Malware

AdWare.Win32.DealPly.dtxlw (file analysis)

Malware Removal

The AdWare.Win32.DealPly.dtxlw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dtxlw virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.DealPly.dtxlw?


File Info:

crc32: DC3C4023
md5: 1f7c12094bacaaecdd2ada4f299dff16
name: 1F7C12094BACAAECDD2ADA4F299DFF16.mlw
sha1: 7fe84cc051c80a763159625ba9e22e0fd096cf8c
sha256: 2376efe10a82ee51763799351bb821d4d6e937540a09a9b83b15d6201286bc28
sha512: 4ed65a17da8eddb0b6757edfc4cccabb96840588c92fbce9547b3443d346c6fe815fdc3d103aa8ac8b7495c13e987b32fd23db6c095445240be0c7d22c500dbf
ssdeep: 12288:HM+mpr05IGOrmSQUu2OQb7IQi5Y8depQkngtooD7prfWXH8sr:HMDAjsjD8Qi5KpQL+oD7pLWsW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Cobeb
FileVersion: 3.9.28.51
CompanyName: Geracamu Software
LegalTrademarks:
ProductName: Gekumo
ProductVersion: 1.4.39.32
FileDescription: Lekuluf
OriginalFilename: cobebmecekel.exe

AdWare.Win32.DealPly.dtxlw also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0053f9621 )
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.DealPly.Win32.189173
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.c8accdad
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.94baca
CyrenW32/DealPly.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.TP potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dtxlw
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.fimvfc
MicroWorld-eScanAdware.DealPly.2.Gen
TencentWin32.Adware.Dealply.Ebhs
Ad-AwareAdware.DealPly.2.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#29auhtcd4be3m
BitDefenderThetaAI:Packer.0F332E1A21
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.1f7c12094bacaaec
EmsisoftAdware.DealPly.2.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.jyuy
AviraHEUR/AGEN.1104226
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.277E3E4
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.DealPly.C2862822
Acronissuspicious
McAfeeGenericRXAA-AA!1F7C12094BAC
VBA32Adware.DealPly
PandaTrj/Genetic.gen
YandexPUA.DealPly!MDFWn3dl/6I
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DealPly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.dtxlw?

AdWare.Win32.DealPly.dtxlw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment