Malware

Ulise.140228 (B) information

Malware Removal

The Ulise.140228 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.140228 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ulise.140228 (B)?


File Info:

name: EC8033833F12179F9B8D.mlw
path: /opt/CAPEv2/storage/binaries/a8ad07f9c7f9a4b924b1257063994e4dbb038f1ea36e22732a8c54b5749502a6
crc32: FC3474AE
md5: ec8033833f12179f9b8de39882f3d584
sha1: 3d330e61d2d9c30637dff1cc316cabf566221052
sha256: a8ad07f9c7f9a4b924b1257063994e4dbb038f1ea36e22732a8c54b5749502a6
sha512: 0a565680d8993491151cc6ffb4dedbbe487a89b144566b8138c165d18afa65317ff483ffb5fdacb7f7e2b8574d3ffd5004180b8489b2eb42121da96ba93b43b6
ssdeep: 24576:/YlM0O150Kv4XAT6TtKWCCK2rjlorAn7fa/ZSW77Lv+f6T8Qnskb2i6OEE:QeGU4QTGKWCCK2/YA7fghbq4TyE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18D45D059236B3687E0272737B82E87BF40C13CB575A7DA7674D13CAA7921B81D806732
sha3_384: 3952bba4ed90d33f1b08b36f9b68ac59db3586b17a3d68c0c40d4475229d0f28cdbdd03e8fdb636cf12f3513eff78dc1
ep_bytes: 6786a8a437ef2c23320e25b2b0444d08
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Ulise.140228 (B) also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ulise.140228
FireEyeGeneric.mg.ec8033833f12179f
SkyhighBehavesLike.Win32.PWSZbot.tc
McAfeeTrojan-FVOQ!EC8033833F12
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3420765
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.m5Z@a4gNhbj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
ClamAVWin.Packed.Razy-9785185-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ulise.140228
NANO-AntivirusTrojan.Win32.Selfmod.ixhswu
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Ulise.140228 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Ulise.140228
Trapminemalicious.high.ml.score
SophosTroj/Agent-BFEY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.alfo
ALYacGen:Variant.Ulise.140228
VaristW32/Trojan.ULNO-1867
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.943
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Ulise.D223C4 [many]
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.11XGYE9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.BG.C5400712
Acronissuspicious
VBA32Trojan.Copak
GoogleDetected
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.33f121
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Kryptik.GIRH

How to remove Ulise.140228 (B)?

Ulise.140228 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment