Malware

How to remove “Ulise.103394”?

Malware Removal

The Ulise.103394 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.103394 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
w.nanweng.cn
a.tomx.xyz

How to determine Ulise.103394?


File Info:

crc32: 5AEA917C
md5: 52f7e3d07f33869341007080fec59f04
name: wpsoffice165002_3141.exe
sha1: b4fa60f90ff64bb0be4c6ff71fb0ba5dc88c7c87
sha256: 53cce3b421f75cb962aa997efc3143ae3e9b5aaec3a75041be88e06780c1894c
sha512: a13bf6fb6aa66fa68e8282e1588a64192f47558d08937b7f247ee7bead08bf0474ed7f173f9d8e8de82f889e19b292e7efe228c7b0007f6a7fd36cd4df9e6802
ssdeep: 24576:V7WGksNMSumx86mbyZDXj7mUOHX2Jy1xBz9SwTtZsSomHG0txdkN:Smx86Dz03q4Z3DHG0TdkN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0318
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0318
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Ulise.103394 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.103394
FireEyeGeneric.mg.52f7e3d07f338693
McAfeeArtemis!52F7E3D07F33
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Ulise.103394
K7GWAdware ( 005105151 )
Cybereasonmalicious.07f338
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R01FH0CCP20
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Ulise.103394
Kasperskynot-a-virus:Downloader.Win32.Agent.mgdt
AlibabaAdWare:Win32/Qjwmonkey.df64b832
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareGen:Variant.Ulise.103394
EmsisoftGen:Variant.Ulise.103394 (B)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA LE (PUA)
CyrenW32/Adware.AUIE-7911
JiangminDownloader.Agent.myu
WebrootW32.Adware.Gen
AviraADWARE/AD.QjwMonkey.dneew
Antiy-AVLRiskWare[Downloader]/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D193E2
AhnLab-V3PUP/Win32.Installer.C4021483
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgdt
MicrosoftPUA:Win32/Qjwmonkey
VBA32BScope.Adware.Qjwmonkey
ALYacGen:Variant.Ulise.103394
MAXmalware (ai score=100)
MalwarebytesAdware.Qjwmonkey
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b96896
YandexPUA.Qjwmonkey!
IkarusPUA.Qjwmonkey
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.121218.susgen

How to remove Ulise.103394?

Ulise.103394 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment