Malware

Ulise.170087 removal tips

Malware Removal

The Ulise.170087 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.170087 virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ulise.170087?


File Info:

name: 8644A7FEDF896EDBC624.mlw
path: /opt/CAPEv2/storage/binaries/80bc3fce8af5fc6c14c768672691d17a4b6d8d4f7b049fcedac694a2f8dd77ef
crc32: 333F64EA
md5: 8644a7fedf896edbc624dca4821bd4c6
sha1: 7d1fafc2818bb12b7befe51d0f72bd4599c4a555
sha256: 80bc3fce8af5fc6c14c768672691d17a4b6d8d4f7b049fcedac694a2f8dd77ef
sha512: 45ff6319a8940d9a3d3982fa7d95fc19086436c7b7dfd76bb48296b047b7bb55f35b731a66fea85ad34bf9c0f511f7702b2024e2d5cfadc91c941bd2531cec74
ssdeep: 6144:9u/wbE79p90J1XUNjJa2ggOSY2dB/4B9FGUlOOtmGIdH:Rg9p9SUNjJa2gCR7/UYUlvRKH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3B5DF4171E44476F1FF3A302EB54B258AB5BC311531D90FA3A079877EB1A82EC2576B
sha3_384: 263b211cb86c14c1306c5bef4db4518e92139c108ea832c525c7f5121d2709c2867f97baf73fdc5195486992d2d01bac
ep_bytes: 6a706890544100e8e201000033db538b
timestamp: 2019-11-26 07:14:39

Version Info:

Translation: 0x040c 0x04b0
Comments: This software is exclusively part of LiberKey. Request for other use must be applied to contact@liberkey.com
CompanyName: LiberKey.com
FileDescription: LiberKey
LegalCopyright: Copyright © LiberKey.com
LegalTrademarks: LiberKey is a Trademark of Captel SARL
ProductName: LiberKey
FileVersion: 5.08
ProductVersion: 5.08
InternalName: LiberKey
OriginalFilename: LiberKey.exe

Ulise.170087 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Waldek.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.8644a7fedf896edb
McAfeeArtemis!8644A7FEDF89
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Waldek.8a9c4d58
K7GWTrojan ( 0055cd8a1 )
K7AntiVirusTrojan ( 0055cd8a1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GZDX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Waldek-7543622-0
KasperskyHEUR:Trojan.Win32.Waldek.pef
BitDefenderGen:Variant.Ulise.170087
NANO-AntivirusTrojan.Win32.Waldek.hjdjou
MicroWorld-eScanGen:Variant.Ulise.170087
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10b86512
Ad-AwareGen:Variant.Ulise.170087
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WL421
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftGen:Variant.Ulise.170087 (B)
IkarusTrojan.Crypt
GDataGen:Variant.Ulise.170087
AviraHEUR/AGEN.1115124
Antiy-AVLTrojan/Win32.Waldek
ArcabitTrojan.Ulise.D29867
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Ulise.170087
MAXmalware (ai score=81)
VBA32Trojan.Waldek
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_GEN.R002C0WL421
YandexTrojan.Waldek!OE3uTC5mbgE
FortinetW32/Injector.EJFO!tr
AVGFileRepMalware
Cybereasonmalicious.edf896
PandaTrj/CI.A

How to remove Ulise.170087?

Ulise.170087 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment