Malware

About “Ulise.459102” infection

Malware Removal

The Ulise.459102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.459102 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ulise.459102?


File Info:

name: 6FEDECC73A78678A3A76.mlw
path: /opt/CAPEv2/storage/binaries/3a6a0f456a721d59c759ad7792442cb145d397487a613e2c66a75d2a8e927b2a
crc32: ED56869A
md5: 6fedecc73a78678a3a761dad3faff350
sha1: 9c4c66a422eb100cf297b9681512f7f884293f9c
sha256: 3a6a0f456a721d59c759ad7792442cb145d397487a613e2c66a75d2a8e927b2a
sha512: e2a94c51abc6de776f77a1c8d8bf0c2106d3272520dfa936c20eef182526b91ca4c241122d2d5f19bbe208c91fd7c8987180fa15030910ea44f4e58937fa0e0b
ssdeep: 12288:JZAd1mSYjrBq6Wkns1rbcol8zie973wEE:nAjmSYjRnOxGA
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BA84CF9ADFD93A57C39503783A7E22FF6B543FBD10F2E28DB4A45189897100422F5E68
sha3_384: daa087fa62a5808b160d7df5628b67637ed43b5b4db9e3fcd4556054a6dcfd660cf0ee804dd3b855938babd174caaabf
ep_bytes: ac53817afc3a05fdf9db0c6ceb9964d6
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Ulise.459102 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.459102
FireEyeGeneric.mg.6fedecc73a78678a
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!6FEDECC73A78
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ulise.459102
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
ClamAVWin.Packed.Razy-9873608-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Ulise.459102
NANO-AntivirusTrojan.Win32.Selfmod.ivuout
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kq
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Kryptik.Win32.3263580
EmsisoftGen:Variant.Ulise.459102 (B)
IkarusTrojan-Downloader.Win32.FakeAlert
GDataWin32.Trojan.PSE.11XGYE9
JiangminTrojan.Selfmod.bbhb
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Ulise.D7015E [many]
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.y4Z@aiNtz3j
ALYacGen:Variant.Ulise.459102
MAXmalware (ai score=86)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.422eb1
DeepInstinctMALICIOUS

How to remove Ulise.459102?

Ulise.459102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment