Malware

About “AdWare.Win32.DealPly.cykdo” infection

Malware Removal

The AdWare.Win32.DealPly.cykdo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.cykdo virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.DealPly.cykdo?


File Info:

crc32: 4805C3F5
md5: 7cba8b24d85583aea9debf314d81b3b2
name: 7CBA8B24D85583AEA9DEBF314D81B3B2.mlw
sha1: 47b961c62e3215c4bee6447ef28b237668d58021
sha256: 214a0dbfe9e17f1d21e3d63ac4ac73a2f0e7d29150a8ec228a07b48f67d3a611
sha512: cdbbe034c416a4aa0a83be2b9dda05128d5944e9370895ef90345f7168a8fa82814852ace20e0c54ccf5b6698a18a13e0424b78b5d5ba23cd924b4971be01012
ssdeep: 6144:p/X2+sXIbSBkAcD53fxWu6GmHieYVMS34C+L6/66D9y3PuxaCnGs:ZViIOkAc535WuDi6VdIDLW6A9y3PusC
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

AdWare.Win32.DealPly.cykdo also known as:

K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.Dealply.ZZ8
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.4d8558
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/DealPly.JS potentially unwanted
APEXMalicious
AvastFileRepMetagen [PUP]
Kasperskynot-a-virus:AdWare.Win32.DealPly.cykdo
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Alje
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#213mt1pbfyhbs
BitDefenderThetaAI:Packer.17B478B116
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.7cba8b24d85583ae
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126504
Antiy-AVLTrojan/Generic.ASMalwS.1DDCDC1
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.R211480
Acronissuspicious
McAfeeGenericRXAA-FA!7CBA8B24D855
MAXmalware (ai score=95)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1326828726
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqMeuy6LEgn6i4X6uHY8srT)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.cykdo?

AdWare.Win32.DealPly.cykdo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment