Malware

Application.DealAgent.AFEH removal

Malware Removal

The Application.DealAgent.AFEH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.AFEH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.DealAgent.AFEH?


File Info:

name: EEFDCDAD5FA878754079.mlw
path: /opt/CAPEv2/storage/binaries/2f4fc9b6375aebdb6b92926aa1d2be079b0999daa20261a048e2494a585e4e60
crc32: EF4E7531
md5: eefdcdad5fa8787540796547c62243fb
sha1: 21380a90ac56f1d4f0b61172a19697ead2dabf02
sha256: 2f4fc9b6375aebdb6b92926aa1d2be079b0999daa20261a048e2494a585e4e60
sha512: b24ce7fa9257911fb41327ab77ecb678a3174ba99342c1eef89f5d9b798cc16c9266360e1688de60b36f301c0f019c07e34d48496518da8be1ab09dda31977e2
ssdeep: 24576:Cki+qW6VvdkM2hI2x0BCP1ZVDITR7GXo7qK81UN2mMz9EBdN+Mk+tasIte:CZFDVO3I2UCP1ZGRGdceMGsqe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C96533C2BEA698BCE050E7336E44BC15193B7C2918B63411B94D9BED5F376AAD80F311
sha3_384: ccadd402b7317185902d6026eb900ba9e7a60267d6f760cce4e197313ffbd79f7af630460a265f22fb485d54c7655b95
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Seb
FileDescription: Donapi Setup
FileVersion:
LegalCopyright: Lite
ProductName: Donapi
ProductVersion: 5.0.4
Translation: 0x0000 0x04b0

Application.DealAgent.AFEH also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.DealAgent.AFEH
FireEyeGeneric.mg.eefdcdad5fa87875
ALYacApplication.DealAgent.AFEH
CylanceUnsafe
SangforTrojan.Win32.Wacatac.A
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/InstallCore.9fd7c1bb
SymantecTrojan.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
ClamAVWin.Trojan.Agent-6402746-0
Kasperskynot-a-virus:AdWare.Win32.DealPly.cvkzs
BitDefenderApplication.DealAgent.AFEH
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Adware-gen [Adw]
Ad-AwareApplication.DealAgent.AFEH
SophosMal/Generic-S + InnoMod (PUA)
ComodoApplicUnwnt@#3r26mm199wkt2
TrendMicroPUA_InstallCore
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
EmsisoftApplication.DealAgent.AFEH (B)
GDataWin32.Application.InstallCore.LR@gen
WebrootPua.Downloadmanager
MAXmalware (ai score=72)
ViRobotAdware.Installcore.1533986
MicrosoftPUA:Win32/Vigua.A
CynetMalicious (score: 100)
McAfeeArtemis!EEFDCDAD5FA8
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.BundleInstaller
TrendMicro-HouseCallPUA_InstallCore
RisingAdware.InstallCore!1.AB2C (CLASSIC)
YandexPUA.DealPly!r6ElPjnYNv8
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Generic_PUA_CB
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.d5fa87
PandaTrj/CI.A

How to remove Application.DealAgent.AFEH?

Application.DealAgent.AFEH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment