Malware

Application.DealAgent.ACQR (file analysis)

Malware Removal

The Application.DealAgent.ACQR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ACQR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.DealAgent.ACQR?


File Info:

name: 29CB09162195430744C7.mlw
path: /opt/CAPEv2/storage/binaries/7ffb0b939d7aa6bbc6b9e578973a22d7806462a4b6977c30527ef1f1c758c320
crc32: CC2732DE
md5: 29cb09162195430744c70d323beecf6d
sha1: cb19f328dc3ea5517c83c2c450a9632fa9edb25d
sha256: 7ffb0b939d7aa6bbc6b9e578973a22d7806462a4b6977c30527ef1f1c758c320
sha512: 8acd22d6fe40d4d1077bf4b87d94a4426426c3a8b95b5ca7ae2b8d7f84e9f32d54cebc042c3f22e5b91afb2e044ebcbe43904966c095d0ba9808c5d1d308368c
ssdeep: 49152:yVFpbD4dylD/3fpfm6698lIo0eIN6SG9hEEY4zeAD:yDpbvh/P1g8l4N6tmyr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AFB53332C3C009BDC915D9B23EB1D56A35BD6B944C702447B2EE6EACCF17782598BB09
sha3_384: d8f6d0cda50e52f7dd772dfedcfeaff29259f37df028ef7a9d3a4641b38e72087a59c4fce7e966e7331606d4722d86ed
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Sikedor
FileDescription: Safise Setup
FileVersion:
LegalCopyright:
ProductName: Safise
ProductVersion: 2.8
Translation: 0x0000 0x04b0

Application.DealAgent.ACQR also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
CynetMalicious (score: 100)
McAfeeArtemis!29CB09162195
MalwarebytesPUP.Optional.BundleInstaller
SangforAdware.Win32.DealPly.dlbnh
AlibabaAdWare:Win32/InstallCore.9a9df285
CrowdStrikewin/grayware_confidence_100% (W)
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.DealPly.dlbnh
BitDefenderApplication.DealAgent.ACQR
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanApplication.DealAgent.ACQR
Ad-AwareApplication.DealAgent.ACQR
EmsisoftApplication.DealAgent.ACQR (B)
ComodoApplicUnwnt@#2ecnwm5fu2use
DrWebTrojan.InstallCore.3436
ZillyaAdware.DealPly.Win32.476244
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
FireEyeGeneric.mg.29cb091621954307
SophosInnoMod (PUA)
SentinelOneStatic AI – Malicious PE
WebrootPua.Downloadmanager
MicrosoftTrojan:Win32/Occamy.C7F
ArcabitApplication.DealAgent.ACQR
GDataWin32.Application.InstallCore.LX
Acronissuspicious
ALYacApplication.DealAgent.ACQR
MAXmalware (ai score=94)
VBA32Malware-Cryptor.2LA.gen
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H07BI22
RisingAdware.InstallCore!1.A30C (CLASSIC)
YandexPUA.DealPly!PJ+eVjy9y6s
FortinetAdware/DealPly
Cybereasonmalicious.621954

How to remove Application.DealAgent.ACQR?

Application.DealAgent.ACQR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment