Malware

AdWare.Win32.DealPly.dorgw removal guide

Malware Removal

The AdWare.Win32.DealPly.dorgw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DealPly.dorgw virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine AdWare.Win32.DealPly.dorgw?


File Info:

crc32: 0ACD283C
md5: 0ca3e123a8c411a54f06174b3f2db77c
name: 0CA3E123A8C411A54F06174B3F2DB77C.mlw
sha1: 40c97f1746cc155a6d70aabe1106a1e657daea50
sha256: 1e0ef821e4ec4a3bad85ce8457a83e989ac278287400cca4bea19156f5538ce0
sha512: 04ae2c1885bdac7b68ffa312ac3c15ee30151128625aabafb0db02bfcb5946a3bf199124215fede5a3f6364e496e2772c087909c7f30c15f7429eb6e609ac908
ssdeep: 12288:tDBakheXg4920KWMLltjhSAADyLVlP6OsB7A5cyq+X7glW8UC:tp4BKWMLr0yu7B7A5cUrQh
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2009-2016
InternalName: sepapi
FileVersion: 2.7.37.0
CompanyName: Heponec
LegalTrademarks:
ProductName: Heneca Cogekiram
ProductVersion: 3.6.13.0
FileDescription: Moker
OriginalFilename: sepapi.exe
Translation: 0x0409 0x04b0

AdWare.Win32.DealPly.dorgw also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0053f9621 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.DealPly.Win32.155662
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.e183d8f5
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.3a8c41
CyrenW32/DealPly.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.TP potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dorgw
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.fhnaaq
MicroWorld-eScanAdware.DealPly.2.Gen
TencentMalware.Win32.Gencirc.10cc5237
Ad-AwareAdware.DealPly.2.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#2lrog0rl8trpt
BitDefenderThetaGen:NN.ZelphiF.34266.OmKfaCmQM6ii
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.0ca3e123a8c411a5
EmsisoftAdware.DealPly.2.Gen (B)
JiangminAdWare.DealPly.jolb
AviraHEUR/AGEN.1104226
Antiy-AVLTrojan/Generic.ASMalwS.2715916
MicrosoftTrojan:Win32/Occamy.C1E
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.DealPly.C2634512
McAfeeGenericRXAA-AA!0CA3E123A8C4
MAXmalware (ai score=99)
VBA32Adware.DealPly
MalwarebytesMalware.AI.2568267493
PandaTrj/Genetic.gen
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!yW9erIkD6Hw
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealPly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.DealPly.dorgw?

AdWare.Win32.DealPly.dorgw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment