Malware

Win32/DealPly.DQ potentially unwanted removal guide

Malware Removal

The Win32/DealPly.DQ potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.DQ potentially unwanted virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/DealPly.DQ potentially unwanted?


File Info:

name: 0C0E66E35AED3203A4F1.mlw
path: /opt/CAPEv2/storage/binaries/b7030b145d4b61655e694441bfe43e8c2bf1bb4d7ff96811f1dc3fce774c5e70
crc32: CB0E5CC8
md5: 0c0e66e35aed3203a4f19ccfb8d9d5ea
sha1: 2381c8399e1545777ea53c0b2644a3611fd43955
sha256: b7030b145d4b61655e694441bfe43e8c2bf1bb4d7ff96811f1dc3fce774c5e70
sha512: 97e143e06b834dff34dcba38291a3b75947005c4fc8bbdb433a37bcf337fe8733019137d124e7265245710b0a36e6d5349c5e9193ea88c4f5c522c97048cdacf
ssdeep: 6144:GF+Vfs/+Zuq24b7DSR9j15zyV+00r5Fw8W8ish9EEyqXMK15yhrh3zYy5oPxD+0Q:aqfsWAf1O+dFw8h3ES15yhZzb5QNhBk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134A48D32A5924CB3C122253CAD925A9FEC3B7E121D78A44677DD1FCCAB3D9C2351D18A
sha3_384: aaa2ee68f332721e82db0412bf8e37748c5ba566f5421a376ec8aeede901ce0d7350e0b36a4b3f1bdfa66f0e7887e2b2
ep_bytes: 558bec83c4f4b84c994600e82cc5f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/DealPly.DQ potentially unwanted also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0c0e66e35aed3203
CAT-QuickHealAdware.DealPly.B8
SkyhighBehavesLike.Win32.AdwareDealPly.gh
McAfeeAdware-DealPly
Cylanceunsafe
VIPREGen:Variant.Application.Bundler.DealPly.84
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00527c6a1 )
AlibabaAdWare:Win32/DealPly.f6e15a62
K7GWAdware ( 00527c6a1 )
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitTrojan.Application.Bundler.DealPly.84
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DealPly.DQ potentially unwanted
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.DealPly.qgiy
BitDefenderGen:Variant.Application.Bundler.DealPly.84
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Application.Bundler.DealPly.84
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.1150ba69
SophosDealPly Updater (PUA)
F-SecureAdware.ADWARE/DealPly.Gen2
DrWebAdware.DealPly.260
ZillyaAdware.DealPly.Win32.19345
TrendMicroTrojan.Win32.DEALPLY.SMJMP
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Application.Bundler.DealPly.84 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/DealPly.Gen2
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
XcitiumApplicUnwnt@#3k3mjz5msy4gz
MicrosoftBrowserModifier:Win32/Prifou
ViRobotAdware.Dealply.477696.SK
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.qgiy
GDataGen:Variant.Application.Bundler.DealPly.84
VaristW32/DealPly.J.gen!Eldorado
AhnLab-V3PUP/Win32.DealPly.R302011
BitDefenderThetaAI:Packer.C97AB9DE21
MAXmalware (ai score=99)
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.9827116.susgen
FortinetAdware/DealPly
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Win32/DealPly.DQ potentially unwanted?

Win32/DealPly.DQ potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment