Malware

Should I remove “Ulise.100315”?

Malware Removal

The Ulise.100315 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.100315 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Ulise.100315?


File Info:

crc32: C43DA8D4
md5: f2712b814b394659b33cb2e54584bb37
name: E5BD93E8B49DE5B882E59CBAE794B5E8A786E78988apk215_143152.exe
sha1: 912c2c375571adbf02363c63e4df7194f1bd6df0
sha256: 364c9c11abbde852e5d7d29c7e1ce295ba7bd8505178eb737bfb7b4033d7e13a
sha512: e3fd5cc12bd54e34b7aa6251da653591a1ee6309c6da22f6a7ad6890ced01293602714373ca774d8d458c611f2c7b9a889eebfd49a2fdabf15389a23f19e8c9c
ssdeep: 24576:MB+FvOMlXspw7nU6LtEeTR4kBFuHXxW4Z20gZzZVlSzJzndeNUPq+C:MBCqwbdZu3d00oVlSzJ7dep+C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0207
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0207
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Ulise.100315 also known as:

DrWebAdware.Qjwmonkey.168
MicroWorld-eScanGen:Variant.Ulise.100315
FireEyeGeneric.mg.f2712b814b394659
ALYacGen:Variant.Ulise.100315
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Ulise.100315
K7GWAdware ( 005105151 )
Cybereasonmalicious.14b394
TrendMicroTROJ_GEN.R002C0PBD20
CyrenW32/Adware.OBYM-0540
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:PUPX-gen [PUP]
GDataGen:Variant.Ulise.100315
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
AlibabaAdWare:Win32/Qjwmonkey.e7ce5d5d
NANO-AntivirusRiskware.Win32.Qjwmonkey.hamvws
Ad-AwareGen:Variant.Ulise.100315
SophosQjMonkey (PUA)
ComodoApplication.Win32.Qjwmonkey.HU@8hjovh
F-SecureHeuristic.HEUR/AGEN.1042852
ZillyaAdware.Qjwmonkey.Win32.615
Invinceaheuristic
McAfee-GW-EditionQJWMonkey
EmsisoftGen:Variant.Ulise.100315 (B)
IkarusPUA.Qjwmonkey
F-ProtW32/S-85fe4f21!Eldorado
JiangminDownloader.Generic.avgr
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1042852
Antiy-AVLGrayWare[AdWare]/Win32.Qjwmonkey
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D187DB
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Generic
MicrosoftPUA:Win32/Qjwmonkey
AhnLab-V3PUP/Win32.RL_Qjwmonkey.R287544
McAfeeQJWMonkey
MAXmalware (ai score=100)
VBA32BScope.Adware.Qjwmonkey
MalwarebytesAdware.ChinAd
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002C0PBD20
RisingAdware.Downloader!1.BDCA (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGFileRepMalware [PUP]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.121218.susgen

How to remove Ulise.100315?

Ulise.100315 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment