Malware

How to remove “AdWare.Win32.DealPly.eyoyv”?

Malware Removal

The AdWare.Win32.DealPly.eyoyv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.eyoyv virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine AdWare.Win32.DealPly.eyoyv?


File Info:

name: 9239996596A54CE9F062.mlw
path: /opt/CAPEv2/storage/binaries/bbad90da288124d5b062dcfc7af4934b9d57d7a922b0d9d48c173f63a8e9385b
crc32: 224606B5
md5: 9239996596a54ce9f0626c33a5ed68fd
sha1: f2f3c03f0b676def4cb69acfea93ac48bec02192
sha256: bbad90da288124d5b062dcfc7af4934b9d57d7a922b0d9d48c173f63a8e9385b
sha512: 31e83d4ff5691a813cba81e1bb5cae090627ce13126b4e58a55d83ce850d0002828db78cdc9ba6c0180d71c8434dbd87b42c0b674b9fa34c52f68c8fa4fe6534
ssdeep: 12288:2gQ/LDfxMbGha9ak0Kj9bwhpNLqfecGFGGQYOUuX66YT/q+WoddJadl+/T3v/:ZQzaboaJ0KjmRKesGQYOxYT/ZF/jH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101E423C6E59167DDC2E26777B455825E050ED90B9B7AA27013CCC2A38EF0AF31D42F19
sha3_384: 88b227a07568d5ee458428cac26a92049e78a2338328986ddd0d0a2c91add1192f2e0bf24564b6a917c886f781a0992b
ep_bytes: 60be00605a008dbe00b0e5ffc78710ac
timestamp: 2013-09-08 06:04:27

Version Info:

CompanyName: Pokesadetama Ltd.
FileDescription: Kof
FileVersion: 1.3.11.1
InternalName: Tonage
LegalCopyright: Pokesadetama Ltd. © 2012-2017
LegalTrademarks:
OriginalFilename: Tonage.exe
ProductName: Pekukehit Semabic
ProductVersion: 3.3.46.42

AdWare.Win32.DealPly.eyoyv also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.2.Gen
FireEyeGeneric.mg.9239996596a54ce9
CylanceUnsafe
ZillyaAdware.DealPly.Win32.390951
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0053f9621 )
AlibabaAdWare:Win32/DealPly.43ba2d72
K7GWAdware ( 0053f9621 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/DealPly.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.WO potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
Kasperskynot-a-virus:AdWare.Win32.DealPly.eyoyv
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.irmadu
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Dealply.Hqld
Ad-AwareAdware.DealPly.2.Gen
SophosDealPly Updater (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftAdware.DealPly.2.Gen (B)
GDataAdware.DealPly.2.Gen
JiangminAdWare.DealPly.npux
AviraHEUR/AGEN.1201179
Antiy-AVLTrojan/Win32.Wacatac
ArcabitAdware.DealPly.2.Gen
ViRobotAdware.Dealply.676352.AQK
MicrosoftBrowserModifier:Win32/Prifou
AhnLab-V3PUP/Win32.DealPly.C4087455
McAfeeArtemis!9239996596A5
MAXmalware (ai score=60)
VBA32Adware.DealPly
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingPUF.DealPly!1.AA42 (CLOUD)
YandexRiskware.Agent!C2gA5ZXPdO8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/AGEN.1033829!tr
BitDefenderThetaGen:NN.ZelphiF.34160.PmKfaufAmIii
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.596a54
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove AdWare.Win32.DealPly.eyoyv?

AdWare.Win32.DealPly.eyoyv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment