Malware

Ulise.211814 removal

Malware Removal

The Ulise.211814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.211814 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Ulise.211814?


File Info:

name: 721895CD8020BC8A7F85.mlw
path: /opt/CAPEv2/storage/binaries/f06e12e10a97454b917f8da0f5ca2b6770809b992e47cb79b01d89743cad5a97
crc32: B9F69FCE
md5: 721895cd8020bc8a7f858969aac309d4
sha1: 4ee6a1ab30da8caf69c38202361ed88295fa03ce
sha256: f06e12e10a97454b917f8da0f5ca2b6770809b992e47cb79b01d89743cad5a97
sha512: 85fd75d4e0b56c170c102bb416376bf8b5e7dc11977ea981222623418e46cedfeeac197831ed3e9d7de6c0d432d6ff3842d51e5d8a36d98208db87a6a86609eb
ssdeep: 1536:wpftJZs5ATURD5ushYVQer/jCzVOX2qM/UdoUS1wucd0CmuJd4BXKikc6C:wxtJ2jRhCr/jCMmqM/Ud9S9sBbd4M5C
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EF930258EBC91CA4ECF41BF501B79B8BA401B0B5F1EED705DE101DA4362AAEAC0C4757
sha3_384: e325e84aeb61e94a4f16a0174349963d2ae19329167d257f16503ed44d097eaeb297ee70b27cd7dc9921ae6a1093adb5
ep_bytes: ba000000005089ff4b8b0c2483c40401
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ulise.211814 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.211814
FireEyeGeneric.mg.721895cd8020bc8a
McAfeeGenericRXNY-NU!721895CD8020
CylanceUnsafe
VIPREGen:Variant.Ulise.211814
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Copak.8c9cef1c
K7GWTrojan ( 0058c5ff1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Copak-9853643-0
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Ulise.211814
NANO-AntivirusTrojan.Win32.Agent.ixszcw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.hb
Ad-AwareGen:Variant.Ulise.211814
EmsisoftGen:Variant.Ulise.211814 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
ZillyaTrojan.Kryptik.Win32.3194509
McAfee-GW-EditionBehavesLike.Win32.VirRansom.nc
SophosML/PE-A + Troj/Agent-BGZJ
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ulise.211814
JiangminTrojan.Copak.civ
GoogleDetected
AviraHEUR/AGEN.1200606
Antiy-AVLTrojan/Generic.ASBOL.C686
ArcabitTrojan.Ulise.D33B66
ZoneAlarmHEUR:Trojan.Win32.Copak.vho
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.fmZ@aqxLbnk
ALYacGen:Variant.Ulise.211814
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Kryptik
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.b30da8
PandaTrj/Genetic.gen

How to remove Ulise.211814?

Ulise.211814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment