Malware

Ulise.203979 removal guide

Malware Removal

The Ulise.203979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.203979 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Creates a hidden or system file

How to determine Ulise.203979?


File Info:

crc32: 60D56B71
md5: 9d4ea92e13d3b093f78906ca9d0eb5d0
name: 9D4EA92E13D3B093F78906CA9D0EB5D0.mlw
sha1: 3c124e9a196f6cd583460e6c8cd930223f655eb6
sha256: a42bf1a2d5d6fda0ff76a06e9e2c6abeef1d3751e9ba9cbbd5c3a3cd2f2edd65
sha512: 5090dac1fd59c7df01382086a2f14c98f3ef60b6355bff7933382b230c682c9915778f4ce9b9857acfbf209d224bd5e97c64d3445738e728454b9dc4dc0162a9
ssdeep: 12288:pjYBlZQKj3kEkjeQKji6UfHlf8VETpBe:tYB1zXcQG6UdfGN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Ontrack
FileVersion: 12.0.0.2
CompanyName: Ontrack
Comments: This installation was built with Inno Setup.
ProductName: Ontrackxae EasyRecoveryx2122 Home for Windows
ProductVersion: 12.0.0.2
FileDescription: Ontrack
Translation: 0x0000 0x04b0

Ulise.203979 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.60238
ClamAVWin.Trojan.Farfli-9833024-0
ALYacGen:Variant.Ulise.203979
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.33561
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0051149f1 )
K7AntiVirusTrojan ( 0051149f1 )
ESET-NOD32a variant of Win32/Farfli.CUB
APEXMalicious
AvastWin32:Downloader-TZT [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Farfli.brub
BitDefenderGen:Variant.Ulise.203979
NANO-AntivirusTrojan.Win32.Farfli.excnot
MicroWorld-eScanGen:Variant.Ulise.203979
TencentMalware.Win32.Gencirc.10b9cdb8
Ad-AwareGen:Variant.Ulise.203979
SophosML/PE-A + Mal/PdfExDr-B
BitDefenderThetaGen:NN.ZexaF.34758.cz0@aurKR4jP
TrendMicroBKDR_ZEGOST.SM40
FireEyeGeneric.mg.9d4ea92e13d3b093
EmsisoftGen:Variant.Ulise.203979 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.bog
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23739D3
MicrosoftBackdoor:Win32/Zegost.DE!bit
ArcabitTrojan.Ulise.D31CCB
GDataWin32.Backdoor.Farfli.H
TACHYONBackdoor/W32.Farfli.1082880
AhnLab-V3Backdoor/Win32.Zegost.C4342692
McAfeeGenericRXAA-AA!9D4EA92E13D3
MAXmalware (ai score=80)
VBA32BScope.Trojan.MulDrop
MalwarebytesSpyware.Socelars
TrendMicro-HouseCallBKDR_ZEGOST.SM40
RisingBackdoor.Zegost!1.D4C0 (CLASSIC)
YandexTrojan.GenAsa!0Afm94UHAik
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.74250093.susgen
FortinetW32/Farfli.CUB!tr
AVGWin32:Downloader-TZT [Trj]

How to remove Ulise.203979?

Ulise.203979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment