Malware

How to remove “AdWare.Win32.DealPly.dqqgf”?

Malware Removal

The AdWare.Win32.DealPly.dqqgf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dqqgf virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine AdWare.Win32.DealPly.dqqgf?


File Info:

crc32: 4D35BBF9
md5: 80e3e47d4f38ec345ff7112869906665
name: 80E3E47D4F38EC345FF7112869906665.mlw
sha1: 75495b465fc5e7a17cdd8e6e4965d449b354b765
sha256: 239d32c3c3ef27e79e4f3ffc2d718d1f889f24c02e7c2b9024967a13ca9718ae
sha512: aa57692368edca3c2bc6ebfd0880a797e036eb62af37c9210355838be7e658e2fd05f15dc818970e6dc1b3ae9dbb8d7ea70675fc116182a8b614b019f264dca8
ssdeep: 12288:kK4//izoDWd+l/Infzf7wGFu92iH/kp0rYnEx4VUcBEyRayLnpov0IOUyd:UizC2Ljwmu92iHcMYnEx49RayL6nyd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2011-2017
InternalName: Ninopim
FileVersion: 1.5.12.51
CompanyName: Tiduromab Ltd.
LegalTrademarks: Tiduromab Ltd.
ProductName: Kirohasu 16
ProductVersion: 2.6.5.98
FileDescription: Tagu Gedum
OriginalFilename: Ninopim.exe

AdWare.Win32.DealPly.dqqgf also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0053f9621 )
Elasticmalicious (high confidence)
MalwarebytesMalware.AI.734989795
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.0322a593
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.d4f38e
CyrenW32/DealPly.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.WU potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 99)
Kasperskynot-a-virus:AdWare.Win32.DealPly.dqqgf
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.fhmowc
MicroWorld-eScanAdware.DealPly.2.Gen
TencentWin32.Adware.Dealply.Eawx
Ad-AwareAdware.DealPly.2.Gen
BitDefenderThetaGen:NN.ZelphiF.34294.OmKfa4qO1odi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeAdware.DealPly.2.Gen
EmsisoftAdware.DealPly.2.Gen (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.DealPly.kihr
AviraHEUR/AGEN.1104226
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.274856B
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.DealPly.C2629638
Acronissuspicious
McAfeeArtemis!80E3E47D4F38
MAXmalware (ai score=99)
VBA32Adware.DealPly
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!OhWV3Mc+D0w
IkarusPUA.DealPly
FortinetW32/AGEN.1033829!tr
AVGWin32:Adware-gen [Adw]

How to remove AdWare.Win32.DealPly.dqqgf?

AdWare.Win32.DealPly.dqqgf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment