Malware

What is “Bundler.DealPly.S2158578”?

Malware Removal

The Bundler.DealPly.S2158578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bundler.DealPly.S2158578 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Bundler.DealPly.S2158578?


File Info:

crc32: 1AF1533D
md5: 316bd25c8ebddeadb6f4dcea68ec9755
name: 316BD25C8EBDDEADB6F4DCEA68EC9755.mlw
sha1: 7760f620d03d025d9dcf446569de24ccb60b0c48
sha256: 236e04fa77cb906f5f529cdbe35942f4b9e19c4f34667ab2f7d393e046262a89
sha512: a90694085481132b59358c5ef1efc8178813fbe9bb91ee8ce628123a56949b5ab2cd8ee416566398d8c7457bbd670600b8d9a11af787a28cd1c786ef899e43d9
ssdeep: 24576:FGuzCskQmUbGz8TZro3Aqnni6YzkIKHgDgDABUSees1b/niiUK9mZocwNaYE53K:YqBkQzDTIHi7s9DA2SeFCKc7wS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Fapolim Software Ltd. xa9
InternalName: Lecup
FileVersion: 1.4.5.44
CompanyName: Fapolim Software Ltd.
LegalTrademarks: Fapolim Software Ltd.
ProductName: Tipoko Higimo
ProductVersion: 3.8.41.99
FileDescription: Celi Meh
OriginalFilename: lecuptemoru.exe
Translation: 0x0409 0x04b0

Bundler.DealPly.S2158578 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005497bb1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBundler.DealPly.S2158578
CylanceUnsafe
ZillyaAdware.DealPly.Win32.107203
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 005497bb1 )
Cybereasonmalicious.c8ebdd
CyrenW32/DealPly.AI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.TC potentially unwanted
APEXMalicious
AvastWin32:DealPly-AJ [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanAdware.DealPly.1.Gen
TencentMalware.Win32.Gencirc.10b6d3f1
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
BitDefenderThetaAI:Packer.584AE0F521
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.nenu
AviraHEUR/AGEN.1104226
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.250E528
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.R307349
Acronissuspicious
McAfeeGenericRXAA-AA!316BD25C8EBD
MAXmalware (ai score=64)
VBA32Adware.DealPly
MalwarebytesMalware.AI.331216481
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexRiskware.Agent!pGYfTq8lrGU
IkarusPUA.DealPly
FortinetW32/AGEN.1033829!tr
AVGWin32:DealPly-AJ [Adw]
Paloaltogeneric.ml

How to remove Bundler.DealPly.S2158578?

Bundler.DealPly.S2158578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment