Malware

AdWare.Win32.DealPly.eweij removal guide

Malware Removal

The AdWare.Win32.DealPly.eweij is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.eweij virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine AdWare.Win32.DealPly.eweij?


File Info:

name: FF6214BC4817A538D2A3.mlw
path: /opt/CAPEv2/storage/binaries/e9354b44cced0cacdc300f7627fcb9bac9252a9b104388e1ce9c7eb83333955c
crc32: 38A3145A
md5: ff6214bc4817a538d2a381be91fdbf05
sha1: ffc7f3470fe25a415e9e9e01f3c7d4527a7912fa
sha256: e9354b44cced0cacdc300f7627fcb9bac9252a9b104388e1ce9c7eb83333955c
sha512: 2bafb88724b7b5a6c760984a3f89dfc1e75df37d1854210bb1685b3af6a22da5e024b72a88aa72e2ded1356498714dcbb49f7fc2845c745a0e3d4a42c97ceb05
ssdeep: 49152:SZ94GG74GRSY+9eswgZB1Mrgmvq2TdbICn:8CxClDwgZPMxdbICn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5853312295845B0E6A0DE714EB7F0298E9B7E934C38431831DD2C5F5F7B7AA8726B13
sha3_384: d2c802ee2cadb8d231d5f97d52dd590f9cc3b924dbc90e2e0caa9c083b5a32fb87e4f9daa4c07d2cf12cb6a4b2eb5473
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Takasok
FileDescription: Somidap Setup
FileVersion: 3.6.1.7
LegalCopyright: Program
ProductName: Somidap
ProductVersion: 4.8.5
Translation: 0x0000 0x04b0

AdWare.Win32.DealPly.eweij also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
MicroWorld-eScanApplication.DealAlpha.1.Gen
FireEyeGeneric.mg.ff6214bc4817a538
ALYacApplication.DealAlpha.1.Gen
ZillyaAdware.DealPly.Win32.428188
K7AntiVirusAdware ( 005104a81 )
AlibabaAdWare:Win32/InstallCore.316eb4f3
K7GWAdware ( 005104a81 )
Cybereasonmalicious.c4817a
SymantecPUA.InstallCore!g1
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Malware.Installcore-6915943-0
Kasperskynot-a-virus:AdWare.Win32.DealPly.eweij
BitDefenderApplication.DealAlpha.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentWin32.Adware.Dealply.Egec
SophosQPDownload Download Manager (PUA)
VIPRETrojan.Win32.Generic!BT
EmsisoftApplication.DealAlpha.1.Gen (B)
GDataWin32.Application.InstallCore.LR@gen
MicrosoftTrojan:Win32/Wacatac.A!ml
MAXmalware (ai score=82)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.InstallCore
TrendMicro-HouseCallTROJ_GEN.R067H0CIG21
RisingAdware.InstallCore!1.AB2C (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetAdware/DealPly
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.12142056.susgen

How to remove AdWare.Win32.DealPly.eweij?

AdWare.Win32.DealPly.eweij removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment