Trojan

Trojan:Win32/Occamy.CC7 removal instruction

Malware Removal

The Trojan:Win32/Occamy.CC7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CC7 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

admindepartment.ir

How to determine Trojan:Win32/Occamy.CC7?


File Info:

crc32: F70A8D4F
md5: 64c76ce243ba2e62277d358280ed6492
name: tmpbyg6ccbq
sha1: 10612abdddc9c63d0ebf42c5060e49e722950793
sha256: c7ed9ceafb18a2851083adb67a9f33e27d35a67cff63b2e08da23f4523a824c7
sha512: 7adc6cd554bb73d96f1fca63f231e152e4812139dfe4053c39c6536c495b9701c84db5a31a2a272c7257d9fd1574372597436a5782abeaebbc071706ab983b2c
ssdeep: 12288:+vb7RSh1zZ+S6rGb2sqdM89yYNQoX5+cQhSkcx+vhiyiKNA0qykogo3U:EHRSh19IxsqFRG3vtiAA0qyZ5k
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Occamy.CC7 also known as:

BkavW32.AIDetectVM.malwareB
DrWebTrojan.PWS.Stealer.23680
MicroWorld-eScanGen:Variant.Zusy.306711
FireEyeGeneric.mg.64c76ce243ba2e62
Qihoo-360HEUR/QVM05.1.F85F.Malware.Gen
McAfeeFareit-FTB!64C76CE243BA
CylanceUnsafe
AegisLabTrojan.Win32.Zusy.4!c
K7AntiVirusTrojan ( 005686cb1 )
BitDefenderGen:Variant.Zusy.306711
K7GWTrojan ( 005686cb1 )
Cybereasonmalicious.dddc9c
ArcabitTrojan.Zusy.D4AE17
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34128.1GW@ayOao5gi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EMKE
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Chisburg.gen
AlibabaTrojan:Win32/GenKryptik.50416094
RisingTrojan.Injector!1.AFE3 (CLOUD)
Ad-AwareGen:Variant.Zusy.306711
EmsisoftGen:Variant.Zusy.306711 (B)
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
IkarusWin32.Outbreak
AviraTR/Injector.ntotm
FortinetW32/Injector.ELZG!tr
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.CC7
ZoneAlarmHEUR:Trojan-PSW.Win32.Chisburg.gen
CynetMalicious (score: 100)
AhnLab-V3Suspicious/Win.Delphiless.X2066
ALYacGen:Variant.Zusy.306711
MAXmalware (ai score=85)
MalwarebytesSpyware.Agent
PandaTrj/GdSda.A
APEXMalicious
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Zusy.306711
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Occamy.CC7?

Trojan:Win32/Occamy.CC7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment