Malware

Win32/DealPly.WA potentially unwanted information

Malware Removal

The Win32/DealPly.WA potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DealPly.WA potentially unwanted virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/DealPly.WA potentially unwanted?


File Info:

name: 12B1388370E3CEE94C59.mlw
path: /opt/CAPEv2/storage/binaries/4de9c81f48206460672891bab1db65f664e2e0661a1397f501a1b68048650b02
crc32: A0300C0C
md5: 12b1388370e3cee94c594c1b2213cd37
sha1: ab688b40194d6ad502ec7632121e4a997477e46a
sha256: 4de9c81f48206460672891bab1db65f664e2e0661a1397f501a1b68048650b02
sha512: 6d98ff8d692644f66e0204d05186ac5d22c081177c4e0e74705a2be4a9cf4cbf44fe1583871ef7d44f5b42b5ddbad0c06a803d60129d4263c43723001c76a11e
ssdeep: 6144:J5++UtNkzvWaDZfX2Qq1GfrnCeCKEIV9yUNu+4sfysOZWK5Edb7xlO46:b+VtNQWaN+91JKBV9NyZZQ7/O46
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117847D72F6D18437C2632A3C9D9F53A4983ABE503D29684A2BE81D4C4F397C13979397
sha3_384: 9f6941e4af09017937df6186b1999fdf9943c66575fd2fc77ef3106283a08c8cbc632256931f5374f89c0fa5e6c726a9
ep_bytes: 558bec83c4f0b820dc4400e8b87dfbff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Picitif Ltd.
FileDescription:
FileVersion: 2.3.45.45
InternalName: Lose
LegalCopyright: Picitif Ltd. © 2011-2016
LegalTrademarks:
OriginalFilename: Lose.exe
ProductName: Kagapenuc Pacab
ProductVersion: 2.3.20.34

Win32/DealPly.WA potentially unwanted also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.1.Gen
FireEyeGeneric.mg.12b1388370e3cee9
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00529a881 )
BitDefenderAdware.DealPly.1.Gen
K7GWAdware ( 00529a881 )
Cybereasonmalicious.370e3c
BitDefenderThetaGen:NN.ZelphiF.34294.xG0@aqlX1Sei
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.WA potentially unwanted
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
AlibabaAdWare:Win32/DealPly.bd452b74
NANO-AntivirusTrojan.Win32.FraudLoad.jfqa
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqBczcD4RXKT9dhKo1Ju0Ms)
Ad-AwareAdware.DealPly.1.Gen
EmsisoftAdware.DealPly.1.Gen (B)
ComodoTrojWare.Win32.Downloader.Banload.arb@26luaz
McAfee-GW-EditionRDN/Generic PUP.z
SophosDealPly Updater (PUA)
APEXMalicious
MaxSecureTrojan.Malware.12132270.susgen
MAXmalware (ai score=66)
MicrosoftBrowserModifier:Win32/Prifou
SUPERAntiSpywarePUP.DealPly/Variant
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C3087931
McAfeeRDN/Generic PUP.z
VBA32TrojanDownloader.Banload
MalwarebytesMalware.AI.131486083
IkarusPUA.DealPly
PandaTrj/CI.A
TencentTrojan.Win32.BitCoinMiner.la
YandexPUA.DealPly!5aq/ZqRA5RM
eGambitUnsafe.AI_Score_93%
FortinetAdware/DealFly
WebrootW32.Adware.Gen
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/DealPly.WA potentially unwanted?

Win32/DealPly.WA potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment