Malware

Ulise.110633 removal guide

Malware Removal

The Ulise.110633 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.110633 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

ip.sap1000.com
as2.liuliangbao.cn
ts2.liuliangbao.cn
cltres.liuliangbao.cn
as1.liuliangbao.cn

How to determine Ulise.110633?


File Info:

crc32: E4A1FBBA
md5: 1c264ef9961d940c2bd237023089650f
name: ringowindows.exe
sha1: 9fe59b92fcfb89a276f9d588e30386ab6c3ecb14
sha256: 8a2578d76bbaa31b9407d21b79c193962699d6538f5798f8f52fbf4115603a08
sha512: 1a7777c32365d171d36c0132ed979a1798187ca84a34f12d9813048f09c59d00946b343d0d77626549a7002b92c2aadce6b3442489fea5577e94da735663fe0b
ssdeep: 24576:6EJG2a5pexxtPkMaJXiAbIKfb7VbcLRPlTruM4nGrr:tG2ep0oMmXiAbIwpbcLRPlTyMwGrr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2011
InternalName: Microsoft
FileVersion: 1.1.82.813
CompanyName: www.microsoft.com
ProductName: Microsoft
ProductVersion: 1.1.82.813
FileDescription: x6807x51c6MFCx7a0bx5e8f
OriginalFilename: Microsoft
Translation: 0x0000 0x04b0

Ulise.110633 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.110633
FireEyeGeneric.mg.1c264ef9961d940c
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Generic/HEUR/QVM10.2.9A38.Malware.Gen
McAfeeGenericRXGG-XH!1C264EF9961D
CylanceUnsafe
SangforMalware
K7AntiVirusAdware ( 005088371 )
BitDefenderGen:Variant.Ulise.110633
K7GWAdware ( 005128d91 )
Cybereasonmalicious.9961d9
TrendMicroTROJ_GEN.R002C0DGF20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Ulise.110633
Kasperskynot-a-virus:AdWare.Win32.Liuliangbao.ei
AlibabaBackdoor:Win32/Buterat.3823dcef
RisingBackdoor.Buterat!8.403 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.110633 (B)
ComodoApplicUnwnt@#m0gi5mqu92jk
F-SecureHeuristic.HEUR/AGEN.1126920
DrWebTrojan.DownLoader26.59979
ZillyaTrojan.GenericKD.Win32.131866
Invinceaheuristic
Trapminemalicious.moderate.ml.score
SophosGeneric PUA JP (PUA)
IkarusPUA.Liuliangbao
JiangminAdWare.Liuliangbao.ad
AviraHEUR/AGEN.1126920
MAXmalware (ai score=86)
Antiy-AVLGrayWare[AdWare]/Win32.Liuliangbao
ArcabitTrojan.Ulise.D1B029
SUPERAntiSpywareAdware.Liuliangbao/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.Liuliangbao.ei
MicrosoftBackdoor:Win32/Buterat.C!bit
CynetMalicious (score: 90)
AhnLab-V3Adware/Win32.Liuliangbao.C2632362
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Ulise.110633
Ad-AwareGen:Variant.Ulise.110633
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Liuliangbao.C potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0DGF20
TencentMalware.Win32.Gencirc.10b1cbc8
YandexPUA.Liuliangbao!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Liuliangbao
BitDefenderThetaGen:NN.ZexaF.34136.dv0@a028BPgj
AVGWin32:Malware-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.73626446.susgen

How to remove Ulise.110633?

Ulise.110633 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment