Malware

Ulise.114960 (B) removal guide

Malware Removal

The Ulise.114960 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.114960 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Attempts to execute a binary from a dead or sinkholed URL
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests information related to installed mail clients
  • Creates a known CrypVault ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
oknoff52.ru

How to determine Ulise.114960 (B)?


File Info:

crc32: C62BEAF2
md5: c93d11ec3a62860ed9795a22bd83780a
name: C93D11EC3A62860ED9795A22BD83780A.mlw
sha1: 1b2202a16008fa0b40b73860a6a49debaff11a80
sha256: 725bdc0a1857d5e0a1b6253522cf4df1dfe944f9aba7724d373b6c2098033dd6
sha512: 96951e41f4a3aae60184ab6629f69646ccbc843f14b5f40e3527b00d92405675808b466ce5eb254900344ec7625c84cc2b0698cc0e3cdd91dbf5d3f91ff5ce51
ssdeep: 6144:q9o7tHiKg02IwLgnIgE8JM9dXlb39jZrqNSQwzXD:WAHiKgHJZtohW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 1.5.0.2712
PrivateBuild: December 30, 2012
Translation: 0x0000 0x04b0

Ulise.114960 (B) also known as:

K7AntiVirusTrojan ( 0013236a1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.60255
ClamAVWin.Trojan.CyptFile2-5536495-0
McAfeeRansomware-FQO!C93D11EC3A62
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Scatter.152c2082
K7GWTrojan ( 0013236a1 )
Cybereasonmalicious.c3a628
CyrenW32/Vaultcrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.FH
ZonerTrojan.Win32.44403
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Scatter.av
BitDefenderGen:Variant.Ulise.114960
NANO-AntivirusTrojan.Win32.Mikey.evhpqg
MicroWorld-eScanGen:Variant.Ulise.114960
TencentWin32.Trojan.Scatter.Sxyb
SophosMal/Generic-S
ComodoMalware@#2un53wcbtkei7
BitDefenderThetaGen:NN.ZexaF.34170.iq0@aqOwy4OG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FireEyeGen:Variant.Ulise.114960
EmsisoftGen:Variant.Ulise.114960 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Nymaim.rq
AviraHEUR/AGEN.1123670
Antiy-AVLTrojan/Generic.ASMalwS.1A048DD
KingsoftWin32.Troj.Agent.ij.(kcloud)
MicrosoftRansom:Win32/Vaultcrypt.A
GDataGen:Variant.Ulise.114960
AhnLab-V3Trojan/Win32.Fareit.C1516197
VBA32SScope.Malware-Cryptor.Hlux
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4110313759
PandaTrj/CI.A
RisingTrojan.Generic@ML.98 (RDML:xdv6JLVVtzo2OUcxmDXqFw)
YandexTrojan.PWS.Fareit!VPEomoLkPjs
IkarusTrojan.Inject
FortinetW32/Injector.DGDK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ulise.114960 (B)?

Ulise.114960 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment