Malware

Should I remove “Ulise.419387 (B)”?

Malware Removal

The Ulise.419387 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.419387 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Ulise.419387 (B)?


File Info:

name: C9AB0BE8269DF49F4B43.mlw
path: /opt/CAPEv2/storage/binaries/890187113b2a4ea3aa724f51b191a5ad77c32a18c76ee7865f05ec3fc4a0f49f
crc32: D57B4A30
md5: c9ab0be8269df49f4b43ac332858a4bc
sha1: 5d7b4519061bfdf5058fac4c1f5552be75772c06
sha256: 890187113b2a4ea3aa724f51b191a5ad77c32a18c76ee7865f05ec3fc4a0f49f
sha512: 093e5037f40d3e1d46ccd34b7ffb13810f743624476ba6e9a278fbbdeb4b1bd9b7919557e568670263e5d2bd6188709654c8e19f9d78149c47edcffab240acd7
ssdeep: 1536:YL3YWJ2AC4lB+nqzbyKvIbBuRoTSGYQDWd18:YLLzLR35w4oTSGYQDWd18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189B36C127750D432E0A21539846AC7724FBE783266B8C9C777CA16BE1EB53D09B3835B
sha3_384: 5119dbd83604607133699208347f51c1f6e275d98dec6b37c4b92a1060b4f3fc4700d1a1a8329b0be45a3b8a6b8abe4d
ep_bytes: 51ff15e4c03101807d98008d4598740d
timestamp: 2016-01-30 00:31:12

Version Info:

0: [No Data]

Ulise.419387 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ulise.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.419387
ClamAVWin.Malware.Bqrf-9645595-0
McAfeeGenericRXAA-FA!C9AB0BE8269D
MalwarebytesMalware.AI.1413118034
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Rifdoor.858f3b28
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8269df
BitDefenderThetaGen:NN.ZexaF.36250.huY@aGyG1qg
CyrenW32/Agent.GHN.gen!Eldorado
SymantecBackdoor.Rifelku
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ulise.419387
AvastFileRepMalware [Misc]
EmsisoftGen:Variant.Ulise.419387 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Ulise.419387
TrendMicroTROJ_GEN.R002C0DF623
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c9ab0be8269df49f
SophosMal/Generic-S
IkarusBackdoor.Win32.Rifdoor
GDataGen:Variant.Ulise.419387
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Rifdoor
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Ulise.D6663B
MicrosoftBackdoor:Win32/Rifdoor.A!bit
GoogleDetected
AhnLab-V3Trojan/Win32.Rifdoor.R346726
ALYacGen:Variant.Ulise.419387
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DF623
RisingTrojan.Agent!1.DAE9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.209108456.susgen
FortinetPossibleThreat.RF
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ulise.419387 (B)?

Ulise.419387 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment