Malware

Ulise.71561 removal instruction

Malware Removal

The Ulise.71561 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.71561 virus can do?

  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

api.ip138.com
ab.popodi.com
down.xiald.com
down.popodi.com
www.9973.com
xzqtj.xiald.com

How to determine Ulise.71561?


File Info:

crc32: AAA4CB10
md5: 037e669a6ae89fcada490879b01c0c63
name: _____________006_400004.exe
sha1: 45f1c6d5d7612f0f303f181b31e721b98fa0e2a2
sha256: 14c721a7d705c8d9274b862ea727429e9e2e97436fdc1838e966553c49766b4d
sha512: 0da012db192c456adec3310065e2712a59195e9f010cb195b6537d621cf781ee435b4dc1dffc805f2c14a20918c0252884efdaf4a1f29b8930176110cb1ca1a1
ssdeep: 49152:XzLVynqo1QE0O7Pfjouypc8ILJ0YiyLuetadb7L49aHWnxghMY0:dMqo4Ovouyp7o7ueta9HKxnxX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x9ad8x901fx4e0bx8f7dx5668
FileVersion: 1.5.3.19924
CompanyName: x9ad8x901fx4e0bx8f7dx5668
ProductName: x9ad8x901fx4e0bx8f7dx5668
ProductVersion: 1,5,3,19924
FileDescription: x9ad8x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Ulise.71561 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Ulise.71561
FireEyeGeneric.mg.037e669a6ae89fca
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXJC-ZY!037E669A6AE8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004d97001 )
BitDefenderGen:Variant.Ulise.71561
K7GWAdware ( 004d97001 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Ulise.71561
Kasperskynot-a-virus:AdWare.Win32.Agent.xxyqfl
AlibabaAdWare:Win32/Softcnapp.93104f24
ViRobotAdware.Ulise.2516904
RisingAdware.Downloader!1.BBEC (CLOUD)
Ad-AwareGen:Variant.Ulise.71561
EmsisoftGen:Variant.Ulise.71561 (B)
Comodofls.noname@0
DrWebAdware.Softcnapp.119
ZillyaAdware.Agent.Win32.145969
McAfee-GW-EditionGenericRXJC-ZY!037E669A6AE8
MaxSecureTrojan.Malware.74616564.susgen
SophosSoftcnapp (PUA)
CyrenW32/Trojan.SWQU-6616
JiangminAdware.Agent.akso
WebrootW32.Adware.Gen
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D11789
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.xxyqfl
MicrosoftPUA:Win32/CoinMiner
AhnLab-V3PUP/Win32.Softcnapp.R293787
ALYacGen:Variant.Ulise.71561
VBA32BScope.Adware.Puwaders
MalwarebytesPUP.Optional.Softcnapp
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
TencentMalware.Win32.Gencirc.10b0bbe3
YandexPUA.Agent!
SentinelOneDFI – Suspicious PE
FortinetAdware/Agent
AVGWin32:AdwareX-gen [Adw]
AvastWin32:AdwareX-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ulise.71561?

Ulise.71561 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment