Malware

How to remove “Application.DealAgent.AGFA”?

Malware Removal

The Application.DealAgent.AGFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.AGFA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Application.DealAgent.AGFA?


File Info:

crc32: 3278111D
md5: 2976bb5d6da21579918ff3709703a23e
name: 2976BB5D6DA21579918FF3709703A23E.mlw
sha1: a8b31b51fb3ec654266f0d946bba53c106f10966
sha256: af29341bf0b012f6c89f28f416af100cb585651748756d11d0060a215bbf685a
sha512: f398ed4221e8e85d7b86dedd5836f276492f74946e4d5318983e8cb20f7cadb205b67a5a5f2e4b96feaa8e6c94748dbda6bbca7b4a90e2eb015d426d8721b055
ssdeep: 24576:kfveIjzIw/6KgRnrPNHmMZOk1WxQHak156Dj3K3p7Hf82C8/MBTlP0QjcpMXVJow:kXwJGMZOkQxRkX33pr68/Gpfr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Ripamepego
Comments: This installation was built with Inno Setup.
ProductName: Sofuge
ProductVersion: 1.3.7
FileDescription: Sofuge Setup
Translation: 0x0000 0x04b0

Application.DealAgent.AGFA also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacApplication.DealAgent.AGFA
CylanceUnsafe
ZillyaTool.DealAgent.Win32.4161
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderApplication.DealAgent.AGFA
Cybereasonmalicious.d6da21
SymantecPUA.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.DealPly.czzvw
AlibabaAdWare:Win32/InstallCore.c8902444
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanApplication.DealAgent.AGFA
Ad-AwareApplication.DealAgent.AGFA
SophosInnoMod (PUA)
ComodoMalware@#nxe7ti7utqus
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.2976bb5d6da21579
EmsisoftApplication.DealAgent.AGFA (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataWin32.Application.InstallCore.LR@gen
AhnLab-V3PUP/Win32.InstallCore.C2387701
McAfeeArtemis!2976BB5D6DA2
MAXmalware (ai score=100)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.BundleInstaller
RisingAdware.InstallCore!1.A30C (CLASSIC)
FortinetAdware/DealPly

How to remove Application.DealAgent.AGFA?

Application.DealAgent.AGFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment