Spy Trojan

Trojan.Spy.Agent.OFS removal instruction

Malware Removal

The Trojan.Spy.Agent.OFS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Agent.OFS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.

How to determine Trojan.Spy.Agent.OFS?


File Info:

name: 260A3F1C66827DE66F3C.mlw
path: /opt/CAPEv2/storage/binaries/a85687e01ac69a4ca3fa4e7eb5ae5be5aaabed7d93d6ce763f4e54b2830a4b4e
crc32: 05601B40
md5: 260a3f1c66827de66f3c2a1eda9e4ce1
sha1: 06d4e9b3d43167ac84662562fec4de36686de9b7
sha256: a85687e01ac69a4ca3fa4e7eb5ae5be5aaabed7d93d6ce763f4e54b2830a4b4e
sha512: b53cbcd2e83bc5c668d73067a5d87ee6d1494b273f2ce2799d3e6c2cdd0ccd68d4e5ffe18fd1c3e34b573d8723030c6373fc00908f0934e1ae8a4bb6878256da
ssdeep: 192:59eodd2fxDclUU0ox9eVT8wPikgOtMIpncn8OQsrhIILOR/+TRw2CfY:5dH2fFUxx9+QwPikxM8cO8lLOR/0Rug
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17462073B319A9972C1988F331C737A899F20AE2339091663935B79F5DDF260E742166C
sha3_384: 3574ac3e4d488bb9805de088b3ba937ded78e778e5cf6bd8be7a02d898647b0f57eda3d5b09640bcf6fe13bd23f734bb
ep_bytes: 8bff568b3546204000ac346a5e7401c3
timestamp: 2008-04-14 16:10:18

Version Info:

0: [No Data]

Trojan.Spy.Agent.OFS also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21552
MicroWorld-eScanTrojan.Spy.Agent.OFS
CAT-QuickHealTrojan.Waledac.C
ALYacTrojan.Spy.Agent.OFS
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.c66827
BitDefenderThetaGen:NN.ZexaF.34742.aqX@aOcVjmai
CyrenW32/SuspPack.DA.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HUM
TrendMicro-HouseCallTROJ_FRAUDLO.SMZ
ClamAVWin.Trojan.Waledac-9947923-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Agent.OFS
AvastWin32:Zbot-MWJ [Trj]
Ad-AwareTrojan.Spy.Agent.OFS
SophosML/PE-A + Mal/Zbot-AN
ComodoBackdoor.Win32.Bredolab.asd@2nruqc
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_FRAUDLO.SMZ
McAfee-GW-EditionPWS-Zbot.gen.auo
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.260a3f1c66827de6
EmsisoftTrojan.Spy.Agent.OFS (B)
IkarusTrojan-Downloader.Win32.Waledac
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojanDownloader:Win32/Waledac.C
ArcabitTrojan.Spy.Agent.OFS
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Spy.Agent.OFS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R829
Acronissuspicious
McAfeePWS-Zbot.gen.auo
VBA32Malware-Cryptor.Hlux
APEXMalicious
RisingTrojan.Generic@AI.98 (RDML:64N7rQ936bE3qiNK1cN36w)
YandexTrojan.GenAsa!OlKmCjNEwzw
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Krypt.G!tr
AVGWin32:Zbot-MWJ [Trj]
PandaAdware/KriptyA
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Spy.Agent.OFS?

Trojan.Spy.Agent.OFS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment