Malware

About “Win32/DealPly.QN potentially unwanted” infection

Malware Removal

The Win32/DealPly.QN potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.QN potentially unwanted virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Win32/DealPly.QN potentially unwanted?


File Info:

crc32: 8E8183F3
md5: c18dcf0d6c54b47beea2ec5b659d7b9e
name: C18DCF0D6C54B47BEEA2EC5B659D7B9E.mlw
sha1: 0ec0fbdd82fc4f6314eb6123ae54afce711f2eb2
sha256: 266c379b5d185b9cd9427b174073fe8bd3032bf59f5ebe7d7800abfcfc5f09c2
sha512: 8b4125194c626849478cfe4e46b0a762957f465866cbc4f71b785e927a5dbdcd072745761fbcf0efb840516b96181e3ed9b5efea2be93e0a57948c9185c16567
ssdeep: 24576:cXNVJ8NoUJAhJDYP1W2BZS4fw4D/uV99/4PqD59ZU:6s0DY/LS0uV99AY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Momo
FileVersion: 1.5.37.40
CompanyName: Kucorun
LegalTrademarks: 2009-2015
ProductName: Senuguf Mabidas Fabucacec
ProductVersion: 3.1.37.10
FileDescription:
OriginalFilename: momogoru.exe

Win32/DealPly.QN potentially unwanted also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0051ed201 )
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.1.Gen
CylanceUnsafe
ZillyaAdware.DealPly.Win32.220018
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.1627122f
K7GWAdware ( 0051ed201 )
Cybereasonmalicious.d6c54b
CyrenW32/DealPly.V.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/DealPly.QN potentially unwanted
APEXMalicious
AvastWin32:DealPly-AJ [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.DealPly.dfypp
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentMalware.Win32.Gencirc.10ba5b01
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA AO (PUA)
ComodoApplicUnwnt@#16a6eoq0q37yi
BitDefenderThetaGen:NN.ZelphiF.34236.8O0@ampnW7ci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.kilq
AviraHEUR/AGEN.1112084
MicrosoftTrojan:Win32/Occamy.C
ArcabitAdware.DealPly.1.Gen
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.dfypp
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C3108517
Acronissuspicious
McAfeeGenericRXAA-AA!C18DCF0D6C54
MAXmalware (ai score=67)
VBA32Adware.DealPly
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!LNWcRHMnjfE
IkarusAdWare.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DealPly
AVGWin32:DealPly-AJ [Adw]
Paloaltogeneric.ml

How to remove Win32/DealPly.QN potentially unwanted?

Win32/DealPly.QN potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment