Malware

Application.DealAgent.ITR removal

Malware Removal

The Application.DealAgent.ITR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.ITR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Application.DealAgent.ITR?


File Info:

crc32: A54AF87C
md5: 0004813e670115d51d61ccd49db24b8b
name: 0004813E670115D51D61CCD49DB24B8B.mlw
sha1: 70269e16128c49dcc8f4f2df4a55435ae5ef93dc
sha256: 1a3085911a9ab75d836249b4bc3c4b7b50dcb1130eb86395ad1643dc5cb21922
sha512: 78c08ab244bb11e238beaf7e212a55828c5937c032e1441e3ce759726b3b38af97b83bd9c983ab454d808ea6224fab4cf6bdead4adf4fd7489aaf467c8da3377
ssdeep: 24576:4q8j1R5UGWM9hwDdBNP4FB5caThq4gQK6xL6HQgw4aYd5cq1mFs6tke0:4xm91dBNP4xFTOH8Yd5cqGV0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 3.3.1.7
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Mufosoli
ProductVersion: 3.6.9
FileDescription: Mufosoli Setup
Translation: 0x0000 0x04b0

Application.DealAgent.ITR also known as:

Elasticmalicious (high confidence)
ALYacApplication.DealAgent.ITR
MalwarebytesPUP.Optional.BundleInstaller
SangforAdware.Win32.DealPly.dsdjz
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/InstallCore.d931159e
Cybereasonmalicious.e67011
SymantecPUA.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
AvastWin32:Dropper-gen [Drp]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dsdjz
BitDefenderApplication.DealAgent.ITR
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanApplication.DealAgent.ITR
Ad-AwareApplication.DealAgent.ITR
SophosQPDownload Download Manager (PUA)
ComodoMalware@#2zn0qhagf55e4
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.0004813e670115d5
EmsisoftApplication.DealAgent.ITR (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.heur
GDataWin32.Application.InstallCore.LR@gen
McAfeeArtemis!0004813E6701
MAXmalware (ai score=79)
VBA32Malware-Cryptor.2LA.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CGM21
RisingAdware.InstallCore!1.AB2C (CLASSIC)
FortinetW32/Generic_PUA_HA.A
AVGWin32:Dropper-gen [Drp]

How to remove Application.DealAgent.ITR?

Application.DealAgent.ITR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment