Malware

How to remove “Application.DealAgent.LKM”?

Malware Removal

The Application.DealAgent.LKM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.LKM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Application.DealAgent.LKM?


File Info:

crc32: A794DDC4
md5: 4a8bf8a0a11bd0cda711e856643fa9f5
name: 4A8BF8A0A11BD0CDA711E856643FA9F5.mlw
sha1: 2e6c9555c0d7787c86dd2345ba3c5daa64c2babc
sha256: 1a4bd51b24eda8dbf963ead2752f8721df94c0b7e7bfa0f0aea2992120109ce1
sha512: cc5fdce5a5ed3abd0af02125ac2e6659f42d310c2f38f45c1ad597be44889bf59704409f7903b60615a2e2833446e4da6fd6c561e6c94879475db25b8f25ce22
ssdeep: 49152:ZHfw9lBB19vnaxCWAB9py9tzDllW+m1qVJ2cz1bpsq0:Z/wXBdvQCJ94h3mi2cfsq0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Nutuhebo
Comments: This installation was built with Inno Setup.
ProductName: Rihofu
ProductVersion: 1.8.0
FileDescription: Rihofu Setup
Translation: 0x0000 0x04b0

Application.DealAgent.LKM also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
ALYacApplication.DealAgent.LKM
CylanceUnsafe
ZillyaTool.DealAgent.Win32.183
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/InstallCore.cabc37af
Cybereasonmalicious.0a11bd
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
AvastFileRepMetagen [PUP]
Kasperskynot-a-virus:AdWare.Win32.DealPly.dkbay
BitDefenderApplication.DealAgent.LKM
NANO-AntivirusVirus.InnoSetup.Gen.ccng
MicroWorld-eScanApplication.DealAgent.LKM
Ad-AwareApplication.DealAgent.LKM
SophosInnoMod (PUA)
ComodoMalware@#2cehuscobl9mz
FireEyeGeneric.mg.4a8bf8a0a11bd0cd
EmsisoftApplication.DealAgent.LKM (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitApplication.DealAgent.LKM
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.dkbay
GDataWin32.Application.InstallCore.LX
VBA32Malware-Cryptor.2LA.gen
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingAdware.InstallCore!1.AB2C (CLASSIC)
FortinetAdware/DealPly
AVGFileRepMetagen [PUP]

How to remove Application.DealAgent.LKM?

Application.DealAgent.LKM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment