Trojan

Trojan:Win32/Occamy.C6B (file analysis)

Malware Removal

The Trojan:Win32/Occamy.C6B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C6B virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Trojan:Win32/Occamy.C6B?


File Info:

crc32: AA216A1E
md5: 2a227088c37f1bb24ff227cb5ffed129
name: 2A227088C37F1BB24FF227CB5FFED129.mlw
sha1: 2e832855d3c9db2e3f241df29cbddac64530fdc9
sha256: 6bd3b912b3d38f94fc8542914db204d3fee22a01b2671c8dea01d2311a0618d9
sha512: 3b796cab5448f66a65757ad7ca3fe256b28d2e92c15a33f47c89ad44e1723f74dcf6f7fed4a5a55f013a9a4d481f7c790eab2cc45aaa6fd6331e11db86383fc7
ssdeep: 6144:ESYF24m2i52YG1ymaRyBGQ2CgBoGslby4KtAKV0XfDH:aIoI2YG1yM+Khy4KtAUqL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Runtime Engine Copyright xa9 2015 MadByte Games (www.madbytegames.com)
InternalName: ams_launch
FileVersion: 1.16.4.8
CompanyName: WinLoader
Comments: Created with AutoPlay Media Studio (www.indigorose.com)
ProductName: Loader
ProductVersion: 1.17.5
FileDescription: Win Loader
OriginalFilename: Loader.exe
Translation: 0x0409 0x0000

Trojan:Win32/Occamy.C6B also known as:

K7AntiVirusTrojan ( 0053fc801 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.42536
CynetMalicious (score: 100)
ALYacGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
CylanceUnsafe
ZillyaTrojan.CoinStealer.Win32.880
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Stealer.1012ece7
K7GWTrojan ( 0053fc801 )
Cybereasonmalicious.8c37f1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
NANO-AntivirusTrojan.Win32.CoinStealer.etdefe
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
TencentWin32.Trojan.Generic.Hqlm
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
SophosMal/Generic-R + Mal/Stealer-E
BitDefenderThetaGen:NN.ZemsilF.34684.Om0@ayQuxipi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jm
FireEyeGeneric.mg.2a227088c37f1bb2
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.B9DF4373 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C6B
ArcabitGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.MSIL.Ransomware.Jigsaw.B9DF4373
AhnLab-V3Trojan/Win32.JigsawLocker.C2166551
Acronissuspicious
McAfeeGenericRXCW-CW!2A227088C37F
MAXmalware (ai score=100)
MalwarebytesRansom.Jigsaw
PandaTrj/GdSda.A
RisingRansom.JigsawLocker!8.52DD (CLOUD)
YandexTrojan.PWS.CoinStealer!IFy+QTlQj58
IkarusTrojan.MSIL.PSW
FortinetMSIL/CoinStealer.AA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Occamy.C6B?

Trojan:Win32/Occamy.C6B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment