Malware

Application.Bundler.DealPly.1 (file analysis)

Malware Removal

The Application.Bundler.DealPly.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.DealPly.1 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.DealPly.1?


File Info:

name: AA1807A8729EB057D8F8.mlw
path: /opt/CAPEv2/storage/binaries/a87a7d718c6467e8306ce95aa3d6fc9418e64fab469b20fcd8462a8cf9a0a0af
crc32: 7797CC83
md5: aa1807a8729eb057d8f8ac482901bdc0
sha1: ffd69ac31fc650e55331ba70e2ecf8dd0600a2d5
sha256: a87a7d718c6467e8306ce95aa3d6fc9418e64fab469b20fcd8462a8cf9a0a0af
sha512: f368a1108b0059d5f5e33f6505d9c1e35ce5782a4ddbdb0720c0c81db207d9210d4a9d7ea1fa3f8c96a9b4b18791e2f7afa829d02359271cd48a4ecb79ea9e57
ssdeep: 6144:De8pfOGE3xao60D6KFiB1KUVtb7zy+u0KoK5ZI+95mAQS4525ghyzgEXo:De8MVEZvbgNIKWughtE4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178748D7FF6D04C37D1232A7C9D8B5B64DD2ABE10292C28862BED1D4C5E396C179283D6
sha3_384: 94c4bdc1fad6263722c56ec08fa7f849c0bc20889284b953b06d340e9d4517b908caab172d3a9e4e718c79a14440027b
ep_bytes: 558bec83c4f4b8e4b44400e86ca5fbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Application.Bundler.DealPly.1 also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.DealPly.1
FireEyeGeneric.mg.aa1807a8729eb057
CAT-QuickHealAdware.DealPly.AL8
SkyhighBehavesLike.Win32.AdwareDealPly.fh
McAfeePUP-FOV
Cylanceunsafe
VIPREGen:Variant.Application.Bundler.DealPly.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/DealPly.3f2dc192
K7GWAdware ( 00527c6a1 )
K7AntiVirusAdware ( 00527c6a1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/DealPly.CA potentially unwanted
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:Evo-gen [Trj]
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
BitDefenderGen:Variant.Application.Bundler.DealPly.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentWin32.AdWare.Generic.Kflw
EmsisoftGen:Variant.Application.Bundler.DealPly.1 (B)
F-SecureAdware.ADWARE/DealPly.Gen2
DrWebAdware.DealPly.260
ZillyaAdware.DealPly.Win32.189196
TrendMicroTrojan.Win32.DEALPLY.SMJMP
Trapminemalicious.high.ml.score
SophosDealPly Updater (PUA)
WebrootPua.Gen
AviraADWARE/DealPly.Gen2
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.998
MicrosoftBrowserModifier:Win32/Prifou
XcitiumApplicUnwnt@#35qf0jgby3zo8
ArcabitTrojan.Application.Bundler.DealPly.1
ViRobotAdware.Dealply.357376.AVC
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataGen:Variant.Application.Bundler.DealPly.1
VaristW32/DealPly.J.gen!Eldorado
AhnLab-V3PUP/Win32.DealPly.C2018907
VBA32Trojan.Bitrep
ALYacGen:Variant.Application.Bundler.DealPly.1
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/DealPly.Gen2

How to remove Application.Bundler.DealPly.1?

Application.Bundler.DealPly.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment