Malware

Should I remove “Ulise.412437”?

Malware Removal

The Ulise.412437 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.412437 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ulise.412437?


File Info:

name: 746605F940BB3D2D82A3.mlw
path: /opt/CAPEv2/storage/binaries/e4dd56409b11ff8ef0a95b53a55cb2f85ecfb490dfe08383b2d38f1dd8f829ff
crc32: 5E86A712
md5: 746605f940bb3d2d82a37e0b4cabf9ea
sha1: f593e99b75e9ac7273d3691ab438152138923f09
sha256: e4dd56409b11ff8ef0a95b53a55cb2f85ecfb490dfe08383b2d38f1dd8f829ff
sha512: 6d05051581eb7b651ffe2654fb0c5c7c94b24c62d177065a3e5592f32fe9e2812552d6b2c85b267bed8cbfb0f50b93a453f96aca6253b69c6a798f07c3f374b1
ssdeep: 98304:nccpj7Z+DlLpjeHLHRRJrODZFFQ1tmCD6A0:zh+DHe/JQZFFQ1tN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192466C61C605E816D46110F3CAEE96617A147F312F21A593E3D47A3C6BF02B7BB1A81F
sha3_384: 6668f90234b800dacc4061cdbc01307494f22cf2b656531a34a6cf3b85f323a49c8b2a93446fbaba0e8721b79c339790
ep_bytes: 558bec6aff68d8df890068f0c9780064
timestamp: 2023-04-24 08:14:53

Version Info:

CompanyName: Microsoft Corp
FileDescription: Host Process for Wind
FileVersion: 10.0.1941.
InternalName: svchost.exe
LegalCopyright: Microsoft Corp
OriginalFilename: svchost.exe
ProductName: Operation system
ProductVersion: 10.0.1941.
Translation: 0x0409 0x04b0

Ulise.412437 also known as:

MicroWorld-eScanGen:Variant.Ulise.412437
VIPREGen:Variant.Ulise.412437
K7AntiVirusTrojan ( 005a19381 )
K7GWTrojan ( 005a19381 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
BitDefenderGen:Variant.Ulise.412437
RisingTrojan.Agent!8.B1E (TFE:5:SlPvklLDH1S)
EmsisoftGen:Variant.Ulise.412437 (B)
F-SecureTrojan.TR/Agent.qdfyd
ZillyaTrojan.Agent.Win32.3410362
FireEyeGen:Variant.Ulise.412437
IkarusTrojan.Win32.Agent
JiangminTrojan.Banker.ClipBanker.cfw
GoogleDetected
AviraTR/Agent.qdfyd
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Zusy
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Ulise.D64B15
GDataGen:Variant.Ulise.412437
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R577569
ALYacGen:Variant.Ulise.412437
TencentMalware.Win32.Gencirc.11a2bc41
YandexTrojan.Agent!ZyxI0nlfRzo
FortinetW32/Zusy.448811!tr

How to remove Ulise.412437?

Ulise.412437 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment