Malware

About “AdWare.Win32.DealPly.aslaf” infection

Malware Removal

The AdWare.Win32.DealPly.aslaf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.aslaf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine AdWare.Win32.DealPly.aslaf?


File Info:

name: 709D95D4B6E1F6616CF5.mlw
path: /opt/CAPEv2/storage/binaries/6423dd646946d8e33bfc785a4c8867897f993ab931f9e72041d3d4f2e2d2771a
crc32: BC474917
md5: 709d95d4b6e1f6616cf516368177a2a1
sha1: df7007dd5bd789b9f35f485b02080db416cb4981
sha256: 6423dd646946d8e33bfc785a4c8867897f993ab931f9e72041d3d4f2e2d2771a
sha512: 3d69570a7f01e472fc6f602f4440d59a27b1911ba754a8b4a79f1e927e7d3a39f18fbc43dd25db9950aa66bb457595ef7efd62423fcce24121fe43b8e37aafdd
ssdeep: 24576:f7gluzPp0cEpD4MJtjklxCswq6PR7PRId6BxMQyGi7pMxs0mUC1:f78OP2Ukq21Pe6A9MeL7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17435235420D44A70C6F3C6F4AC7694FA07A33E255E74A90D728CE88D2F3FB81681E766
sha3_384: eb04a737e10118dfb24e475a41861e46e255841c769d4cb24ea5606c92b7c2da338b0821d796d75f0c49ed13cadee126
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Mapesiref Setup
FileVersion:
LegalCopyright:
ProductName: Mapesiref
ProductVersion: 2.4.4
Translation: 0x0000 0x04b0

AdWare.Win32.DealPly.aslaf also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanAdware.GenericKD.4871316
FireEyeGeneric.mg.709d95d4b6e1f661
ALYacAdware.GenericKD.4871316
CylanceUnsafe
SangforTrojan.Win32.Heuristic.rg
AlibabaAdWare:Win32/InstallCore.55385226
Cybereasonmalicious.4b6e1f
SymantecPUA.InstallCore!g11
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
ClamAVWin.Malware.Installcore-6912929-0
Kasperskynot-a-virus:AdWare.Win32.DealPly.aslaf
BitDefenderAdware.GenericKD.4871316
NANO-AntivirusVirus.InnoSetup.Gen.ccng
AvastFileRepMetagen [PUP]
TencentWin32.Adware.Dealply.Agbl
Ad-AwareAdware.GenericKD.4871316
SophosInnoMod (PUA)
F-SecureHeuristic.HEUR/AGEN.1203448
ZillyaAdware.DealPly.Win32.46045
McAfee-GW-EditionBehavesLike.Win32.PUPInstaller.tc
EmsisoftAdware.GenericKD.4871316 (B)
GDataAdware.GenericKD.4871316
JiangminAdWare.DealPly.lqpa
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1203448
MAXmalware (ai score=95)
KingsoftWin32.Troj.DealPly.(kcloud)
ArcabitAdware.Generic.D4A5494
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 99)
McAfeeArtemis!709D95D4B6E1
VBA32Malware-Cryptor.InstallCore.gen
MalwarebytesPUP.Optional.BundleInstaller
RisingAdware.InstallCore!1.AB2C (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetAdware/DealPly
AVGFileRepMetagen [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove AdWare.Win32.DealPly.aslaf?

AdWare.Win32.DealPly.aslaf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment