Malware

Should I remove “AdWare.Win32.DealPly.cxwro”?

Malware Removal

The AdWare.Win32.DealPly.cxwro is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.cxwro virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AdWare.Win32.DealPly.cxwro?


File Info:

crc32: A0663D5A
md5: cbf8d883879fec47fc5cbbf41d12c6c8
name: CBF8D883879FEC47FC5CBBF41D12C6C8.mlw
sha1: b0df6dd347f50a659ccc03143c6cf0ad959a34cf
sha256: 03937fc16209e4c1a847c2e6eaa03a8762166fba3df1a0810452a138c93712e9
sha512: d8bea966f32b289b59cafde298d121e51d2cb9e0bd8faca64b39f9ee20e7f9ed45ae573b713401565eb7d1b202973fe15136149a2e82cb9e8a2ef5989f1a15e7
ssdeep: 12288:VC9TEMaPRYvYQp4PtT4yJAIqLrrIXd9nCxSwiULuJH+h:8sPRYk2krnSxiUu+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

AdWare.Win32.DealPly.cxwro also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005223711 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 005223711 )
Cybereasonmalicious.3879fe
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DealPly.KM.gen potentially unwanted
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Dropper.Nanocore-9810750-0
Kasperskynot-a-virus:AdWare.Win32.DealPly.cxwro
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Tdfs
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#3fstdrib2k9ie
BitDefenderThetaGen:NN.ZelphiF.34266.JmGfaeHU!9
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.cbf8d883879fec47
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.jhqi
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1126510
Antiy-AVLTrojan/Generic.ASMalwS.1DDD9AE
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataWin32.Application.DealPly.AL
AhnLab-V3PUP/Win32.DealPly.C1924730
Acronissuspicious
McAfeeArtemis!CBF8D883879F
MAXmalware (ai score=97)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.281651028
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.cxwro?

AdWare.Win32.DealPly.cxwro removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment