Malware

About “Ulise.103394 (B)” infection

Malware Removal

The Ulise.103394 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.103394 (B) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Ulise.103394 (B)?


File Info:

crc32: A31A8D1F
md5: 85ffb5fd2af48c793de02081738a877e
name: E8BF85E68DB7E8AFADE99FB3E8BDACE69687E5AD97E8BDACE68DA2E599A81554_459262.exe
sha1: f1dfba72f5dee6a18815caa6106ba3d9e05d41af
sha256: be0c8d6f56f746fb98c0e3acb86cd8dfd69d17a333ddce1d7af5294d0b3a7bc1
sha512: 020f820769c65236c8df95e43e4c0d4fbcc4c09600f55b45658973581a425d3aa1e86d935a926a6cdf72e2f157cb4e2d4e2feb50b5798fda161526f72342b0b5
ssdeep: 24576:U7WGksNMSumx86mbyZDXj7mUOHX2Jy1xBz9SwTtZsSomHG0txdk5:Lmx86Dz03q4Z3DHG0Tdk5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0318
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0318
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Ulise.103394 (B) also known as:

BkavW32.AIDetectVM.malware2
DrWebAdware.Qjwmonkey.168
MicroWorld-eScanGen:Variant.Ulise.103394
FireEyeGeneric.mg.85ffb5fd2af48c79
ALYacGen:Variant.Ulise.103394
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Ulise.103394
K7GWAdware ( 005105151 )
K7AntiVirusAdware ( 005105151 )
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Ulise.103394
Kasperskynot-a-virus:Downloader.Win32.Agent.mgdu
AlibabaAdWare:Win32/Qjwmonkey.df64b832
RisingAdware.Downloader!1.BDCA (CLOUD)
Endgamemalicious (high confidence)
SophosGeneric PUA PB (PUA)
ComodoApplicUnwnt@#1fdg9le4bkij7
F-SecureAdware.ADWARE/AD.QjwMonkey
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Ulise.103394 (B)
IkarusPUA.Qjwmonkey
CyrenW32/Adware.MWGX-6881
JiangminDownloader.Agent.myu
WebrootW32.Adware.Gen
AviraADWARE/AD.QjwMonkey.dneew
eGambitUnsafe.AI_Score_100%
Antiy-AVLRiskWare[Downloader]/Win32.Agent
ArcabitTrojan.Ulise.D193E2
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgdu
AhnLab-V3PUP/Win32.Installer.C4021483
McAfeeArtemis!85FFB5FD2AF4
MAXmalware (ai score=100)
VBA32BScope.Adware.Qjwmonkey
MalwarebytesAdware.Qjwmonkey
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CCP20
TencentMalware.Win32.Gencirc.10b96896
YandexPUA.Qjwmonkey!
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qjwmonkey.KD!tr
Ad-AwareGen:Variant.Ulise.103394
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Ulise.103394 (B)?

Ulise.103394 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment