Trojan

Should I remove “Trojan:Win32/Occamy.C61”?

Malware Removal

The Trojan:Win32/Occamy.C61 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C61 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

986a89d3131d29cb.xyz

How to determine Trojan:Win32/Occamy.C61?


File Info:

crc32: C4EA2F43
md5: 30c31eeb2f1c00d060de7c129bb30fe8
name: test07.exe
sha1: 93fe89f14ccf6160e8a2607e2266ddef35e78224
sha256: 614a86dbd37e3ed63dcb84aef1b8ac0a8b1fcb0678fd995b7db3d7a5090f45ec
sha512: 79f7a9794add8af1f162918dadcf5db554a0521a6fe42b23a3ba578753d9045a0a1b2c5457e8eff6487bc08065ac88676a0331ed73bb62838ba91cb424ac0c73
ssdeep: 24576:lxKytGsqAIi34+5lAR2VP0FUy2FC9Ds5FVt:HMTi3d5l62VP0u3FQs5FVt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2009-2018 Wargaming.net
FileVersion: 0.0.1.8
CompanyName: Wargaming.net
Comments: World of Warplanes Launcher
ProductName: World of Warplanes
ProductVersion: 0.0.1.8
FileDescription: World of Warplanes Launcher
Translation: 0x0000 0x04e4

Trojan:Win32/Occamy.C61 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Mikey.114156
FireEyeGeneric.mg.30c31eeb2f1c00d0
CAT-QuickHealTrojan.Selfdel
Qihoo-360Win32/Trojan.762
McAfeeArtemis!30C31EEB2F1C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056a1561 )
BitDefenderGen:Variant.Mikey.114156
K7GWTrojan ( 0056a1561 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.SelfDel.vho
AlibabaTrojan:Win32/GenKryptik.909053af
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
EmsisoftGen:Variant.Mikey.114156 (B)
F-SecureTrojan.TR/Kryptik.ibvar
DrWebTrojan.DownLoader33.60704
TrendMicroTrojanSpy.Win32.METERPRETER.USXVPG820
FortinetW32/SelfDel.ENOQ!tr
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.MDUR-4666
WebrootW32.Gen.BT
AviraTR/Kryptik.ibvar
MAXmalware (ai score=100)
ArcabitTrojan.Mikey.D1BDEC
ZoneAlarmHEUR:Trojan.Win32.SelfDel.vho
MicrosoftTrojan:Win32/Occamy.C61
CynetMalicious (score: 85)
Acronissuspicious
VBA32Trojan.SelfDel
ALYacGen:Variant.Mikey.114156
Ad-AwareGen:Variant.Mikey.114156
MalwarebytesTrojan.SelfDelete
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.ENTM
TrendMicro-HouseCallTrojanSpy.Win32.METERPRETER.USXVPG820
TencentMalware.Win32.Gencirc.10cddb60
SentinelOneDFI – Malicious PE
GDataGen:Variant.Mikey.114156
BitDefenderThetaGen:NN.ZexaF.34132.ED3@au5edVhk
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Occamy.C61?

Trojan:Win32/Occamy.C61 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment