Malware

Application.DealAgent.ATBD (file analysis)

Malware Removal

The Application.DealAgent.ATBD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ATBD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.DealAgent.ATBD?


File Info:

name: E513300D4813DBE997F6.mlw
path: /opt/CAPEv2/storage/binaries/796d2d43cd2b74f3b6b9cb56c85c3a1fbc50f0bbd6e584ccd0e6f4efbfaf8b1b
crc32: 59C93938
md5: e513300d4813dbe997f64b42c5418fe3
sha1: 38e89cf0df589e9599b26694187eac845a51cfc7
sha256: 796d2d43cd2b74f3b6b9cb56c85c3a1fbc50f0bbd6e584ccd0e6f4efbfaf8b1b
sha512: 3f8770398bf1e31a70eef0d3a2db082fb919c5ffc72bb3541eca1d7afe9dd2756864e0b6a414d07c4073c43e662db006bbd7cd1e4ee7147ea7dce821172b8afb
ssdeep: 24576:593FrbPSvsq6Xl2KAHUjNdhuvfprbMfp2ZgooFawJTCvdlXw6Il6CmFs6tkeQ:XVrbzXY4ovfprbYwKNawYdlAHMHVQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118453302E5E50136EDB3953D2E2185901E9FBF383C75A09675AEEFDC3BD21A6061B384
sha3_384: 0903b336efc3a5224ab41d2460bb92a2817bbab078c46436a74e752b5821766f9a3455261a90add158af35c4c5f221b2
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Kugamira
FileDescription: Tipi Setup
FileVersion:
LegalCopyright:
ProductName: Tipi
ProductVersion: 3.3.2
Translation: 0x0000 0x04b0

Application.DealAgent.ATBD also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanApplication.DealAgent.ATBD
FireEyeGeneric.mg.e513300d4813dbe9
McAfeeArtemis!E513300D4813
CylanceUnsafe
AlibabaAdWare:Win32/InstallCore.7136ddf8
Cybereasonmalicious.d4813d
SymantecPUA.InstallCore
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H07GQ21
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.Win32.DealPly.gen
BitDefenderApplication.DealAgent.ATBD
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareApplication.DealAgent.ATBD
EmsisoftApplication.DealAgent.ATBD (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
SentinelOneStatic AI – Malicious PE
SophosQPDownload Download Manager (PUA)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataWin32.Application.InstallCore.LR@gen
VBA32Malware-Cryptor.2LA.gen
ALYacApplication.DealAgent.ATBD
MAXmalware (ai score=82)
MalwarebytesPUP.Optional.BundleInstaller
RisingAdware.InstallCore!1.AB2C (CLASSIC)
WebrootW32.Adware.Installcore
PandaPUP/DownloadAssistant
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.DealAgent.ATBD?

Application.DealAgent.ATBD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment