041013_y.exe

DealPly

DealPly Technologies Ltd

The application 041013_y.exe by DealPly Technologies has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program VuuPC, You're Always a Click Away! by installCore which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.airdlr6.com and multiple other hosts.
Publisher:
DealPly Technologies Ltd  (signed and verified)

Product:
DealPly

Version:
4.7.5.9

MD5:
4b4f478a9c377ec6c44ff59c4d0873f0

SHA-1:
27f63c928a3441cb5b1d1c1e6cf4e80099c30d20

SHA-256:
3442f6987909a0762a8882b13affc6936dd34184682cf267317d6016721b3fa2

Scanner detections:
15 / 68

Status:
Adware

Analysis date:
12/23/2024 12:37:30 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod16e.Trojan
1.3.0.4613

Dr.Web
Adware.Shopper.328
9.0.1.0352

ESET NOD32
Win32/DealPly
7.9174

Fortinet FortiGate
Adware/Agent
12/18/2013

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.174.10509

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.4603

Malwarebytes
PUP.DealPly
v2013.12.18.08

nProtect
Trojan-Clicker/W32.Agent.1279744.B
13.12.15.01

Reason Heuristics
PUP.DealPly.I
14.8.7.17

Trend Micro House Call
TROJ_GEN.R047H05I913
7.2.352

Trend Micro
ADW_DEALPLY
10.465.18

Vba32 AntiVirus
Trojan.MSIL.Zapchast
3.12.24.3

VIPRE Antivirus
Adware.DealPly
24378

XVirus List
Win32.Detected
2.8.7

File size:
1.2 MB (1,279,744 bytes)

Product version:
4.7.5.9

Copyright:
Copyright (C) 2012 DealPly Technologies Ltd

Trademarks:
[dealplydef:dealplydef] - DealPly is a trademark or registered trademark of DealPly Technologies Ltd in the U.S. and/or other countries.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\041013_y.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/13/2012 9:00:00 PM

Valid to:
6/14/2015 8:59:59 PM

Subject:
CN=DealPly Technologies Ltd, O=DealPly Technologies Ltd, STREET=13 Barth St., L=Tel Aviv, S=Israel, PostalCode=69104, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
016DFA78310264827B57EAD4F620C264

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:2KamF1ya45mgr31s2cRIFezHHzEGN+k9+KJo31s2cRIFezHHAb:3TzUmgr3WbRZznIjE+KK3WbRZznAb

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file 041013_y.exe has been discovered within the following programs.

The software uses the InstallCore Click run software which is an installer that bundles legitimate applications that may also offer additional third party applications that may be unwanted by the user.
www.vuupc.com
71% remove it
 
Powered by Should I Remove It?

The file 041013_y.exe has been seen being distributed by the following 4 URLs.

http://cdn.airdlr6.com/downloads/offers/.../dp.exe

Remove 041013_y.exe - Powered by Reason Core Security