Malware

How to remove “Application.DealAgent.ARCN”?

Malware Removal

The Application.DealAgent.ARCN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ARCN virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Application.DealAgent.ARCN?


File Info:

crc32: C18602F2
md5: 4819595f16f6350803985dafb3a1b8f0
name: ff26ee52-6749-4ad9-8f44-94a2e17b99c6.exe
sha1: 6a75c9ce6d0ff86ca104f60b71d3b98b32b9cf52
sha256: 10f9448e035a682c5388d15ae8fcf2c2c7bdd4b328f7dfe653ee342637ef7b54
sha512: 55c8d0eece7887cafcde5a10776ceea8ddd3c757bd2f14d5fca226d6d079040467ca7f621bc274b1ed13c295af5cba2db20227022d8e83e89a84cf2dc3b50776
ssdeep: 49152:ABjrGGE/ON8L2RfL1oaaVcbCVrVxM0VUvKuqUSzvXFSXbH59KTn+FnxbdvuIn7:ejrGGEWN8iRowbcxM/pK7XQXbH59Y0nV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: MEmu Play
FileVersion: 1.0.1.1
CompanyName: MEmu Play
Comments: This installation was built with Inno Setup.
ProductName: Memu-Installer
ProductVersion: 1.0.1.1
FileDescription: MEmu Play Installer
Translation: 0x0000 0x04b0

Application.DealAgent.ARCN also known as:

MicroWorld-eScanApplication.DealAgent.ARCN
FireEyeGeneric.mg.4819595f16f63508
CAT-QuickHealTrojan.IGENERIC
Qihoo-360Generic/Application.c08
McAfeePUPInstaller
CylanceUnsafe
VIPREInstallCore (fs)
SangforMalware
K7AntiVirusAdware ( 0053d27f1 )
BitDefenderApplication.DealAgent.ARCN
Cybereasonmalicious.f16f63
Invinceaheuristic
ClamAVWin.Adware.Installcore-7170288-0
GDataWin32.Application.InstallCore.LR@gen
Kasperskynot-a-virus:AdWare.Win32.DealPly.ecedi
AlibabaAdWare:Win32/DealPly.93f07bef
NANO-AntivirusVirus.InnoSetup.Gen.ccng
RisingAdware.InstallCore!1.A30C (CLASSIC)
Ad-AwareApplication.DealAgent.ARCN
EmsisoftApplication.InstallCore (A)
ComodoMalware@#1q3n5owngvvig
F-SecureHeuristic.HEUR/AGEN.1042131
DrWebTrojan.InstallCore.3379
ZillyaTool.DealAgent.Win32.1467
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
Trapminemalicious.high.ml.score
SophosInstallCore (PUA)
JiangminDownloader.Generic.bhp
WebrootAdware.Installcore
AviraHEUR/AGEN.1042131
Endgamemalicious (high confidence)
ArcabitApplication.DealAgent.ARCN
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.ecedi
MicrosoftPUA:Win32/InstallCore
AhnLab-V3PUP/Win32.InstallCore.R241651
Acronissuspicious
MAXmalware (ai score=99)
VBA32Adware.DealPly
MalwarebytesAdware.InstallCore
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
YandexPUA.InstallCore!
SentinelOneDFI – Malicious PE
FortinetRiskware/InstallCore
AVGFileRepMalware [PUP]
PandaPUP/Multitoolbar
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecurenot-a-virus:AdWare.Win32.DealPly.ehppe

How to remove Application.DealAgent.ARCN?

Application.DealAgent.ARCN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment