PUA

PUP.Optional.DealPly malicious file

Malware Removal

The PUP.Optional.DealPly is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.DealPly virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUP.Optional.DealPly?


File Info:

name: 58A0DA4D37D731FD84E9.mlw
path: /opt/CAPEv2/storage/binaries/b07f100e3ddecf3d602f9acce54f65c8580ffecd31c054fdbeb0560b07e577a0
crc32: 3001B6FD
md5: 58a0da4d37d731fd84e910ca4bca2d20
sha1: c5dc54ddcb52dcb779c9d522ed81e056bc97a47b
sha256: b07f100e3ddecf3d602f9acce54f65c8580ffecd31c054fdbeb0560b07e577a0
sha512: cb1c8c88de6d4b6b59a76998a0c2f928f97717edaa4ae3473912b05ed5d9e10962ad8a707f8d09c73686b7176f234cc5060c9f1de726ef47da47d04aa2bf6137
ssdeep: 12288:T0MZbXqu6PPBAOOg3VBMQHmu8KGSprYA5fkg:rDqVS7gbVptrn5fr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175B46E32A6E288B3D16315788C5B57AA5C3A7D113D2958472BED3D0C6F383C3356E29B
sha3_384: 90d67645780dc976e2aa9ab21eb704b643adcd60cf910f3e1fe9a4b89c764509132e8ce1cadea7289c6d16384ebfef78
ep_bytes: 558bec83c4f0b8784d4600e8840cfaff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

PUP.Optional.DealPly also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.DealPly.1!c
Elasticmalicious (high confidence)
DrWebAdware.DealPly.260
MicroWorld-eScanAdware.DealPly.1.Gen
FireEyeGeneric.mg.58a0da4d37d731fd
CAT-QuickHealAdware.DealPly.AL8
McAfeeArtemis!58A0DA4D37D7
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00527c6a1 )
K7GWAdware ( 00527c6a1 )
Cybereasonmalicious.d37d73
BitDefenderThetaGen:NN.ZelphiF.34294.GGW@aCWixzpi
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DealPly.CV potentially unwanted
TrendMicro-HouseCallPUA_DEALPLY.SM
BitDefenderAdware.DealPly.1.Gen
AvastWin32:Adware-gen [Adw]
RisingAdware.DealPly!1.AA42 (CLASSIC)
Ad-AwareAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.PUPXKJ.hh
SentinelOneStatic AI – Malicious PE
SophosDealPly Updater (PUA)
IkarusPUA.DealPly
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1126495
Antiy-AVLTrojan/Generic.ASMalwS.16C7789
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
GDataAdware.DealPly.1.Gen
CynetMalicious (score: 100)
VBA32Adware.DealPly
MalwarebytesPUP.Optional.DealPly
APEXMalicious
TencentWin32.Risk.Adware.Sxoi
YandexRiskware.Agent!X0lcY7yHSMw
MAXmalware (ai score=66)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUP.Optional.DealPly?

PUP.Optional.DealPly removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment