Malware

Win32/PSW.Agent.OOY removal

Malware Removal

The Win32/PSW.Agent.OOY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.OOY virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Win32/PSW.Agent.OOY?


File Info:

name: E81B42D89E7436588308.mlw
path: /opt/CAPEv2/storage/binaries/9b87f40ef1b1677bcf7897962226983c2079cdd4feb34b8f97f03e6076808e8d
crc32: 53037701
md5: e81b42d89e74365883086d75b0646aa5
sha1: d5746890b9cb577cfe025182a3e286969901e6d8
sha256: 9b87f40ef1b1677bcf7897962226983c2079cdd4feb34b8f97f03e6076808e8d
sha512: 7d4a656e717c1a885273b5d709a9aca6575fc94e8ab5d4acf8368ed5e32187db139acef5ad1a29c764f186fa5abadf616ec7def2da53b30a5becc1daaa1a13f6
ssdeep: 12288:0qbmJzX98QoFvA7r44V5s4gmQoP2UjJW5x4bmcETz2XcEiP/3IWVJ/uxdc4EO:0qbmJzX98MssP2UFW5z9/E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DB4D7532ACA0CB6CCA227F495C72776A7389E348517CB6BA754CD369FA32C0BD59301
sha3_384: 6a8437f2cb3716db2129215576bf62ce1d55548a16f23e8c759b2317547492e068e5cf75608cc54ae737ff3c768ef619
ep_bytes: 5589e583ec08c7042402000000ff15b8
timestamp: 2022-07-12 02:40:51

Version Info:

0: [No Data]

Win32/PSW.Agent.OOY also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.i!c
MicroWorld-eScanTrojan.GenericKD.49347973
FireEyeTrojan.GenericKD.49347973
McAfeeArtemis!E81B42D89E74
CylanceUnsafe
SangforInfostealer.Win32.Agent.Vj9s
K7AntiVirusPassword-Stealer ( 005951b61 )
BitDefenderTrojan.GenericKD.49347973
K7GWPassword-Stealer ( 005951b61 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D2F0FD85
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Agent.gen
AlibabaTrojanPSW:Win32/Genome.0b116d96
RisingTrojan.Generic@AI.85 (RDML:kLVDA4wvLxyxqJMAhchiQA)
Ad-AwareTrojan.GenericKD.49347973
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.49347973 (B)
IkarusTrojan.Win32.Genome
WebrootW32.Malware.Gen
AviraTR/PSW.Agent.evrxm
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-PSW.Win32.Agent.gen
GDataWin32.Trojan.Agent.0QS4XZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malex.C5204337
ALYacTrojan.GenericKD.49347973
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002H0DGC22
TencentWin32.Trojan-qqpass.Qqrob.Airr
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34786.EuZ@aW4qM3k
AVGWin32:Trojan-gen
Cybereasonmalicious.0b9cb5
AvastWin32:Trojan-gen

How to remove Win32/PSW.Agent.OOY?

Win32/PSW.Agent.OOY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment