Malware

What is “Application.DealAgent.LXW”?

Malware Removal

The Application.DealAgent.LXW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.DealAgent.LXW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs

How to determine Application.DealAgent.LXW?


File Info:

crc32: 7F340908
md5: 5906e54409369e18be1bcd2507549019
name: 5906E54409369E18BE1BCD2507549019.mlw
sha1: c8fc0721dfcc24f0bea3393e44c8a1e616daf52d
sha256: d0fdebc577339b35da50938d2383d648840aeccbe55f3f853dd5cb6aa444f024
sha512: 06dbcdbeba67526f109ddc0861ee2b4705d7594e1aefd80c592f3e88b28cb0001ff6b2eb8767d7cacc151ad7c88433edcde7b6e196e342d67e7d6f6c38411362
ssdeep: 49152:Ln6ueShgrWQfhw87/RW32MZHA1EjvMT5GpfA:bn0rWQJwh3ZHZjvMcA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Cam
ProductVersion: 2.0.8
FileDescription: Cam Setup
Translation: 0x0000 0x04b0

Application.DealAgent.LXW also known as:

Elasticmalicious (high confidence)
ALYacApplication.DealAgent.LXW
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderApplication.DealAgent.LXW
Cybereasonmalicious.409369
SymantecTrojan.Gen.2
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.DealPly.dakdx
AlibabaAdWare:Win32/InstallCore.94572668
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotAdware.Installcore.1836426
MicroWorld-eScanApplication.DealAgent.LXW
TencentWin32.Adware.Dealply.Sudy
Ad-AwareApplication.DealAgent.LXW
SophosQPDownload Download Manager (PUA)
ComodoApplicUnwnt@#3dladx5tfz3cb
FireEyeGeneric.mg.5906e54409369e18
EmsisoftApplication.DealAgent.LXW (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Azorult!ml
SUPERAntiSpywarePUP.Bundler/Variant
GDataWin32.Application.InstallCore.LR@gen
AhnLab-V3PUP/Win32.InstallCore.R236961
McAfeeArtemis!5906E5440936
MAXmalware (ai score=94)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesPUP.Optional.BundleInstaller
RisingAdware.InstallCore!1.A30C (CLASSIC)
YandexPUA.DealPly!ueHxi7LDmJ0
FortinetAdware/DealPly

How to remove Application.DealAgent.LXW?

Application.DealAgent.LXW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment