Malware

Ulise.103175 removal instruction

Malware Removal

The Ulise.103175 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.103175 virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
rl.ammyy.com

How to determine Ulise.103175?


File Info:

crc32: 6FE19817
md5: 390ddaff20160396e7490b239b4cad9b
name: a.exe
sha1: 44c10c691fc2639b3436abe8dc25542ff5a73067
sha256: 357230056c30b4d7a7d697114d3d90ddc9a13dcb174a9a6d1f74c950e5bcd570
sha512: fd9d519d5e0f3c7d5ac55d594ef23eff6b96e45efe582b8f2fb88c657d76dd4966de73faf4dcea02913940a46c2aa9a6cec8748bcdfb43530e0b3228f8eb833b
ssdeep: 12288:bWJDVSwZtyHFaMhY1SPEKH0OERt4PMsajW0pSEV3fugE:q7FZtoFaiY1SsKpERtMMRy0ptf7E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.9
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.9
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

Ulise.103175 also known as:

DrWebProgram.RemoteAdmin.900
MicroWorld-eScanGen:Variant.Ulise.103175
McAfeeRemAdm-Ammyy
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Variant.Ulise.103175
K7GWHacktool ( 005519b11 )
K7AntiVirusHacktool ( 005519b11 )
ArcabitTrojan.Ulise.D19307
Invinceaheuristic
CyrenW32/Trojan.CWQW-5031
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallTROJ_FRS.VSNTCI20
Paloaltogeneric.ml
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.zzq
AlibabaRiskWare:Win32/Ammyy.ff6acdb6
NANO-AntivirusRiskware.Win32.Ammyy.hfwywp
RisingMalware.Undefined!8.C (CLOUD)
Ad-AwareGen:Variant.Ulise.103175
EmsisoftGen:Variant.Ulise.103175 (B)
ComodoMalware@#1tlctzec0c24t
ZillyaTool.Ammyy.Win32.539
TrendMicroTROJ_FRS.VSNTCI20
McAfee-GW-EditionRemAdm-Ammyy
FortinetRiskware/RemoteAdmin_Ammyy
FireEyeGeneric.mg.390ddaff20160396
F-ProtW32/RemoteAdmin.L
JiangminRemoteAdmin.Ammyy.hu
WebrootW32.Ammyy.Ra
MAXmalware (ai score=99)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.zzq
AhnLab-V3Unwanted/Win32.RemoteAdmin.R278120
ALYacGen:Variant.Ulise.103175
CylanceUnsafe
PandaTrj/CI.A
APEXMalicious
YandexTrojan.Igent.bTuczr.39
SentinelOneDFI – Malicious PE
eGambitRAT.Ammyy
GDataWin32.Riskware.RemoteAdmin.A
MaxSecureVirus.Trojan.Ammyy.wrj
AVGFileRepMalware [PUP]
Cybereasonmalicious.f20160
AvastFileRepMalware [PUP]
Qihoo-360Win32/Trojan.Adware.37e

How to remove Ulise.103175?

Ulise.103175 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment