Malware

AdWare.Win32.DealPly.danta malicious file

Malware Removal

The AdWare.Win32.DealPly.danta is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.danta virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.DealPly.danta?


File Info:

crc32: 157D918D
md5: 5bf7116e3ef843bca77c096f059595a7
name: 5BF7116E3EF843BCA77C096F059595A7.mlw
sha1: 48030b5c3499bb5b45f370e1954b5431088ae515
sha256: a4ce5aa086b789e88247e4f3839af101f13e0a4fd7c48f483d6ace07decfdbbe
sha512: d048f61b39ea23177cab025cc2a05ab69af77562f696aa7cb0c8c605616262007d428f92a4309c61e8c229e2df5caa9cbcbaeb9ee52e161eb55737963d7147a6
ssdeep: 6144:luP4pdqAYePCfCajbhruCxwIjk5R+UlCrxwaYl2WwEaLrg:cP4p4hUC6aP5fC86Cuaqav
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

AdWare.Win32.DealPly.danta also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00529a881 )
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
ZillyaAdware.DealPly.Win32.106798
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.e3ef84
CyrenW32/DealPly.AG.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DealPly.KY.gen potentially unwanted
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:AdWare.Win32.DealPly.danta
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Tapj
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA EI (PUA)
BitDefenderThetaAI:Packer.2911724F21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.5bf7116e3ef843bc
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.hvmq
AviraHEUR/AGEN.1142397
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.210B843
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitAdware.DealPly.1.Gen
GDataAdware.DealPly.1.Gen
AhnLab-V3Adware/Win32.DealPly.R192070
Acronissuspicious
McAfeeArtemis!5BF7116E3EF8
MAXmalware (ai score=96)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.475492962
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrjDw0cXWbmCABCG5Kf+hBW)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.danta?

AdWare.Win32.DealPly.danta removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment