Malware

Ulise.237368 (B) removal instruction

Malware Removal

The Ulise.237368 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.237368 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Ulise.237368 (B)?


File Info:

name: 5019A0BFCB28D703B631.mlw
path: /opt/CAPEv2/storage/binaries/2118ee426c7d968d97e2020ce7b1d6d9dee579173e506df16d62ab70dabc8b74
crc32: 02E8D67C
md5: 5019a0bfcb28d703b631859e089ba486
sha1: e866d0d1558affe5659a2262152202a6a72e9ea0
sha256: 2118ee426c7d968d97e2020ce7b1d6d9dee579173e506df16d62ab70dabc8b74
sha512: 0497757214c19b82507a1a5d131777ac2642efbf9923ba73954c1a5a10f8271a4be212fbe5e4bd91763eadb3945bca356b27dffaabec3f7c026cb65427fb82e6
ssdeep: 24576:Oh0ENIWDn8AA1+GPPcHvfBY/mxsz0ca+e30131g:IrJBA1+GPUHvC/mxtv+zZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F8053378DF4A82C2F50885F9EE299BE279037F94F74593F71DAE541CD42D222230AC26
sha3_384: 349083b043e0866ce6adce417c2a4bd7a08312c1f8613b0d93aaaa90b163202ef126e9c7b0bea561afbfec06a628c162
ep_bytes: 6800000000595001fb535b5a21ff524b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ulise.237368 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Ulise.237368
FireEyeGen:Variant.Ulise.237368
ALYacGen:Variant.Ulise.237368
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 005762bf1 )
BitDefenderThetaGen:NN.ZexaF.34062.XmW@aGaFGsl
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Ulise.237368
AvastWin32:CoinminerX-gen [Trj]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareGen:Variant.Ulise.237368
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Ulise.237368 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.bdy
AviraHEUR/AGEN.1140994
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.C688
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Ulise.237368
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R369357
McAfeeGenericRXAA-FA!5019A0BFCB28
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
APEXMalicious
TencentTrojan.Win32.Coinminer.yi
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Ulise.237368 (B)?

Ulise.237368 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment