Malware

Ulise.233132 (B) removal tips

Malware Removal

The Ulise.233132 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.233132 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Ulise.233132 (B)?


File Info:

name: 8E62B2676B6F6E55C59E.mlw
path: /opt/CAPEv2/storage/binaries/ba9ae6283ea69406a5a97949291e9d89ad1498bca1c28416c82eccedb9b65940
crc32: 792F4CA2
md5: 8e62b2676b6f6e55c59e08a66fa7698c
sha1: c8311dfbf54019b29658a92983390a902454e939
sha256: ba9ae6283ea69406a5a97949291e9d89ad1498bca1c28416c82eccedb9b65940
sha512: da8c13efedbf0cbc6db2734697ccaa8f7547b6b1fa1480935e7d506709b118cf7acc135fb4eaf1863f4b5ad53b535df223157564cda34dfd351d267fa6a8b09d
ssdeep: 49152:jTdsooqRDWPPI+UKH7RnIpaMXlBCXYdwzp77DPH:nJTGPntsBCoS77zH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1477533C03B19E218ECF6C5BC446226F3F628B8AC59FBE2E4C9841551057FF5E6809BD9
sha3_384: ff99bde4a0213c88a4290b45d4bcaee5b92b6df52a61c8461ca5484e7a02b14a0237ed6f475b85ee19e628342d9da241
ep_bytes: b80000000083ec0489142481eb24a07f
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ulise.233132 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.233132
FireEyeGeneric.mg.8e62b2676b6f6e55
McAfeeGenericRXAA-FA!8E62B2676B6F
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.bf5401
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Generic
BitDefenderGen:Variant.Ulise.233132
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Ulise.233132
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Ulise.233132 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Ulise.233132
JiangminTrojan.Copak.vhg
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C687
ArcabitTrojan.Ulise.D38EAC
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R369189
BitDefenderThetaGen:NN.ZexaCO.34294.InZ@aycsZO
ALYacGen:Variant.Ulise.233132
MAXmalware (ai score=82)
VBA32Trojan.Packed
MalwarebytesTrojan.Injector
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
Qihoo-360HEUR/QVM19.1.7B3B.Malware.Gen

How to remove Ulise.233132 (B)?

Ulise.233132 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment