Malware

About “Ulise.153544” infection

Malware Removal

The Ulise.153544 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.153544 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ulise.153544?


File Info:

name: CC160DFC90278C2DEF73.mlw
path: /opt/CAPEv2/storage/binaries/e51cd8eade082fb7eddda0cdd87af311c521bb2eab917e7ee5659ca7211d4201
crc32: 871B6056
md5: cc160dfc90278c2def737d7c84cc88b8
sha1: 51555b54424a73b8e083785734d6f05337bad4d9
sha256: e51cd8eade082fb7eddda0cdd87af311c521bb2eab917e7ee5659ca7211d4201
sha512: cc6eba2f82e5160ca055527f1712b73fd83d4193585143fd92266fc838703b39c01b1d2e9b32a9934ca7ea3b710f26fcfb3c3eaad6a9ad355ab632a62eba3d7e
ssdeep: 49152:kOTYL06MQCTLQc2dVq3gPyeBhbq4TTow+lsg:kOTaMdTL3syeBhhTW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C195E00F23649903C523277AD86DC73F594968BE6A93D6F671813C9FF1223C8E596B20
sha3_384: 25817fcb5d217dae55d31728683efc655e8bb8b93ce51d99da778fc3d35153ab43be0578752719ff485abdb358fe515a
ep_bytes: db45d5198b2c519e8ecd580f0c8730b5
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Ulise.153544 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ulise.153544
SkyhighBehavesLike.Win32.Generic.tc
McAfeeTrojan-FVOQ!CC160DFC9027
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.2770120
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.4424a7
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9785185-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:RATX-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Ulise.153544
SophosTroj/Agent-BFEY
IkarusTrojan.Win32.Glupteba
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.15NLAT
VaristW32/Trojan.ULNO-1867
AhnLab-V3Packed/Win.FJB.C5537701
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.09Z@aqNvM9h
ALYacGen:Variant.Ulise.153544
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Redcap!zbi6EFdgH7I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ulise.153544?

Ulise.153544 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment