Malware

Win32/DealPly.JR potentially unwanted removal

Malware Removal

The Win32/DealPly.JR potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.JR potentially unwanted virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/DealPly.JR potentially unwanted?


File Info:

name: 3984B8A42455F5CF1A67.mlw
path: /opt/CAPEv2/storage/binaries/22f638a8f379044bd32a12a45daf65f436fec69bb017e13ffe978bac92851c32
crc32: 4AA5E096
md5: 3984b8a42455f5cf1a67c58697e8ddfb
sha1: 46f962f7c7d2006798a5b51b12133edbbbec2dc4
sha256: 22f638a8f379044bd32a12a45daf65f436fec69bb017e13ffe978bac92851c32
sha512: c1f23ff97059c0760d2a095b96c6c941f28909596ea9e3fee7df9da823a2b1ba01d84d72d92fd39631adea57e8a6966d460e6e10995703ad78ce32854e9a6f70
ssdeep: 6144:DwAPPMMVYgJPs8OdTz1Zb9STB/RmruTRDf5d26xB9/F:QMTJE3dVrudDfTBRF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3241297D4C4BD16C1E04BB5A3AFAB335B8AE5327BBD0F41CA86D04EEE384584806D0D
sha3_384: 17b6a63343b8b334c3476ed1affc7a24a05a4f955c27b5af5c546cb398d0a7720599bb9093365b1c0daee049238c0bc5
ep_bytes: 60be003044008dbe00e0fbffc7879ce0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/DealPly.JR potentially unwanted also known as:

LionicAdware.Win32.DealPly.2!c
MicroWorld-eScanAdware.DealPly.1.Gen
FireEyeGeneric.mg.3984b8a42455f5cf
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
ZillyaAdware.DealPly.Win32.32210
SangforTrojan.Win32.Agent.aa
K7AntiVirusAdware ( 00529a881 )
K7GWAdware ( 00529a881 )
Cybereasonmalicious.42455f
BitDefenderThetaGen:NN.ZelphiF.34294.nmGfa8Bsbfb
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.JR potentially unwanted
TrendMicro-HouseCallPUA_DEALPLY.SM
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.DealPly.yoqm
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusRiskware.Win32.DealPly.ekbczf
AvastFileRepMetagen [PUP]
TencentWin32.Adware.Dealply.Llhk
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA EG (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
SentinelOneStatic AI – Malicious PE
EmsisoftAdware.DealPly.1.Gen (B)
IkarusPUA.DealPly
GDataAdware.DealPly.1.Gen
JiangminAdWare.DealPly.dcmj
eGambitUnsafe.AI_Score_96%
AviraHEUR/AGEN.1126495
Antiy-AVLTrojan/Generic.ASMalwS.1722A84
MicrosoftProgram:Win32/Bitrepeyu.B
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C1931523
McAfeeArtemis!3984B8A42455
VBA32TScope.Trojan.Delf
MalwarebytesAdware.DealPly.Generic
APEXMalicious
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!b7EkWEHi8RA
MAXmalware (ai score=66)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
WebrootW32.Adware.Gen
AVGFileRepMetagen [PUP]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/DealPly.JR potentially unwanted?

Win32/DealPly.JR potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment