Malware

AdWare.Win32.DealPly.ddqlu removal guide

Malware Removal

The AdWare.Win32.DealPly.ddqlu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.ddqlu virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AdWare.Win32.DealPly.ddqlu?


File Info:

name: BF955C52C25B903B7251.mlw
path: /opt/CAPEv2/storage/binaries/7bae5fedeba334ec1022e1b41bdce242739c9e7697a1c39724e5a52b4b70853b
crc32: 18B35C6F
md5: bf955c52c25b903b7251b8988524b189
sha1: c8a609b28478cc5a3fea7979d5eb7c9c7f57f9eb
sha256: 7bae5fedeba334ec1022e1b41bdce242739c9e7697a1c39724e5a52b4b70853b
sha512: cb9e179ae25a406c50fabdaf8ad8cdcb51dbc7f71269314baca20fe73e4cfafa672c7fc32680006ab500931ac0f5feb05c3fad6eeae032c3b5a8a5d17378492c
ssdeep: 6144:SoR9AKivxJ/z9/sOC0K5gL/JWmihO3ZeksO2/hwms6:3loJ/pXKcVRUk525C6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1545422140D32E8AFD5EBD7311BBD2FB5C24C1186A1171A88E9B0488F4E15FEE1791BA7
sha3_384: c30dac00abffc73176d49b90e32877965131a4d2cdfed3756efabfbd0f796968ceffa6a95b4d2e91bd20fec2721c9de0
ep_bytes: 60be00d044008dbe0040fbffc7879ca0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

AdWare.Win32.DealPly.ddqlu also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
DrWebAdware.DealPly.260
ClamAVWin.Malware.Delphi-9845275-0
FireEyeGeneric.mg.bf955c52c25b903b
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
ZillyaAdware.DealPly.Win32.184404
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00529a881 )
AlibabaAdWare:Win32/DealPly.14c4fe24
K7GWAdware ( 00529a881 )
Cybereasonmalicious.2c25b9
BitDefenderThetaGen:NN.ZelphiF.34084.rmGfae6CSbd
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.XH potentially unwanted
TrendMicro-HouseCallPUA_DEALPLY.SM
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.DealPly.ddqlu
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Dealply.Pjnh
Ad-AwareAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosDealPly Updater (PUA)
IkarusAdWare.DealPly
GDataAdware.DealPly.1.Gen
JiangminTrojan/Pakes.uwu
AviraHEUR/AGEN.1201623
Antiy-AVLTrojan/Generic.ASMalwS.18D8716
GridinsoftRansom.Win32.Wacatac.sa
ViRobotAdware.Dealply.280576.WZ
MicrosoftTrojan:Win32/Wacatac.A!ml
SentinelOneStatic AI – Malicious PE
AhnLab-V3PUP/Win32.DealPly.C1921318
Acronissuspicious
McAfeeRDN/Generic PUP.x
VBA32AdWare.DealPly
MalwarebytesMalware.AI.3207633397
APEXMalicious
RisingAdware.DealPly!1.AA42 (CLASSIC)
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove AdWare.Win32.DealPly.ddqlu?

AdWare.Win32.DealPly.ddqlu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment