Malware

How to remove “Win32/PSW.Agent.OKD”?

Malware Removal

The Win32/PSW.Agent.OKD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.OKD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

kduck.emc
sealorgames.com
iplogger.org
apps.identrust.com
isrg.trustid.ocsp.identrust.com
www.bing.com
ocsp.int-x3.letsencrypt.org
scgmailserv19fd.xyz

How to determine Win32/PSW.Agent.OKD?


File Info:

crc32: A06EB21A
md5: 7490f7389c2f25bbae7a8779f76c41df
name: upload_file
sha1: 5481f25f8ae878bc134558ad60f686cad7651b36
sha256: cd2fb19598084681b5fe849bf1cdbabb07325de447d8150463d189440e10932d
sha512: 29786e6ff486d4f39c55acd54d0bb5ed6d647b18d06f72160b68303d4dd8eaabf5d9e242ed1d7f37860e9af45e65c9984843574711bb861e494613ac81b462d6
ssdeep: 12288:pANwRo+mv8QD4+0V16KNOlw6HtAQEIdXWIzt8ZGicHAHGg6AFBT8w:pAT8QE+kvNiDAQEa7xAHt6AFBQw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: wotsuper
FileDescription: wotsuper 2.1 Installation
FileVersion: 2.1
Comments:
CompanyName: wotsuper
Translation: 0x0409 0x04e4

Win32/PSW.Agent.OKD also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34253514
CAT-QuickHealTrojanpws.Vidar
McAfeeArtemis!7490F7389C2F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusPassword-Stealer ( 0056a47d1 )
BitDefenderTrojan.GenericKD.34253514
K7GWPassword-Stealer ( 0056a47d1 )
Cybereasonmalicious.89c2f2
ArcabitTrojan.Generic.D20AAACA
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OKD
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Vidar.vho
AlibabaTrojanPSW:Win32/Vidar.bc5c17a6
ViRobotTrojan.Win32.Z.Agent.623503
SUPERAntiSpywareTrojan.Agent/Gen-Chapak
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.34253514
EmsisoftTrojan-Dropper.Agent (A)
F-SecureHeuristic.HEUR/AGEN.1113283
DrWebTrojan.Siggen9.44744
TrendMicroTROJ_GEN.R002C0DGS20
FireEyeGeneric.mg.7490f7389c2f25bb
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
CyrenW32/Trojan.FMTI-2785
eGambitUnsafe.AI_Score_99%
AviraTR/AD.VidarStealer.ypavl
MicrosoftTrojan:Win32/Vidar.AA!MTB
AegisLabTrojan.Win32.Vidar.i!c
ZoneAlarmHEUR:Trojan-PSW.Win32.Vidar.vho
GDataTrojan.GenericKD.34253514
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C3733562
BitDefenderThetaGen:NN.ZexaF.34144.ImW@aK1K5q
ALYacTrojan.GenericKD.34253514
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Predator
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGS20
TencentWin32.Trojan.Generic.Ahoi
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Agent.OKD!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.PSW.44f

How to remove Win32/PSW.Agent.OKD?

Win32/PSW.Agent.OKD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment