Malware

Ulise.84461 removal

Malware Removal

The Ulise.84461 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.84461 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Loads a driver
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

vt1.site

How to determine Ulise.84461?


File Info:

crc32: F5A71DB8
md5: bbff44266587696c22df81337ddf8178
name: vt.exe
sha1: c467da0e9db31d2356ff05a4c1f7254b778d262b
sha256: 15cb54089e89cd72b66b8c7d686297352e2617ad423b3385b399c7506becfc76
sha512: 5324b9562f9b8c66a9a6fbd1b66bfa861abb71d447148d4b2cc3e34e7f1fe68ab88d5137f794d8c7c9a846adaf615499d7d80be11262950e51f5b8ca893abd36
ssdeep: 6144:VRjbUHOvGUNIE/FDjBazqjWgR+MSEtvlZTONpRGX5B4PY3mA0O0Gp8Nhd5JodPU:Ljbh9tDjiuT+xEtl0u4w3mAZy+dMd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 360.cn All Rights Reserved.
InternalName: SoftMgr
FileVersion: 7, 5, 0, 1420
CompanyName: 360.cn
ProductName: 360x8f6fx4ef6x7ba1x5bb6
ProductVersion: 7, 5, 0, 1420
FileDescription: 360x8f6fx4ef6x7ba1x5bb6
OriginalFilename: SoftMgr.exe
Translation: 0x0804 0x04b0

Ulise.84461 also known as:

MicroWorld-eScanGen:Variant.Ulise.84461
FireEyeGeneric.mg.bbff44266587696c
CAT-QuickHealBackdoor.FarfliRI.S8943025
McAfeeTrojan-FRMW!BBFF44266587
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.36169
K7AntiVirusTrojan ( 0055a5d81 )
BitDefenderGen:Variant.Ulise.84461
K7GWTrojan ( 0055a5d81 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Agent.BOB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Ulise.84461
KasperskyTrojan.Win32.Staser.cszk
NANO-AntivirusTrojan.Win32.Farfli.gethzp
RisingBackdoor.Farfli!8.B4 (C64:YzY0Oj6WyyIdwWRS)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.84461 (B)
F-SecureTrojan.TR/Kryptik.kvtnn
DrWebTrojan.Siggen8.63629
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionTrojan-FRMW!BBFF44266587
MaxSecureTrojan.Malware.74728544.susgen
Trapminemalicious.moderate.ml.score
JiangminHeur:TrojanDropper.TDSS
AviraTR/Kryptik.kvtnn
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/GhostRAT.AA!MTB
ArcabitTrojan.Ulise.D149ED
ZoneAlarmTrojan.Win32.Staser.cszk
AhnLab-V3Trojan/Win32.RL_Farfli.R299612
Acronissuspicious
BitDefenderThetaAI:Packer.DF6F89F01F
ALYacGen:Variant.Ulise.84461
VBA32Backdoor.Farfli
MalwarebytesBackdoor.Ghost
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.DWFX
TencentMalware.Win32.Gencirc.10b0922c
SentinelOneDFI – Malicious PE
FortinetW32/Generic.AP.1EEA56A!tr
Ad-AwareGen:Variant.Ulise.84461
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.665876
AvastWin32:BackdoorX-gen [Trj]
Qihoo-360Win32/Trojan.e28

How to remove Ulise.84461?

Ulise.84461 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment