Malware

Should I remove “Application.DealAgent.DNX”?

Malware Removal

The Application.DealAgent.DNX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.DNX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Application.DealAgent.DNX?


File Info:

crc32: 7B870F0E
md5: 6ff6c45dc6e37b7bc7f99dd0427474d2
name: 6FF6C45DC6E37B7BC7F99DD0427474D2.mlw
sha1: 7d5339c922d71e93f40c8653d1bfce511fb9f45b
sha256: 2c66b33ba33273a8acb64747dcedeb0036be88e82611db6397f9344134d442f2
sha512: d97f6ae591e96aab02da0f4f3914ac55cb8a5c71956e8d98368d3b560f734f733968a161fd2b6107d3a10038b9a0ed641f61cc9d15cbec5f9016a7ef52630050
ssdeep: 49152:93cBLQDuxF20Yzo8Jv7iIj5wQf21K9PsF4BGpfU:1cBXFeo897/a1KJs6IU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.8.4.1
CompanyName: Samap
Comments: This installation was built with Inno Setup.
ProductName: Cotuta
ProductVersion: 2.1
FileDescription: Cotuta Setup
Translation: 0x0000 0x04b0

Application.DealAgent.DNX also known as:

DrWebTrojan.InstallCore.3436
ALYacApplication.DealAgent.DNX
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.e2216ee3
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
AvastFileRepMalware [PUP]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dkshh
BitDefenderApplication.DealAgent.DNX
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanApplication.DealAgent.DNX
Ad-AwareApplication.DealAgent.DNX
SophosInnoMod (PUA)
ComodoMalware@#3lg2bjkj4wdxm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
FireEyeGeneric.mg.6ff6c45dc6e37b7b
EmsisoftApplication.DealAgent.DNX (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.DealPly.mocq
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.heur
GDataWin32.Application.InstallCore.LR@gen
McAfeeArtemis!6FF6C45DC6E3
MAXmalware (ai score=94)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.BundleInstaller
PandaTrj/CI.A
RisingAdware.InstallCore!1.AB2C (CLASSIC)
FortinetAdware/DealPly
AVGFileRepMalware [PUP]
Paloaltogeneric.ml

How to remove Application.DealAgent.DNX?

Application.DealAgent.DNX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment