Malware

Application.DealAgent.ASKO removal guide

Malware Removal

The Application.DealAgent.ASKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ASKO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.DealAgent.ASKO?


File Info:

name: 2A1C2A01EC9F323C9160.mlw
path: /opt/CAPEv2/storage/binaries/ce73c82b0ee7b56e93e079e62d099a2c49e2cd9498990011efa56091bdef571e
crc32: A4D2F13C
md5: 2a1c2a01ec9f323c9160869532c90997
sha1: 5247501d38d75d77f16480c89ea33fe1972782f3
sha256: ce73c82b0ee7b56e93e079e62d099a2c49e2cd9498990011efa56091bdef571e
sha512: e4e0be91fe4737beb56e60f6d0bc5571e3c2c89cac2c7e4f31f1fa0948a2853874771389dcb5dd7e304a4737d86964d40f78d8273df94878d412bf61b3816153
ssdeep: 24576:CfEaT0uNnCb6ZqrNAjnhdYucjmngeDoG16OdKJO0sF4RsItG:Ccc0snCGZq5ADhdYneDGJICRsqG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F17533167AF1593EC2D05DB44FDA19111A2B2C1A9C72A04E758EADFC0FB77D8A0073B6
sha3_384: d7bcf99a025f28d4d96293bd8d53b3968d5922856e96df0820aee9efbe899d13733706862e22f81f1be11dbfd4938ecd
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Kokomad Setup
FileVersion: 2.6.5.1
LegalCopyright:
ProductName: Kokomad
ProductVersion: 1.6.6
Translation: 0x0000 0x04b0

Application.DealAgent.ASKO also known as:

LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.DealAgent.ASKO
FireEyeGeneric.mg.2a1c2a01ec9f323c
ALYacApplication.DealAgent.ASKO
AlibabaAdWare:Win32/InstallCore.ff71552f
Cybereasonmalicious.1ec9f3
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.DealPly.dgfmr
BitDefenderApplication.DealAgent.ASKO
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastFileRepMalware [PUP]
Ad-AwareApplication.DealAgent.ASKO
SophosInnoMod (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
EmsisoftApplication.DealAgent.ASKO (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.InstallCore.LR@gen
WebrootW32.Adware.Gen
ArcabitApplication.DealAgent.ASKO
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C2458766
McAfeeArtemis!2A1C2A01EC9F
VBA32BScope.Adware.DealPly
TrendMicro-HouseCallTROJ_GEN.R002H0CL921
RisingAdware.InstallCore!1.AB2C (CLASSIC)
YandexPUA.DealPly!ZOgr6Q3DTPI
FortinetAdware/DealPly
AVGFileRepMalware [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.DealAgent.ASKO?

Application.DealAgent.ASKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment