Malware

AdWare.Win32.DealPly.dfvfo removal

Malware Removal

The AdWare.Win32.DealPly.dfvfo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dfvfo virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine AdWare.Win32.DealPly.dfvfo?


File Info:

name: 30393D09AC205B830F7F.mlw
path: /opt/CAPEv2/storage/binaries/2348e976b0f03dda3cd82368d48f10a7eec47a81c75c846f1e453ccfb253c5e1
crc32: 812A4678
md5: 30393d09ac205b830f7f79e4cb5d90f9
sha1: d8ea91bfc8a50269d7f7b65447ecce1394264198
sha256: 2348e976b0f03dda3cd82368d48f10a7eec47a81c75c846f1e453ccfb253c5e1
sha512: 41ba83db09834ae2a643704339eaf96568d08f04cfc2a11a0d7c7d9e88ae460874796b416d61ccf2b1e16836d4f2540b019822c7d253e20c41bc23a34f43fc32
ssdeep: 12288:n64Gc3Vr3APXhZMxDk5miv7fhZAsCiNhwwWu:z9p3APXDMa4iv7fPvhLWu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196A4AF72B3F04A33D1372E7DDD1B92959829BE112D2824463FD86E8C5F3A781352E297
sha3_384: cf9b8e7e50bbefbde9479144a07e3cb58b2589f4e34dadd22d340a9b45a0562491cb8d193ee5d5854da247bad62b6901
ep_bytes: 558bec83c4f0b838804600e8b0cef9ff
timestamp: 2015-09-17 09:52:01

Version Info:

CompanyName: Ditaterak Software Ltd.
FileDescription:
FileVersion: 1.2.13.13
InternalName: Setimi
LegalCopyright:
LegalTrademarks: Ditaterak Software Ltd. trademark
OriginalFilename: Setimi.exe
ProductName: Locori Fenet Fekogoto
ProductVersion: 3.7.7.18
Translation: 0x0409 0x04e4

AdWare.Win32.DealPly.dfvfo also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.1.Gen
FireEyeGeneric.mg.30393d09ac205b83
McAfeeGenericR-LPX!30393D09AC20
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforVirus.Win32.Save.a
K7AntiVirusAdware ( 005393151 )
AlibabaAdWare:Win32/DealPly.72f1fed7
K7GWAdware ( 005393151 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZelphiF.34294.DK0@ai8kAGhi
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.WC potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OKL21
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.DealPly.dfvfo
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:DealPly-AJ [Adw]
TencentMalware.Win32.Gencirc.10b18ab0
Ad-AwareAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
ComodoApplicUnwnt@#3pp985z1a8ka1
ZillyaTool.Bundler.Win32.6081
TrendMicroTROJ_GEN.R002C0OKL21
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SophosDealPly Updater (PUA)
IkarusPUA.DealPly
GDataAdware.DealPly.1.Gen
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1125473
MAXmalware (ai score=61)
Antiy-AVLTrojan/Generic.ASMalwS.2454000
APEXMalicious
MicrosoftTrojan:Win32/Occamy.C23
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2407783
Acronissuspicious
VBA32Adware.DealPly
MalwarebytesMalware.AI.936451774
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexRiskware.Agent!Nb73CO2dGmc
SentinelOneStatic AI – Malicious PE
FortinetRiskware/DealPly
AVGWin32:DealPly-AJ [Adw]
Cybereasonmalicious.9ac205
PandaTrj/Genetic.gen

How to remove AdWare.Win32.DealPly.dfvfo?

AdWare.Win32.DealPly.dfvfo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment