Malware

About “Ulise.338102” infection

Malware Removal

The Ulise.338102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.338102 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ulise.338102?


File Info:

name: F746D64764536F30FD32.mlw
path: /opt/CAPEv2/storage/binaries/29df7d6db2eed61a6c2843d7702f6430a85083ad4e6d2fac5d4ef1f446d9e9d7
crc32: DD6AD961
md5: f746d64764536f30fd328b3a6b80a12d
sha1: 47d095eaa68602acf0c65af9b8e26ec6024c4c43
sha256: 29df7d6db2eed61a6c2843d7702f6430a85083ad4e6d2fac5d4ef1f446d9e9d7
sha512: 79099a3adddde727acbabddc5cfc936e2ec329e059c1e3f439433af399fdc125e5f83a23466b5a0c03810e84f4e64817289635d4a43f52ed8fe3b38216346203
ssdeep: 12288:LwCXnLquXU99ICZj7xrcqPkePh+RvMaBlYJQCe2:8Fn9pZjFMePh+RpBlU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BB4CE257650D0B1E7680B314416E6B50969AC3D06A8E6CFF77C3E3A6D312D38A7728F
sha3_384: 3277870b25ae48065e2dbee14c5a830498afb5bd361c77d6d0be24c12818643208862082cd67d373a175ad97210a0f54
ep_bytes: e9560b00000058055a0b00008b3003f0
timestamp: 2012-11-09 05:51:39

Version Info:

CompanyName: Apple
FileDescription: Apple iCloud
FileVersion: 1, 0, 0, 85
InternalName: Apple New Ipad
LegalCopyright: Copyright (C) 2012
OriginalFilename: app stroe
ProductName: Apple iPad
ProductVersion: 1, 0, 0, 85
Translation: 0x0412 0x04b0

Ulise.338102 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.338102
FireEyeGeneric.mg.f746d64764536f30
ALYacGen:Variant.Ulise.338102
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
BaiduWin32.Rootkit.Agent.s
CyrenW32/Urelas.BS.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.AR
APEXMalicious
ClamAVWin.Dropper.Tinba-9943147-0
KasperskyRootkit.Win32.Plite.pvf
BitDefenderGen:Variant.Ulise.338102
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Urelas-D [Trj]
TencentTrojan.Win32.Agent.afj
Ad-AwareGen:Variant.Ulise.338102
SophosMal/Generic-R
ComodoTrojWare.Win32.GupBoot.BFC@5szi8p
DrWebTrojan.AVKill.25437
ZillyaRootkit.Plite.Win32.44
McAfee-GW-EditionTrojan-FCSU!F746D6476453
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ulise.338102 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1HZEHYG
JiangminTrojan/Refroso.afgk
AviraTR/Crypt.XPACK.Gen2
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wecod.R41369
Acronissuspicious
McAfeeTrojan-FCSU!F746D6476453
MAXmalware (ai score=87)
MalwarebytesMalware.AI.121288069
RisingTrojan.Agent!1.9D23 (CLASSIC)
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.AR!tr
BitDefenderThetaGen:NN.ZexaF.34742.Em0@aW1urfeO
AVGWin32:Urelas-D [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ulise.338102?

Ulise.338102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment