Malware

Ulise.19990 (file analysis)

Malware Removal

The Ulise.19990 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.19990 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ulise.19990?


File Info:

crc32: CD45C5FD
md5: 718d579ea6ea48f95225cc9c794f9703
name: opext.gif
sha1: 465351b1b8e40b8e2ebd32ee6ca10fd3f95d95d2
sha256: 4dac88a67bc3f755c0ef3ceea5515a3e3310820978ef249d1813c9982dc6aadf
sha512: 3a0915effe6d1b6680f75631df4f58611eba630cde5318327f137e697d057bcdeafa9d4353418d47520fe6fdbda34a98792e6d9deb9d907b694f63f7b2892a76
ssdeep: 3072:1f5zRI5N4V2MuN+aPuh7qfYNDJsM0cmgyxCrECmAYX/il3:XW5q2HwmQ7qfoqFsmvil3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ulise.19990 also known as:

BkavW32.WirzemroAYEI.Trojan
MicroWorld-eScanGen:Variant.Ulise.19990
CAT-QuickHealTrojan.Khalesi.S1872410
McAfeePacked-XB!718D579EA6EA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
SangforMalware
K7AntiVirusTrojan ( 0052b1cd1 )
BitDefenderGen:Variant.Ulise.19990
K7GWTrojan ( 0052b1cd1 )
Cybereasonmalicious.ea6ea4
TrendMicroTROJ_KHALESI.SMALY
F-ProtW32/Slenfbot.B.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GSKY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6947762-0
KasperskyHEUR:Trojan.Win32.Khalesi.gen
AlibabaVirTool:Win32/CeeInject.28e0054d
NANO-AntivirusTrojan.Win32.Khalesi.fmzlvt
RisingTrojan.Injector!1.BABB (CLASSIC)
Ad-AwareGen:Variant.Ulise.19990
EmsisoftGen:Variant.Ulise.19990 (B)
ComodoTrojWare.Win32.Khalesi.DS@7h11qn
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen7.49534
ZillyaTrojan.Kryptik.Win32.1801181
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.ch
FireEyeGeneric.mg.718d579ea6ea48f9
SophosTroj/AutoG-GG
IkarusTrojan.Win32.CryptInject
CyrenW32/Slenfbot.B.gen!Eldorado
JiangminTrojan.Lethic.aa
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
FortinetW32/GenKryptik.ARNZ!tr
Antiy-AVLTrojan/Win32.Khalesi
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D4E16
ViRobotTrojan.Win32.Khalesi.267776
ZoneAlarmHEUR:Trojan.Win32.Khalesi.gen
MicrosoftTrojan:Win32/DefenseEvasion!rfn
AhnLab-V3Trojan/Win32.MDA.R221226
Acronissuspicious
VBA32BScope.Trojan.Packed
ALYacTrojan.Khalesi.gen
MAXmalware (ai score=87)
MalwarebytesTrojan.Injector
PandaTrj/CI.A
ZonerTrojan.Win32.75824
TrendMicro-HouseCallTROJ_KHALESI.SMALY
TencentMalware.Win32.Gencirc.10b0d035
YandexTrojan.Khalesi!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GDataWin32.Trojan.Khalesi.B
BitDefenderThetaAI:Packer.928489D11F
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Khalesi.A

How to remove Ulise.19990?

Ulise.19990 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment