Trojan

Trojan:Win32/Occamy.C56 removal instruction

Malware Removal

The Trojan:Win32/Occamy.C56 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C56 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Occamy.C56?


File Info:

crc32: D99C9B0A
md5: 622e1d56c7b187d0eaba20ff7c137985
name: dqwh_qweq.exe
sha1: 484d0903a76fd654d8683e4797d67dc39553f5d3
sha256: 56bdbc6f1d06ad5c8c2442bf5d8196af7b745830c230efc58f5f3121578b8f0a
sha512: 6289aa59fea5b1692c938ea4c2a18b1d0f9d385b84347257b72bc2f223284448aeeb98270d0e08a6f728611be8d5e603a24029ddfb306b530c186c5d0e1eb1b8
ssdeep: 24576:o/tl9Vtg5VfbdRNKAjDObkWOfzYVJRLqjvu9:ovtgBRNKiC36YVmvu9
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x70edx8840x6218x6b4c
ProductVersion: 3.0.0.0
FileDescription: x70edx8840x6218x6b4c install
Translation: 0x0804 0x03a8

Trojan:Win32/Occamy.C56 also known as:

FireEyeGeneric.mg.622e1d56c7b187d0
CAT-QuickHealApplication.Agent.ZZ5
McAfeeArtemis!622E1D56C7B1
CylanceUnsafe
K7AntiVirusAdware ( 004e2f011 )
CyrenW32/Application.YXLC-6015
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Application.Agent.O5UWGP
Kasperskynot-a-virus:AdWare.Win32.Wews87.edd
AlibabaAdWare:Win32/Wews87.5b277962
ViRobotAdware.Wews87.1015040
TencentWin32.Adware.Wews87.Wlfq
ComodoMalware@#1nvsf36gx9qzx
F-SecureAdware.ADWARE/Wews87.aouig
DrWebProgram.Unwanted.3980
ZillyaAdware.Wews87.Win32.482
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA NJ (PUA)
IkarusAdWare.Wews87
AviraADWARE/Wews87.moakv
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.Wews87.edd
MicrosoftTrojan:Win32/Occamy.C56
VBA32Adware.Wews
MalwarebytesAdware.ChinAd
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R007H0CER20
RisingPUA.Wews87!8.642 (CLOUD)
eGambitUnsafe.AI_Score_70%
FortinetRiskware/Generic_PUA_NJ
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Generic/Virus.Adware.340

How to remove Trojan:Win32/Occamy.C56?

Trojan:Win32/Occamy.C56 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment