Malware

Should I remove “Win32/Agent.ULI”?

Malware Removal

The Win32/Agent.ULI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ULI virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/Agent.ULI?


File Info:

crc32: F1376B8E
md5: 666f8d0c00671471e270c1f091d50ba0
name: 666F8D0C00671471E270C1F091D50BA0.mlw
sha1: 2ba592a694cfa2945a760ba3dca63fb121c6f661
sha256: 6cd76147f6b58d702a3f103353f54421239b838f00104ee86b1137734a396ccf
sha512: 3c4ae381efb929788cb7861e5d421a0bfaf1f3dc9d3800ed57ff802933af6fc0a114837ca288727042939ef4be1aeba5e5fd372c0e72f2da85330e3286ac8a21
ssdeep: 12288:gTiOXe8+8MdVfpwdVl3mTbOPz7SmPUJULjwY6ieEmsv7L:gTiOXVMdwvuKp8JA6iFv7L
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (c) Microsoft Corporation. All rights reserved.
InternalName: winaudio.exe
FileVersion: 1.0.0.1
CompanyName: Microsoft Corporation
ProductName: winaudio.exe
ProductVersion: 1.0.0.1
FileDescription: winaudio.exe
OriginalFilename: winaudio.exe
Translation: 0x0409 0x04b0

Win32/Agent.ULI also known as:

K7AntiVirusTrojan ( 005776e01 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader39.14250
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S20637061
ALYacGen:Variant.Graftor.962297
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2169622
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Mimdau.22d24f9d
K7GWTrojan ( 005776e01 )
Cybereasonmalicious.c00671
CyrenW32/Agent.CHX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ULI
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Mimdau-9870274-0
KasperskyHEUR:Trojan.Win32.Mimdau.vho
BitDefenderGen:Variant.Graftor.962297
NANO-AntivirusTrojan.Win32.Mimdau.iwbetw
MicroWorld-eScanGen:Variant.Graftor.962297
TencentMalware.Win32.Gencirc.10ce5758
Ad-AwareGen:Variant.Graftor.962297
SophosMal/Generic-R + Troj/Agent-BGQT
ComodoMalware@#1g40hosh0redq
BitDefenderThetaGen:NN.ZexaF.34236.JmMfaGd0pcjj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R035C0PF521
McAfee-GW-EditionBehavesLike.Win32.Fake.hc
FireEyeGen:Variant.Graftor.962297
EmsisoftGen:Variant.Graftor.962297 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Mimdau.br
AviraHEUR/AGEN.1142358
Antiy-AVLTrojan/Generic.ASMalwS.336D470
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.962297
AhnLab-V3Trojan/Win.Generic.R434216
McAfeeGenericRXAA-FA!666F8D0C0067
MAXmalware (ai score=84)
VBA32BScope.Trojan.Mimdau
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R035C0PF521
YandexTrojan.Mimdau!oKPmg5/H8pI
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.104417502.susgen
FortinetW32/Agent.ULI!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Agent.ULI?

Win32/Agent.ULI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment