Malware

AdWare.Win32.DealPly.epkdo removal

Malware Removal

The AdWare.Win32.DealPly.epkdo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.epkdo virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Loads a driver
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz
ascstats.iobit.com

How to determine AdWare.Win32.DealPly.epkdo?


File Info:

crc32: A9DC06E6
md5: 432c0ebec3e204fa0212c54a6a540a2a
name: smart.defrag.setup.exe
sha1: 9f6bff69bb22015df6e0f6f2067f482cc6980a60
sha256: 11cb17451bb8973a4fa0cad7b0dc322ee5c3133d5d19ca8b6328abe95642b45c
sha512: 093f6333866620f9dc8aaa0525b3998fa7a18205ec4c34ead5b3b849d70f60b711afbe83f4964d34edbea3b7cec8e13b8543d07a3c70fa9abdf0637e2d0b0373
ssdeep: 393216:H+v/0smonSkf+aAKRdQatrvMVhwoARuTc7AFxIzG:eXHvnSkHdQaNehwdAoG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2005-2018
FileVersion: 5.8.0.1276
CompanyName: IObit
Comments: This installation was built with Inno Setup.
ProductName: Smart Defrag 5
ProductVersion: 5.8.0
FileDescription: Smart Defrag 5
Translation: 0x0000 0x04b0

AdWare.Win32.DealPly.epkdo also known as:

McAfeeArtemis!432C0EBEC3E2
CylanceUnsafe
AvastWin32:Malware-gen
GDataWin32.Application.iObit.B
Kasperskynot-a-virus:AdWare.Win32.DealPly.epkdo
NANO-AntivirusTrojan.Win32.InstallCore.ftbbnt
DrWebProgram.Unwanted.1183
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.epkdo
VBA32Adware.DealPly
ESET-NOD32a variant of Win32/IObit.AL potentially unwanted
eGambitPUP.Optional.IObit
AVGWin32:Malware-gen

How to remove AdWare.Win32.DealPly.epkdo?

AdWare.Win32.DealPly.epkdo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment