Malware

Application.DealAgent.ATAU removal instruction

Malware Removal

The Application.DealAgent.ATAU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ATAU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.DealAgent.ATAU?


File Info:

name: 62EA29FE08836DA6EBB2.mlw
path: /opt/CAPEv2/storage/binaries/bc43ae473d5c2db56d262a022e4114234686207c52e3b2429981da822af63183
crc32: 8C9B174B
md5: 62ea29fe08836da6ebb284ad2e979a60
sha1: 2f6704728d877fc4ea54d69c6443aee59f545512
sha256: bc43ae473d5c2db56d262a022e4114234686207c52e3b2429981da822af63183
sha512: caaee1dbbba30974c47f1ed7460e675153b4324536dc22985f8a55e3c14f60a57ec815dde360bbc3ce0504f998538fa8729149192f763439f974c92ce0b175a1
ssdeep: 49152:hDs0vw7YEHfkarERCcIkA4QW9k0hS8WpLDkjw77p62lmCeAD:9s+wFtQRWkA4Q6kt8ufkjgV6qRr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9B53312EF94C0F8D063C6B404365A5A84F65F664D785D20262E08FEBF6B2346ED93DB
sha3_384: 1a260c40165e9f315ac46d4cddd3f17127a88babdd088d0f5e575948e862b387c94fcf8b0dfdead31fd749721aade814
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Bebobilul Setup
FileVersion: 4.4.3.4
LegalCopyright:
ProductName: Bebobilul
ProductVersion: 1.6
Translation: 0x0000 0x04b0

Application.DealAgent.ATAU also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanApplication.DealAgent.ATAU
ALYacApplication.DealAgent.ATAU
CylanceUnsafe
AlibabaAdWare:Win32/InstallCore.8027a438
Cybereasonmalicious.e08836
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.DealPly.easst
BitDefenderApplication.DealAgent.ATAU
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Adware-gen [Adw]
Ad-AwareApplication.DealAgent.ATAU
EmsisoftApplication.DealAgent.ATAU (B)
ComodoMalware@#1m5a04bnys5gb
ZillyaTool.DealAgent.Win32.2684
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
FireEyeGeneric.mg.62ea29fe08836da6
SophosInnoMod (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitApplication.DealAgent.ATAU
GDataWin32.Application.InstallCore.LR@gen
CynetMalicious (score: 100)
McAfeeArtemis!62EA29FE0883
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.InstallCore
RisingAdware.InstallCore!1.A30C (CLASSIC)
YandexPUA.DealPly!05s84wxdGjE
FortinetRiskware/InstallCore_Gen
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Application.DealAgent.ATAU?

Application.DealAgent.ATAU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment