Malware

About “UDS:AdWare.Win32.DealPly.sb” infection

Malware Removal

The UDS:AdWare.Win32.DealPly.sb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:AdWare.Win32.DealPly.sb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs

How to determine UDS:AdWare.Win32.DealPly.sb?


File Info:

name: A513F35BB22062FBFDD3.mlw
path: /opt/CAPEv2/storage/binaries/5a3e47ae3d039c1cf1adbe6c28c689e5ca4b77a76ae9682b48764267d105b493
crc32: E7F8D4FA
md5: a513f35bb22062fbfdd33d78fdc6d5c8
sha1: 6ab5adb0e4f57dc246e2d4b0698f49d16edd84cd
sha256: 5a3e47ae3d039c1cf1adbe6c28c689e5ca4b77a76ae9682b48764267d105b493
sha512: e04873ee108a4c9f201cccb5d7ac8aef5a3cb2eff672623bf419b258fe3319f26c0ebf103e6186a1753f7cd8c0e73cf830de03c095c871ad7d1328a359d00432
ssdeep: 24576:ZVvrxjc+in3tu+A3f6ivp+ge90qX5z5MACcnIA6uw7D8dBGOygRs7b:ZpFbyklFvpqFzIADw7DSO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6453361B1860DF9D3B552700B46852CE77379BA3638149E30DE76AE9F739A1AC0B343
sha3_384: dcea97948bcf8d46752407c9667cc2ef1c906e0b488adc0cb370e0eb2a93f59126784f8096337f54bd38cd1f16f46735
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: AdworldInternet
FileDescription: installer setup
FileVersion: 1.0.1.1
LegalCopyright: AdworldInternet
ProductName: installer setup
ProductVersion: 1.0.1.1
Translation: 0x0000 0x04b0

UDS:AdWare.Win32.DealPly.sb also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.DealAlpha.1.Gen
FireEyeGeneric.mg.a513f35bb22062fb
McAfeeArtemis!A513F35BB220
MalwarebytesPUP.Optional.InstallCore
SangforPUP.Win32.InstallCore.1
Cybereasonmalicious.bb2206
SymantecSMG.Heur!gen
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H05KK21
Kasperskynot-a-virus:UDS:AdWare.Win32.DealPly.sb
BitDefenderApplication.DealAlpha.1.Gen
NANO-AntivirusTrojan.Win32.Agent.epgqoh
SUPERAntiSpywarePUP.InstallCore/Variant
EmsisoftApplication.InstallDeal (A)
ComodoMalware@#343lm0esntoco
DrWebAdware.Siggen.32544
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SentinelOneStatic AI – Suspicious PE
SophosQPDownload Download Manager (PUA)
GDataWin32.Application.InstallCore.KW
Antiy-AVLTrojan/Generic.ASSuf.BFD6
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
VBA32Malware-Cryptor.InstallCore.gen
ALYacApplication.Alphaeon.1.Gen
MAXmalware (ai score=78)
CylanceUnsafe
RisingAdware.InstallCore!1.AB2C (CLASSIC)
FortinetAdware/DealPly
WebrootAdware.Installcore
CrowdStrikewin/malicious_confidence_100% (D)

How to remove UDS:AdWare.Win32.DealPly.sb?

UDS:AdWare.Win32.DealPly.sb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment