Malware

AdWare.Win32.DealPly.dkfiz removal instruction

Malware Removal

The AdWare.Win32.DealPly.dkfiz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dkfiz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine AdWare.Win32.DealPly.dkfiz?


File Info:

crc32: 9383035E
md5: 11bbcdaf3326aded16b5b5cd22d95532
name: 11BBCDAF3326ADED16B5B5CD22D95532.mlw
sha1: 264130ee9f6992edfb247c54814e1d29efa6b436
sha256: dbdc16bc7936235c2a07ffc9278add25171e235f9d331c077615ccfe46edca8f
sha512: a4d6e5c9233edcc692258b161752b58221785894d5f20b40b6779cd5b136f19bd57af6a13be5f59571e6ab60de9808fe8fba21055e652c7133dce424108069d1
ssdeep: 24576:Ei5mkXdRon3kr71ppWOVqNbJzEVMclzyC94dqsCljbeamFs6tkeQ:ZmKHbpWAq1JwPyVI3mVQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 5.1.3.5
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Fosakasode
ProductVersion: 2.8
FileDescription: Fosakasode Setup
Translation: 0x0000 0x04b0

AdWare.Win32.DealPly.dkfiz also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
ALYacApplication.DealAlpha.1.Gen
CylanceUnsafe
ZillyaAdware.GenericKD.Win32.9948
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.eca772a2
SymantecPUA.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 99)
Kasperskynot-a-virus:AdWare.Win32.DealPly.dkfiz
BitDefenderApplication.DealAlpha.1.Gen
NANO-AntivirusVirus.InnoSetup.Gen.ccng
MicroWorld-eScanApplication.DealAlpha.1.Gen
TencentWin32.Adware.Dealply.Dxnf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.11bbcdaf3326aded
SophosInnoMod (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1110665
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.dkfiz
GDataWin32.Application.InstallCore.LX
McAfeeArtemis!11BBCDAF3326
MAXmalware (ai score=96)
RisingAdware.InstallCore!1.AB2C (CLASSIC)
YandexPUA.DealPly!9NAezPcSAdk
FortinetRiskware/InstallCore_Gen
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.dkfiz?

AdWare.Win32.DealPly.dkfiz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment