Trojan

Should I remove “Trojan.Occamy”?

Malware Removal

The Trojan.Occamy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan.Occamy virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Trojan.Occamy?


File Info:

crc32: 46F4B641
md5: 69151a11fa04f698816a2e4b36a34f58
name: setup_m.exe
sha1: 93a7d4537f7b34105a2d5f59564dc9327ef2a072
sha256: 22d5447cace450971bac1055cac836686691a30e31880dbf1e66acd0c7c4e2df
sha512: 1dbbe3129bafb15cbb526e6f15e5ad64beedb5733fad6e064e66d1d298f86dd5383f4951f7652c51bbeb53ceb537510fef8be5e18fbb5a670f5672c967e4cf4f
ssdeep: 24576:IGk69IS0rw4pP9p41GXbT7koeZRh0NIVIg8EwpsQ35gdn5H7/bPwEjHly3H:Xkjrl341GHQo40WSg8EwsQ35gdnp7TP
type: MS-DOS executable, MZ for MS-DOS

Version Info:

FileVersion: 6.2.6.1
ProductVersion: 6.2.6.1
Translation: 0x0809 0x04b0

Trojan.Occamy also known as:

FireEyeGeneric.mg.69151a11fa04f698
McAfeeGenericRXIX-KX!69151A11FA04
MalwarebytesTrojan.Qulab
Cybereasonmalicious.37f7b3
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.tc
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
IkarusTrojan.Win32.Autoit
MicrosoftTrojan:Win32/Wacatac.B!ml
Endgamemalicious (high confidence)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.32247.vnuaaWHSwidi
VBA32Trojan.Occamy
ESET-NOD32a variant of Win32/Packed.Autoit.NBE suspicious
SentinelOneDFI – Malicious PE
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan.Occamy?

Trojan.Occamy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment