Malware

Win32/PSW.Agent.OFE (file analysis)

Malware Removal

The Win32/PSW.Agent.OFE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.OFE virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the CryptoStealerGo malware family
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/PSW.Agent.OFE?


File Info:

name: 36ABEC7F0AE1E54FBBDD.mlw
path: /opt/CAPEv2/storage/binaries/3b0f02d489d28bdd8dd4ad45c5b5d262df7c758c46073bf44a428148d50d9dd1
crc32: EDA759D8
md5: 36abec7f0ae1e54fbbdd00b2db83e4c3
sha1: 97677c9d6e1ce1ee53d79eebfea988644cd1e111
sha256: 3b0f02d489d28bdd8dd4ad45c5b5d262df7c758c46073bf44a428148d50d9dd1
sha512: a08389dab782f41352d172aa25b64c31796bce44a1bf9eefcbbb5f1554c7e34de1e8ad6764c1e5eacac878cae5c53042ac4d23dbf95e85720ac1a89f95418b0a
ssdeep: 98304:pEY/ZL7SbmWWgOsdE4nv6etBgUIfAVhQgyxyX3:pEYBL7umWWyCetiAVnEW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2665A91E9DF10F5EB03147084A7623F2730620A8779CEDBC7805F86F967AE15A73629
sha3_384: f4773a9b710e6a0ddcd0b6210d3486a9a4d652af5ca1243114cd59b104d5f57fc3f8152088d0573183a7440ab99cc6ee
ep_bytes: e93bdaffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32/PSW.Agent.OFE also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.36abec7f0ae1e54f
SkyhighGenericRXHD-UP!36ABEC7F0AE1
McAfeeGenericRXHD-UP!36ABEC7F0AE1
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.4335
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Esulat.bdff3130
K7GWTrojan ( 0057135f1 )
K7AntiVirusTrojan ( 0057135f1 )
BitDefenderThetaGen:NN.ZexaF.36744.@FW@aGKbkQoi
VirITTrojan.Win32.Stealer.BLOI
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.Agent.OFE
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.79922
NANO-AntivirusTrojan.Win32.Stealer.flvkoh
MicroWorld-eScanTrojan.GenericKDZ.79922
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b11ab0
EmsisoftTrojan.GenericKDZ.79922 (B)
DrWebTrojan.PWS.Stealer.25384
VIPRETrojan.GenericKDZ.79922
TrendMicroTROJ_FRS.0NA103IG20
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
GDataTrojan.GenericKDZ.79922
JiangminPacked.Multi.gee
WebrootW32.Trojan.Gen
VaristW32/S-2ac4a611!Eldorado
Antiy-AVLTrojan/Win32.Agent.ofe
XcitiumMalware@#dc703pr8emp9
ArcabitTrojan.Generic.D13832
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Fareit
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R267245
VBA32Trojan.Fuerboos
ALYacTrojan.GenericKDZ.79922
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103IG20
RisingSpyware.Stealer!8.3090 (TFE:6:5Vtb6UBtE1L)
YandexTrojan.GenAsa!mYNNLX6LNUc
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74061008.susgen
FortinetW32/Agent.OFE!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/PSW.Agent.OFE?

Win32/PSW.Agent.OFE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment