Malware

Should I remove “Ulise.140228”?

Malware Removal

The Ulise.140228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.140228 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ulise.140228?


File Info:

name: FA8B299AFAA81603FCE9.mlw
path: /opt/CAPEv2/storage/binaries/51ffdc505d7a2f5129b6e4d43c1e364c1c577c6988254f4ed5d063ced56ba3e3
crc32: 13DB0ECD
md5: fa8b299afaa81603fce912e21d6e0ddb
sha1: e2f7b7d843dac8e4f1902a1438da3066aa31d81e
sha256: 51ffdc505d7a2f5129b6e4d43c1e364c1c577c6988254f4ed5d063ced56ba3e3
sha512: 27c57a53b2c10bd5f2863905ad1ef69801db9b3d2f6d7bac2d63e82c8136887e1fe226f360c830618e87d6cb068c3e89c74daffa8232b8895fadde9e83fb44ce
ssdeep: 24576:Ndge+IK2/Bll3ygiATbkbys/W730bLweE9dB2a/ZSW77Lv+f6T8Qnskb2i6OEE:N62pHCgO+s/W5PB2ghbq4TyE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10445C04E079618E3C077177E996EC77F000A78B97A9396653981B0AFB690B784903F7C
sha3_384: 5c0d58d058091751e613ff83eed119b4527a97bf2bea810c7c59e3e97fe083617b4bd002eddd5eee371f0d745cf24513
ep_bytes: 98fa9538c89311bfcd72182e4f387094
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Ulise.140228 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ulise.140228
SkyhighBehavesLike.Win32.PWSZbot.tc
McAfeeTrojan-FVOQ!FA8B299AFAA8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3889189
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.afaa81
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
ClamAVWin.Packed.Razy-9785185-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
BitDefenderGen:Variant.Ulise.140228
NANO-AntivirusTrojan.Win32.Selfmod.kczhoj
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Ulise.140228 (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen12.42976
VIPREGen:Variant.Ulise.140228
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fa8b299afaa81603
SophosTroj/Agent-BFEY
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Selfmod.aqec
VaristW32/Trojan.ULNO-1867
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.970
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Ulise.D223C4 [many]
GDataWin32.Trojan.PSE.11XGYE9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.BG.C5400712
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.m5Z@a4gNhbj
ALYacGen:Variant.Ulise.140228
MAXmalware (ai score=87)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Obfuscate.FakeEp.DYN(dyn)

How to remove Ulise.140228?

Ulise.140228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment