Malware

Win32/DealPly.KM potentially unwanted malicious file

Malware Removal

The Win32/DealPly.KM potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.KM potentially unwanted virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/DealPly.KM potentially unwanted?


File Info:

crc32: 2D39B76F
md5: 63035ce631bfa8d55ee017eddf4e1aaa
name: 63035CE631BFA8D55EE017EDDF4E1AAA.mlw
sha1: c8e80c8dc6320a6167339ee0ba98dcf6064a5dd2
sha256: 15bebad8c6bd60ee10aa47396bd6e8a08ada8595343aafdd1b7fb10aa8b551a4
sha512: a8158989787440c5f309195ad0d8133e93ba5ba5cfc77b54405436e38976fdbdaeaa87a4df220992b32ed582b94275ad4d7e10d2fd28ae56df23f426e5dbccf7
ssdeep: 6144:Uh9PTt4oK/2RHq0NPGF0DHc/zO5qNMtfDYu8ClUyP5L2mv+Tpk:QTiok2hq0NPJLgNMtfDYunN+lk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Hatidom
FileVersion: 1.5.32.43
CompanyName: Fogod
LegalTrademarks: Fogod 2010-2015
ProductName: Ganorek Saru
ProductVersion: 2.6.42.54
FileDescription:
OriginalFilename: Hatidom.exe

Win32/DealPly.KM potentially unwanted also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005223711 )
LionicAdware.Win32.Generic.lTSM
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.b674030e
K7GWAdware ( 005223711 )
Cybereasonmalicious.631bfa
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/DealPly.KM.gen potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.bqdru
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusRiskware.Win32.DealPly.fhhtvb
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Wkvj
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#3vj3ahw853cwo
BitDefenderThetaAI:Packer.DF8019D118
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.63035ce631bfa8d5
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126510
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.19071C8
KingsoftWin32.Troj.Dealply.Wk.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitAdware.DealPly.1.Gen
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.DealPly.gen
GDataWin32.Application.DealPly.AL
AhnLab-V3PUP/Win32.DealPly.C2638976
Acronissuspicious
McAfeeArtemis!63035CE631BF
MAXmalware (ai score=61)
VBA32Adware.DealPly
PandaTrj/GdSda.A
TrendMicro-HouseCallPUA_DEALPLY.SM
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!44u09FzKjS4
IkarusPUA.DealPly
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/DealPly.KM potentially unwanted?

Win32/DealPly.KM potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment