Malware

AdWare.Win32.DealPly.deeiq removal tips

Malware Removal

The AdWare.Win32.DealPly.deeiq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.deeiq virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.DealPly.deeiq?


File Info:

crc32: 0DFC5968
md5: ca48bb9d5ffa82237e44b5eca2bad087
name: CA48BB9D5FFA82237E44B5ECA2BAD087.mlw
sha1: 6601cbcdcb57fe4ac20ead39b9faf5b3d414c404
sha256: 238f3dae9c17447f46f574952aa09b7dd8009ea9c7a246923356734ea14244ba
sha512: a5983b5f3f888dbe6bb1cda573201eefd2373b8cda5a44ebf84f7c84acc9b4dc715ad9df3db8a4d9b21463e1724fbfe5422753481ec9a62c01cca1afd5487e3a
ssdeep: 6144:YVrtikLsoDgx2yTrmfBUnVBc4AxekKI/3s91hXhs50FwXP:YDLhDgMyTrASVa4eeOkHHFwX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Tohucomegu Software Ltd. All Rights Reserved
InternalName: sogiduh
FileVersion: 1.8.20.73
CompanyName: Tohucomegu Software Ltd.
LegalTrademarks: Tohucomegu Software Ltd.
ProductName: Solumad Kimopebi Lasid
ProductVersion: 1.8.42.52
FileDescription:
OriginalFilename: sogiduh.exe
Translation: 0x0409 0x04b0

AdWare.Win32.DealPly.deeiq also known as:

K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.d5ffa8
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/DealPly.JS potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.deeiq
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Syro
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#1qh40mdl07hlo
BitDefenderThetaGen:NN.ZelphiF.34294.rmKfa0rnRkmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.ca48bb9d5ffa8223
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126504
Antiy-AVLTrojan/Generic.ASMalwS.20A7A02
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1926284
Acronissuspicious
McAfeeArtemis!CA48BB9D5FFA
MAXmalware (ai score=97)
VBA32Adware.DealPly
MalwarebytesMalware.AI.4194283550
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!szOq7qwYy6s
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.deeiq?

AdWare.Win32.DealPly.deeiq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment