Malware

About “AdWare.Win32.DealPly.cpnea” infection

Malware Removal

The AdWare.Win32.DealPly.cpnea is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.cpnea virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AdWare.Win32.DealPly.cpnea?


File Info:

crc32: B497960F
md5: 161119b0492af48df5d2d65dc3b5e872
name: 161119B0492AF48DF5D2D65DC3B5E872.mlw
sha1: ed052d5bb13c3835947f3174a23eb29e5210565c
sha256: 7765a3100f66d408d60c3576260a4f61c177e2c6b7eff03336273abcaa77f3d7
sha512: b74a92f3b8c1e41bb50956cecd874ed2d6fc4dfa8dd2cf8a05ea83609ec12f3640f82aac74809c284644f39a3fe2d572f1c4f7e8b93e92a155357cb4c49d5a6c
ssdeep: 6144:ObUMcjJ+D2FEx6qKqGZwNdvnzSpGz38T:f+DgWQMnzSpU38
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Detaki Software Ltd. 2009-2016 All Rights Reserved
InternalName: Refog
FileVersion: 1.9.23.90
CompanyName: Detaki Software Ltd.
LegalTrademarks:
ProductName: Sihopolar
ProductVersion: 3.5.49.36
FileDescription: Docokan
OriginalFilename: RefogFegute.exe

AdWare.Win32.DealPly.cpnea also known as:

K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
ZillyaAdware.DealPly.Win32.90383
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.0492af
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/DealPly.JS potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.DealPly.cpnea
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Dvpp
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
BitDefenderThetaAI:Packer.940B0F6218
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.161119b0492af48d
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.fprx
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1126504
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.20B1F67
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1926284
Acronissuspicious
McAfeeArtemis!161119B0492A
MAXmalware (ai score=99)
VBA32Adware.DealPly
MalwarebytesMalware.AI.3376525161
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!Gp50Np4riHk
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.cpnea?

AdWare.Win32.DealPly.cpnea removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment