Threat Database Adware Adware.Dealply.FB

Adware.Dealply.FB

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 10,483
Threat Level: 20 % (Normal)
Infected Computers: 2,882
First Seen: July 24, 2009
Last Seen: April 5, 2026
OS(es) Affected: Windows

Aliases

3 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Troj/Zlobie-Gen
Panda Suspicious file
AntiVir ADSPY/Toolbar.A.2

SpyHunter Detects & Remove Adware.Dealply.FB

File System Details

Adware.Dealply.FB may create the following file(s):
# File Name MD5 Detections
1. iesplugin.dll 9dbf91dee96498efd8f25fd78ff500e8 0

Analysis Report

General information

Family Name: Adware.Dealply.FB
Signature status: No Signature

Known Samples

MD5: ec304a9f0ac27bf041085f41c9fbdf0e
SHA1: d7a73fa9e8a7a95e68a4cfd74824ec7a13685671
File Size: 633.86 KB, 633856 bytes
MD5: a0a8a8cadeaac08a191081f4b50e9786
SHA1: cd45b81f10ca3bfc637832158e21e1d1b812ff29
File Size: 291.84 KB, 291840 bytes
MD5: 5e805c7cb29a3d360ab90c95aeb564e9
SHA1: 62c66f57c8466fdc333a8657f89771a8957f42fe
SHA256: D00A22ECDBA35D0D8BCFEEE260077F61B95A6004541AA3A38A162A06C222EAB9
File Size: 284.16 KB, 284160 bytes
MD5: 67c928cee09608f6597dec40437ad732
SHA1: eb88a24d5787306330f25c097f0242d05fa8aab9
SHA256: A613E986EAE81872681152F2A2E18F6F14B1210C6E14AA07C26A6ECEC82DB000
File Size: 852.48 KB, 852480 bytes
MD5: 4cc8a12f4c545923f61bf7497b498344
SHA1: 48ea087dd52918ed861670ef073b4902352a374d
SHA256: C864224BE6D21867C8A64E6337FF18ED6564831464A72B95D6DFA7DA637CF7A7
File Size: 344.58 KB, 344576 bytes
Show More
MD5: 5af8006d3313b8ae89e55b06d3e0365c
SHA1: 6980aa8cce72678c2962566953fc58f7742d13a5
SHA256: EC0A78B2926D915BBA410E5434944340AC1E333D29D6F329E985C6D36AA09184
File Size: 601.09 KB, 601088 bytes
MD5: 6a808c6aa34674ee845f071ff2b9ffc8
SHA1: 5d969b121b0b95254a4793c594cf643c6ab83f95
SHA256: A1E3B056025FEA4F47225CC0E0C5EE9B3CE785590F6D939E2EE47D25988ADE11
File Size: 288.26 KB, 288256 bytes
MD5: 3e5b1cd37314a70d74561f33917534c1
SHA1: 6697cf344a8cc705ae79ec61e3bda41b3a447394
SHA256: 93B1980FB058FF4F2CC6E0B35C34C9A7F0C79265A3D90C37DC05D39B787424A9
File Size: 529.92 KB, 529920 bytes
MD5: 3eddc5e638324c31be411f95a6118a3b
SHA1: 1696b26c7bc94276d929c1ab570e2e34f54966ce
SHA256: F87B83C5A8B53778375093573909F8B38872839DEAB571C44572172F198A5247
File Size: 537.09 KB, 537088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Bebererurepa
  • Danagam
  • Gebalisocoro Ltd.
  • Kihopegico Ltd.
File Description
  • Serul Naraki
  • Sibeb Ramecife
File Version
  • 3.4.7.0
  • 1.7.27.46
  • 1.7.12.34
  • 1.2.8.3
Internal Name
  • Bifinop
  • Cotihap
  • MaguceMefohe
  • Sufeco
Legal Copyright Gebalisocoro Ltd. All Rights Reserved
Legal Trademarks
  • Bebererurepa 2009-2016
  • Kihopegico Ltd.
Original Filename
  • bifinoprekapo.exe
  • cotihap.exe
  • MaguceMefohe.exe
  • Sufeco.exe
Product Name
  • Hanefub Nugod
  • Molapugeb Fope
  • Noco Dora
  • Torafa Kasi Kabodubih
Product Version
  • 3.2.33.70
  • 3.1.48.41
  • 2.4.40.67
  • 1.9.24.89

File Traits

  • HighEntropy
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 1,758
Potentially Malicious Blocks: 0
Whitelisted Blocks: 1,749
Unknown Blocks: 9

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.HJG
  • BadJoke.TH
  • Banker.GF
  • Banload.NB
  • Banload.XA
Show More
  • Banload.XN
  • Gamehack.PDFA
  • Injector.DFF
  • Injector.FGGA
  • Injector.FHBA
  • Injector.GDSA
  • Injector.KFE
  • Injector.KS
  • Kagee.A
  • Lamer.B
  • Proleeg.A
  • ScriptExpert.A
  • Trojan.Downloader.Gen.FD
  • Trojan.Downloader.Gen.MK
  • Trojan.Filecoder.Gen.BM
  • Trojan.Kryptik.Gen.FJ
  • Trojan.Kryptik.Gen.MM

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...