Malware

How to remove “Ulise.230261”?

Malware Removal

The Ulise.230261 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.230261 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Ulise.230261?


File Info:

name: 639B1839CF7B9E0AFDCE.mlw
path: /opt/CAPEv2/storage/binaries/19f9e5047cfe24188e78a623c30ec8492eba3927b1eac0f6eca6cee5871164f0
crc32: 19300D0A
md5: 639b1839cf7b9e0afdce10155b7f0a79
sha1: 49e5609af331081584050d9838abf2e02db4f138
sha256: 19f9e5047cfe24188e78a623c30ec8492eba3927b1eac0f6eca6cee5871164f0
sha512: af9e260cc4add972e39a2dbf24a5d213d8377a5064e7cd2ee6dfd44e96f23e7790cfd44e6afdba24d5ea993ea39a4c18ee39e2df516ecf15b10f860131ca2c1d
ssdeep: 24576:jJWQecAJyIhDi3kmk29glkDBITOwbzG9V6Az8f62Ca:TahD7mk2SCDU/bz08yt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1710523DA584EAE83CFE6D2702658127C5BDD40E223C4A7C34D5B42EAE3B0E6CF574A54
sha3_384: 8d4c250fea42ea445f457a853cd6bb7c6243eedc240e48d389be07da4aa72de402e8929ea31eb8012f1812599085805e
ep_bytes: be000000005721db5929db83ec04890c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ulise.230261 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Ulise.230261
FireEyeGeneric.mg.639b1839cf7b9e0a
McAfeeGenericRXAA-FA!639B1839CF7B
MalwarebytesTrojan.Crypt.UPX
K7GWTrojan ( 005762bf1 )
K7AntiVirusTrojan ( 0057ffc71 )
BitDefenderThetaGen:NN.ZexaF.34062.XmW@aWIJJyn
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Ulise.230261
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Ulise.230261
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ulise.230261 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Ulise.230261
JiangminTrojan.Copak.dba
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C687
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366210
VBA32Trojan.Packed
ALYacGen:Variant.Ulise.230261
APEXMalicious
RisingTrojan.Kryptik!1.D238 (CLASSIC)
MAXmalware (ai score=82)
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Ulise.230261?

Ulise.230261 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment