Malware

Should I remove “Ulise.193920”?

Malware Removal

The Ulise.193920 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.193920 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ulise.193920?


File Info:

crc32: 90A83C11
md5: 4fea0b3777bac7a41f04669cfd213862
name: 4FEA0B3777BAC7A41F04669CFD213862.mlw
sha1: df69c6cd3c969f41f5b1f47f1f34450924a3fe82
sha256: b77fc7a5469affba23f8f4a3732da2b004940ebd8f9c54d9086e5fd7854dee37
sha512: 41c3610d478cf263c854ae3d2276b5b27074532958643168f0854a2c0d640ac1a05255d431abe801bebf284ba634b3882906773e8b3bde0b931018427f5abb3a
ssdeep: 24576:+faRoGRzatThRiVNbLGJv6plFh9iGa2oMYMgdsHGe9:+fs8TjFJspDLoVMgdkL9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Fuji Xerox Co., Ltd. 2016
InternalName: FXEzMkDsk
FileVersion: 1.3.0
CompanyName: Fuji Xerox Co., Ltd.
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Print Driver Installation Tool
SpecialBuild:
ProductVersion: 1.3.0
FileDescription: Print Driver Setup Disk Creation Tool
OriginalFilename: MakeDisk.exe
Translation: 0x0409 0x04b0

Ulise.193920 also known as:

K7AntiVirusTrojan ( 003dc1641 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.58694
ClamAVWin.Malware.Bzub-6727003-0
CAT-QuickHealTrojanToga.MUE.R9
McAfeePWSZbot-FIB!4FEA0B3777BA
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 003dc1641 )
Cybereasonmalicious.777bac
BaiduWin32.Trojan-Dropper.Injector.f
CyrenW32/S-24f4c04b!Eldorado
SymantecW32.Faedevour!inf
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
APEXMalicious
AvastWin32:Zbot-THZ [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.qxe
BitDefenderGen:Variant.Ulise.193920
NANO-AntivirusTrojan.Win32.Androm.ctymsi
ViRobotWin32.Daws.B
MicroWorld-eScanGen:Variant.Ulise.193920
TencentBackdoor.Win32.Androm.qxe
Ad-AwareGen:Variant.Ulise.193920
SophosML/PE-A + Troj/Mdrop-JIJ
ComodoTrojWare.Win32.Toga.PYF@7g9q1h
BitDefenderThetaGen:NN.ZexaF.34266.kr3@aChIGZni
TrendMicroBKDR_ANDROM_HA050002.UVPM
McAfee-GW-EditionPWSZbot-FIB!4FEA0B3777BA
FireEyeGeneric.mg.4fea0b3777bac7a4
EmsisoftGen:Variant.Ulise.193920 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Daws.byh
AviraTR/Dropper.Gen
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASBOL.CF5
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.Ulise.D2F580
GDataWin32.Trojan.PSE.12A3YX9
Acronissuspicious
VBA32BScope.Trojan.Autoit
MAXmalware (ai score=81)
MalwarebytesBackdoor.Andromeda
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ANDROM_HA050002.UVPM
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqAyZjVgL6EZ/CTiM0q2r/T)
YandexTrojan.GenAsa!zFH4sqyAwHU
IkarusBackdoor.Win32.Androm
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.AQV!tr
AVGWin32:Zbot-THZ [Trj]

How to remove Ulise.193920?

Ulise.193920 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment