Malware

What is “Ulise.459102”?

Malware Removal

The Ulise.459102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.459102 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ulise.459102?


File Info:

name: A6E456155A12722CB141.mlw
path: /opt/CAPEv2/storage/binaries/c57e011b02389358900df8c3c14c09b8b6b8e6e1c69c17153b59b61e09cae9d3
crc32: CEDEAAF5
md5: a6e456155a12722cb1417882efcc94bf
sha1: 6d37dc6b46c24397c94c3faea44212ee76268d77
sha256: c57e011b02389358900df8c3c14c09b8b6b8e6e1c69c17153b59b61e09cae9d3
sha512: 91f68c17bc7388f44f4e424b16556ab67a2dd376e307e67b705c58d512df1db0089882c065d99f7b41a1b357e01716a3eb126321ab83967a2018f5565d158c48
ssdeep: 6144:puDH9zSF0Ygs91l35RSjfcIctrbc67dANNG8zieDB73sU9wEie+/:gDggQl35RLFrbcol8zie973wEE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12384CF5AD62A3610F3F70F747AA801AF2A51B36D026FED9DBD94578B1F7620316DC220
sha3_384: ae6b43389dc7631c38537f78583e10dd0b5cf5edcf8ed3da614c9c8e39f697293cd5b0e9f7dbc1d7b1650e6c72d391d5
ep_bytes: e233dc34b25a58b3b7bb5122a5f93998
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Ulise.459102 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Ulise.459102
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!A6E456155A12
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3263580
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.55a127
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
ClamAVWin.Packed.Razy-9873608-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Ulise.459102
NANO-AntivirusTrojan.Win32.Selfmod.ivuout
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kq
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Ulise.459102
FireEyeGeneric.mg.a6e456155a12722c
EmsisoftGen:Variant.Ulise.459102 (B)
IkarusTrojan-Downloader.Win32.FakeAlert
JiangminTrojan.Selfmod.bbhb
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.980
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Ulise.D7015E [many]
GDataWin32.Trojan.PSE.11XGYE9
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.y4Z@aiNtz3j
ALYacGen:Variant.Ulise.459102
MAXmalware (ai score=87)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Kryptik.GIRH

How to remove Ulise.459102?

Ulise.459102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment