Malware

Application.DealAgent.AHCB (file analysis)

Malware Removal

The Application.DealAgent.AHCB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.AHCB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Application.DealAgent.AHCB?


File Info:

crc32: 528E09A1
md5: 6b2d9dbeeaf0ce1f29e96581701e46ed
name: 6B2D9DBEEAF0CE1F29E96581701E46ED.mlw
sha1: bf6d629f87918fdef2ee6d6f4bc7707e33f6de3e
sha256: 79215a5e99c8298967eceed7b7b661475f16b0e3a57ef52b203c23917ed182ca
sha512: 428f5552b4ee987007b7a1413693322ca363447c67c094e3e596f7b4b51a446dca7e269bc0fccf3a37f4b48ed80f325d228b6b5f271e00e3797377526618deec
ssdeep: 24576:CycGFmDj2UwHej0Ykc08J9IAbAJIXTseAFEAMXQrABH919qRgMBTlP0QjcpMXVJ8:C5gmupHeTO8JKuAS8eTac19qRgGpf8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Gecamagen
Comments: This installation was built with Inno Setup.
ProductName: Fudopoh
ProductVersion: 1.4
FileDescription: Fudopoh Setup
Translation: 0x0000 0x04b0

Application.DealAgent.AHCB also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacApplication.DealAgent.AHCB
CylanceUnsafe
SangforAdware.Win32.InstallCore.1
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/InstallCore.25d14a2c
Cybereasonmalicious.eeaf0c
SymantecTrojan.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
APEXMalicious
AvastFileRepMalware [PUP]
Kasperskynot-a-virus:UDS:AdWare.Win32.DealPly.heur
BitDefenderApplication.DealAgent.AHCB
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanApplication.DealAgent.AHCB
Ad-AwareApplication.DealAgent.AHCB
SophosInnoMod (PUA)
ComodoMalware@#17y06v7j94f28
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
FireEyeGeneric.mg.6b2d9dbeeaf0ce1f
EmsisoftApplication.DealAgent.AHCB (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataWin32.Application.InstallCore.LR@gen
AhnLab-V3Malware/Gen.Generic.C2115229
McAfeeArtemis!6B2D9DBEEAF0
MAXmalware (ai score=99)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.BundleInstaller
PandaPUP/DealPly
RisingAdware.InstallCore!1.A30C (CLASSIC)
FortinetAdware/DealPly
AVGFileRepMalware [PUP]
Paloaltogeneric.ml

How to remove Application.DealAgent.AHCB?

Application.DealAgent.AHCB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment