How to remove msedgewebview2.exe

msedgewebview2.exe

The module msedgewebview2.exe has been detected as Adware.DealPly

msedgewebview2.exe

msedgewebview2.exe is a Windows file recorded in the ThreatInfo database. It is associated with Microsoft Edge WebView2. The reported company name is Microsoft Corporation. The current detection status is Adware.DealPly, based on the latest analysis from 2024-08-12 23:01:58 (2 years ago).

If msedgewebview2.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Adware.DealPly.

Product Name: Microsoft Edge WebView2
Company Name: Microsoft Corporation
MD5: 502ccce84b75db97f169e35973095343
Size: 2 MB
First Published: 2023-09-14 23:03:00 (2 years ago)
Latest Published: 2024-08-12 23:01:58 (2 years ago)
Status: Adware.DealPly (on last analysis)
Analysis Date: 2024-08-12 23:01:58 (2 years ago)
Signed By: Nelogica Sistemas de Software Ltda.
Status: Valid

The signature on msedgewebview2.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%appdata%\nelogica\xptrader
%appdata%\nelogica\profit

ThreatInfo has observed msedgewebview2.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Brazil with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for msedgewebview2.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

msedgewebview2.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000ceb10

PE Sections:

Name Size of data MD5
.text 2289152 641f3129fc83f48e540504461516debc
.rdata 383488 55ca1cbeab6a9df06b77e02ff58ff902
.data 33792 612a5e0054448be716331f77f11cbcca
.pdata 73216 324ad3ae96ca3625c5ada18e294a4897
.00cfg 512 c3a2d1327b2f1641777efe36deda15f8
.retplne 512 60e7349e46063b144cf642326da037fd
.tls 512 9aa06f145d2598570c21005b86668587
.voltbl 512 d50fee10662cc21787b3b4f0787cd43f
CPADinfo 512 60d3ea61d541c9be2e845d2787fb9574
_RDATA 512 70a0fde97cff9b7be54bf233a4cbb62d
.rsrc 60928 e65cc21d15a326a4ff64e654139bb480
.reloc 11776 67a20ad22bf44370e6e5c45c6aa05b1e

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for msedgewebview2.exe