Malware

What is “Ulise.459102”?

Malware Removal

The Ulise.459102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.459102 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ulise.459102?


File Info:

name: 09D2C2A4EC88BFCCB73E.mlw
path: /opt/CAPEv2/storage/binaries/31c5b8191bf544a0b81334f48be902f506f764f7f13029df91198a5084498214
crc32: F7012C94
md5: 09d2c2a4ec88bfccb73eaabf3d4e0a08
sha1: ce5638a5856a3c062d4040c709ba0133043fea41
sha256: 31c5b8191bf544a0b81334f48be902f506f764f7f13029df91198a5084498214
sha512: df862039a0723515e9e52348ba5690e9623b3b10baa49da7958a1084a60c5fccda9efca90304ba776cc1d5a9a40a6d143b0525ab57a181e73a88fcee5f84730d
ssdeep: 12288:T53B8mBK9aS++Wu99drbcol8zie973wEE:ThBFqaGxGA
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19C84D0ABDE5FBA11C3B503782E451ED32A60BB7E01266AC835F4499ADBB301539F5370
sha3_384: f123a9fdc5c3f15da881e2b96d3dc7cc5f5394da50a747d0205ea38367da1615f7915c78c7879922ea308b2edc501a3e
ep_bytes: 44b82da414d1a9231130a0b20372c808
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Ulise.459102 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.123
MicroWorld-eScanGen:Variant.Ulise.459102
SkyhighBehavesLike.Win32.HLLP.fc
McAfeePacked-FJB!09D2C2A4EC88
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3263580
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.5856a3
ArcabitTrojan.Ulise.D7015E [many]
BitDefenderThetaGen:NN.ZexaF.36608.y4Z@aiNtz3j
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9873608-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Ulise.459102
NANO-AntivirusTrojan.Win32.Kryptik.fjymkq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.kg
EmsisoftGen:Variant.Ulise.459102 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Ulise.459102
FireEyeGeneric.mg.09d2c2a4ec88bfcc
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cvyfi
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.989
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Ulise.459102
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ulise.459102?

Ulise.459102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment