Malware

What is “Ulise.459102”?

Malware Removal

The Ulise.459102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.459102 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ulise.459102?


File Info:

name: CBDBC5B76012DF6A126E.mlw
path: /opt/CAPEv2/storage/binaries/2f9a1cd1ceac99b9216753f3b73813b3822e26f382f5099955bc14d4acbdd58f
crc32: 82550389
md5: cbdbc5b76012df6a126e88d557d2708a
sha1: 5137b66ca7abb8a038299afdbfb5fd373b15a5dc
sha256: 2f9a1cd1ceac99b9216753f3b73813b3822e26f382f5099955bc14d4acbdd58f
sha512: 47b9ce51f0700723183e9839572e79c8b399b787d351297b92fce4cc5fde08c95798646ebe175b3c90e2209abf05a8c681fd4fad3823ab34e36ead5a18e4b80b
ssdeep: 6144:tBL7Jl8QoMZovOvECYO+QNWgLoftUo4Oktwrbc67dANNG8zieDB73sU9wEie+/:bZl8KvEDQN0ft7Swrbcol8zie973wEE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C584C0DFF246FD10CFE903787B272293AB1C7A6C311BA2A77970156A49E340469F5638
sha3_384: acd17b56d0ab490197bb523281172ec4d9bc8f4f628009de8b7fc09897f63a5c8c5275197c7351dc6c095ddf21ae3a33
ep_bytes: 0d2c9e445d451ac358a413524ae67be8
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Ulise.459102 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.459102
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!CBDBC5B76012
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3263580
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.ca7abb
ArcabitTrojan.Ulise.D7015E [many]
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9873608-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Ulise.459102
NANO-AntivirusTrojan.Win32.Selfmod.jwjvjq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.kg
EmsisoftGen:Variant.Ulise.459102 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Ulise.459102
FireEyeGeneric.mg.cbdbc5b76012df6a
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.bbhb
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36608.y4Z@aiNtz3j
ALYacGen:Variant.Ulise.459102
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ulise.459102?

Ulise.459102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment