Trojan

Trojan:Win32/Occamy.C36 removal instruction

Malware Removal

The Trojan:Win32/Occamy.C36 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C36 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

ip-api.com
jfogigh3i.2ihsfa.com
reports.adexpertsmedia.com

How to determine Trojan:Win32/Occamy.C36?


File Info:

crc32: 3E571D87
md5: 10a0bc24ad42954206748274e56bf34c
name: jieolll.exe
sha1: b910eb0e43468437f84802e9ead033c7e8fbe752
sha256: 3627c89625d468127342bf074e014c0b0c0c44650eddba227659dc5100300a70
sha512: b845714a5b3b1cd696eb38711c94a818d6a2f3efec81dfcc9cf222407db495f1bbdcc5124b1ee2296990c9fe3a0072519e44abe2b1c34406181ee3ef284a775b
ssdeep: 6144:Iihthr0SYqIdftXc48s00VFepPyawxKQUsftcYBSzxxRqH3NmoSY:Jd0SYqIdv90su6ahqtcY03RSIoSY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Occamy.C36 also known as:

DrWebTrojan.DownLoader33.51274
MicroWorld-eScanGen:Variant.Razy.301902
CAT-QuickHealTrojan.Wacatac
MalwarebytesSpyware.PasswordStealer
AegisLabTrojan.Win32.Fabookie.4!c
BitDefenderGen:Variant.Razy.301902
Cybereasonmalicious.e43468
ArcabitTrojan.Razy.D49B4E
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34126.xmGfamme5vaj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.UAW
TrendMicro-HouseCallTROJ_GEN.R002H0AF620
Paloaltogeneric.ml
KasperskyTrojan.Win32.Fabookie.y
AlibabaTrojan:Win32/Fabookie.d9dddd32
AvastWin32:DropperX-gen [Drp]
RisingDropper.Generic!8.35E (TFE:dGZlOgX0PJNqwH0SXA)
EmsisoftGen:Variant.Razy.301902 (B)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.HLLP.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.10a0bc24ad429542
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/Dropper.Gen
FortinetW32/Agent.VHO!tr
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C36
ViRobotTrojan.Win32.Z.Razy.382464.AJ
ZoneAlarmTrojan.Win32.Fabookie.y
AhnLab-V3Trojan/Win32.Agent.C4109178
Acronissuspicious
McAfeeGenericRXAA-AA!10A0BC24AD42
MAXmalware (ai score=88)
VBA32BScope.Trojan.Infospy
CylanceUnsafe
APEXMalicious
TencentWin32.Trojan.Fabookie.Dwtc
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Razy.301902
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.BO.53c

How to remove Trojan:Win32/Occamy.C36?

Trojan:Win32/Occamy.C36 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment