Malware

Ulise.140228 information

Malware Removal

The Ulise.140228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.140228 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Ulise.140228?


File Info:

name: 3E951E5D3CA491D763E4.mlw
path: /opt/CAPEv2/storage/binaries/9ff91c1f1e73063775734efaec35d6a099729d743a771782fa563ddc1785bba1
crc32: 6365E52A
md5: 3e951e5d3ca491d763e4775340d0b5fb
sha1: 76248f295dc4f842863d900cc632eec71b2784b7
sha256: 9ff91c1f1e73063775734efaec35d6a099729d743a771782fa563ddc1785bba1
sha512: b7cefb5b7dd96ee3929236dfdf476d00d1b00645fad6ee72cf0f7830cb2b02e09ee4b1b4036210cf5889f06fa9857e2297232ff78984cb22f7c7c174bcf4b021
ssdeep: 24576:aZ/or7/RK3CHhelb/pYzlESCCpD2Ja/ZSW77Lv+f6T8Qnskb2i6OEE:aZQPZICHclizDyghbq4TyE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D145CF0C5741099BD433BB32886CDABF44617E7CA1BBD6AA7C80B8EEB561F819511F70
sha3_384: 623dbba30bea46d1d9efde747d7b383e2ab1864f43179829af28a0056cdff032e63ccf1904483328fc62e8ec26343e98
ep_bytes: 419a27cb11f3a34c1412aadd9658c267
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Ulise.140228 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.140228
ClamAVWin.Packed.Razy-9785185-0
FireEyeGeneric.mg.3e951e5d3ca491d7
SkyhighBehavesLike.Win32.Picsys.tc
McAfeeTrojan-FVOQ!3E951E5D3CA4
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ulise.140228
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.95dc4f
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Khalesi.gen
BitDefenderGen:Variant.Ulise.140228
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Kryptik.Win32.1917476
EmsisoftGen:Variant.Ulise.140228 (B)
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Generic.dbclz
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.970
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Ulise.D223C4 [many]
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.11XGYE9
VaristW32/Trojan.ULNO-1867
AhnLab-V3Trojan/Win.BG.C5400712
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.m5Z@a4gNhbj
ALYacGen:Variant.Ulise.140228
MAXmalware (ai score=84)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ulise.140228?

Ulise.140228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment