Malware

About “AdWare.Win32.DealPly.dntqy” infection

Malware Removal

The AdWare.Win32.DealPly.dntqy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dntqy virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine AdWare.Win32.DealPly.dntqy?


File Info:

name: 611FC4B2D6F3874085C7.mlw
path: /opt/CAPEv2/storage/binaries/1cba2a9d55e5fbd145783197e92a1566913d11ebdfad23df99403eb4c6b8fcc5
crc32: 8216038A
md5: 611fc4b2d6f3874085c7abdb6fd07699
sha1: eac260cd6156d38477182755641db59c0ac24847
sha256: 1cba2a9d55e5fbd145783197e92a1566913d11ebdfad23df99403eb4c6b8fcc5
sha512: 467891529bbae1a00be2cf6516088622326810daa9dbb99905fcb0717c4acb4e450891612da4712573515110772918709a763e603324b94be22e29ca0db79b7d
ssdeep: 12288:9SRpDGw4ZnwSZ7Dsy6k8LXQ4sZAh4y/EtUGacdeWhMWzQmlIUKd:OFGbxkIZw/OUGaQe+MGQm6U8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198D423D5E6A46990CDDD7BB39420CAA85AE8F932195F3E6033C5D79F847B0B60F01782
sha3_384: 355070ab89239545bf953c8246589c1155c7fb7ab2b58930389a0782b5e936734a00a249e2a2630ede3dd4c28269d3a1
ep_bytes: 60be003058008dbe00e0e7ffc787100c
timestamp: 2012-10-03 21:09:32

Version Info:

CompanyName: Nusemeno Ltd.
FileDescription:
FileVersion: 3.9.21.1
InternalName: mesintona
LegalCopyright: Copyright 2009-2017
LegalTrademarks:
OriginalFilename: mesintona.exe
ProductName: Dabebarok Nabuteco Hesucil
ProductVersion: 1.3.35.64

AdWare.Win32.DealPly.dntqy also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.2.Gen
FireEyeAdware.DealPly.2.Gen
McAfeeArtemis!611FC4B2D6F3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforAdware.Win32.DealPly.Gen
K7AntiVirusAdware ( 0053f9621 )
AlibabaAdWare:Win32/DealPly.ca677596
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.2d6f38
BitDefenderThetaGen:NN.ZelphiF.34084.MmKfaKOKSYbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.WO potentially unwanted
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dntqy
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.fidmjc
TencentMalware.Win32.Gencirc.114d4cb8
Ad-AwareAdware.DealPly.2.Gen
EmsisoftAdware.DealPly.2.Gen (B)
ComodoApplicUnwnt@#3kidcmojd8tlp
ZillyaAdware.DealPly.Win32.176849
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
SophosDealPly Updater (PUA)
Paloaltogeneric.ml
JiangminAdWare.DealPly.jzfa
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1104226
Antiy-AVLTrojan/Generic.ASMalwS.26EF95D
MicrosoftTrojan:Win32/Occamy.C1C
GDataAdware.DealPly.2.Gen
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C2629638
VBA32Adware.DealPly
MAXmalware (ai score=99)
MalwarebytesMalware.AI.2664797169
APEXMalicious
RisingAdware.DealPly!1.AA42 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AGEN.1033829!tr
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove AdWare.Win32.DealPly.dntqy?

AdWare.Win32.DealPly.dntqy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment