Malware

Win32/DealPly.TN potentially unwanted information

Malware Removal

The Win32/DealPly.TN potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.TN potentially unwanted virus can do?

  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Win32/DealPly.TN potentially unwanted?


File Info:

crc32: 5B5303FF
md5: 958e6a636534c0cce14a7e47d8fde8c7
name: 958E6A636534C0CCE14A7E47D8FDE8C7.mlw
sha1: 0469a1d0fc3bc703fbf2e6061cc404837ff9aa35
sha256: ddf501b0c122850270347eef2bc4cd0f12429e12e3dbf7c658e6cc271f424b96
sha512: 5821c554a0d1509b073597ea2d7e424110e9c363148f0ca954ceefcca9403962586be2ffb8a959f42a0bbd068f6e1aeeed5d68d0db536e6fa2e5b0259f7f9d41
ssdeep: 12288:I/4TdJqjZT8zjFItHFNJYGUMfHJNsqU7IDArLB5RsS:E9FTZtHFDvJNsnMDsz
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Nemikefirel Ltd. xa9 2012-2017 All Rights Reserved
InternalName: Lore
FileVersion: 1.1.21.35
CompanyName: Nemikefirel Ltd.
LegalTrademarks:
ProductName: Bubopot Lipomirek
ProductVersion: 1.5.42.19
FileDescription: Lisonok
OriginalFilename: lore.exe

Win32/DealPly.TN potentially unwanted also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.57924388
K7GWAdware ( 00529a881 )
Cybereasonmalicious.36534c
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/DealPly.TN potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.czgbb
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Htmc
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA AE (PUA)
BitDefenderThetaGen:NN.ZelphiF.34170.FmKfaicOAgei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.958e6a636534c0cc
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126504
Antiy-AVLTrojan/Generic.ASMalwS.1DE5A40
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.DealPly.gen
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1926104
Acronissuspicious
McAfeeArtemis!958E6A636534
MAXmalware (ai score=98)
VBA32Adware.DealPly
MalwarebytesMalware.AI.3351005483
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!qXabDh3p9HM
IkarusPUA.DealPly
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/DealPly.TN potentially unwanted?

Win32/DealPly.TN potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment