1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar






A trojan that secretly downloads malicious files from a remote server, then installs and executes the files.

Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Technical Details

Trojan-Downloader:W32/Oficla.AE is distributed as an attachment to fake e-mail messages; once installed, the trojan-downloader connects to a remote server.


Oficla.AE is distributed as executable or zipped files attached to misleading e-mail messages. Some of the most common messages used to deliver this trojan involve fake offers for iTunes Gift certificates or for Amazon.com orders; other attachments are disguised as resumes.The text in the e-mail message entices the unsuspecting user to launch the attached file, which installs and executes the trojan.


Once the attached executable file is launched, the trojan creates the following files:

  • %Temp%\1.tmp
  • %System%\pgsb.lto

It also makes changes to the Windows Registry to ensure the installed copy is launched when the computer is started up.


Once installed on the computer, the trojan opens a connection to a remote server, from which it may download additional malicious programs.

Submit a sample

Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free