Malware

Ulise.45009 removal instruction

Malware Removal

The Ulise.45009 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.45009 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Ulise.45009?


File Info:

crc32: 5A8974DC
md5: aea58c21577fe5528da9d9e5cd922bed
name: AEA58C21577FE5528DA9D9E5CD922BED.mlw
sha1: 70c4d528154cab32693fc17f362d60205b1ae401
sha256: e200609a68500eb1be69584120791b400b57c00bedb4e630ae846a7a0d0d1fe6
sha512: 85fe181cd464c34093d8a3aed73dcb3e9f3e074185d6066eeba7c826881a6726340a8f4d6b42f65dbbff93e5a39326318f153d9e368c7dfdfb32b4d996a60cf1
ssdeep: 768:hojY9PYYQisWvWWzCEc/wqaDxPRDU2oKyHHojY9P:0mAYQWvJFZoKyHSm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ulise.45009 also known as:

BkavW32.FakeLpkMVe.Trojan
DrWebTrojan.DnsAmp.35
MicroWorld-eScanGen:Variant.Ulise.45009
CMCTrojan.Win32.MicroFake!O
CAT-QuickHealTrojan.MicroFake.BA6
ALYacGen:Variant.Ulise.45009
CylanceUnsafe
ZillyaTrojan.Scar.Win32.37130
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/MicroFake.7d7bd7b3
K7GWTrojan ( 001b906c1 )
K7AntiVirusTrojan ( 0040f89d1 )
TrendMicroDDOS_NITOL.SMD
BaiduWin32.Trojan.FakeMicro.c
CyrenW32/OnlineGames.GC.gen!Eldorado
SymantecBackdoor.Nitol
ESET-NOD32Win32/Agent.RNS
ZonerTrojan.Win32.7012
APEXMalicious
AvastWin32:GenMalicious-EWM [Trj]
ClamAVWin.Trojan.Generic-6297788-0
GDataGen:Variant.Ulise.45009
KasperskyTrojan.Win32.MicroFake.ba
BitDefenderGen:Variant.Ulise.45009
NANO-AntivirusTrojan.Win32.MicroFake.brqlq
ViRobotTrojan.Win32.Scar.45056.H
SUPERAntiSpywareTrojan.Agent/Gen-Virut
TencentTrojan.Win32.MicroFake.baa
Ad-AwareGen:Variant.Ulise.45009
SophosMal/Nitol-C
ComodoTrojWare.Win32.Ramnit.d@4pji6o
F-SecureTrojan:W32/MicroFake.A
BitDefenderThetaGen:NN.ZedlaF.32519.cu4@aGzo!ag
VIPRETrojan.Win32.Ramnit.d (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Scar.pm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.aea58c21577fe552
EmsisoftGen:Variant.Ulise.45009 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/MalwareF.YMPW
Endgamemalicious (high confidence)
WebrootTrojan.Nitol
AviraTR/MicroFake.BA.2
Antiy-AVLTrojan/Win32.MicroFake.ba
MicrosoftDDoS:Win32/Nitol
JiangminTrojan/Generic.pai
ArcabitTrojan.Ulise.DAFD1
ZoneAlarmTrojan.Win32.MicroFake.ba
TACHYONTrojan/W32.MicroFake.Zen
AhnLab-V3Trojan/Win32.Scar.R806
Acronissuspicious
McAfeeGenericRXEB-ET!AEA58C21577F
MAXmalware (ai score=87)
VBA32Trojan.MicroFake
MalwarebytesTrojan.MicroFake
PandaGeneric Malware
TrendMicro-HouseCallDDOS_NITOL.SMD
RisingBackdoor.Overie!1.64BD (CLASSIC)
YandexTrojan.Scar!SvAe3OnybFg
IkarusTrojan.Backdoor.SuspectCRC
FortinetW32/Dropper.RNS!tr
AVGWin32:GenMalicious-EWM [Trj]
Paloaltogeneric.ml
Qihoo-360Trojan.Win32.FakeLPK.A

How to remove Ulise.45009?

Ulise.45009 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment