskyHEUR:Trojan.Win32.Kryptik.gen
Ad-AwareGen:Variant.Ulise.104673
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.jh
EmsisoftGen:Variant.Ulise.104673 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Delf.BUCY-6261
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D198E1
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
McAfeeFareit-FSK!197A10DC9FEB
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EIIH
RisingTrojan.Fuery!8.EAFB (TFE:dGZlOgWe0gx9EIpU5w)
FortinetW32/Injector.ELKP!tr
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ulise.104673?

Ulise.104673 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment