Trojan

Trojan:Win32/Occamy.CFA (file analysis)

Malware Removal

The Trojan:Win32/Occamy.CFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CFA virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Occamy.CFA?


File Info:

crc32: F07C4A72
md5: b0e7c5affe110644f86b6950b9ab0213
name: B0E7C5AFFE110644F86B6950B9AB0213.mlw
sha1: f090d97671aa27e0f037cf71691ded3f76e8c784
sha256: fa310aa7f861379540d41480c1d962beea5b66f3d97c9923854eb575d06e8abe
sha512: f5ced76dad6153b999776b0f5f1961e61432d90ca4acae22a95560512f5cac28d4f1c858433ec847e53840373cc5927cad0aa40d9cf02078d3cafa733e93d20f
ssdeep: 6144:wVh0LN0PXrvPVdNT6zncVUJKWehinoCnC:WJrlTT6zncVUJ7vn5C
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: ProxyChecker.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: ProxyChecker
ProductVersion: 1.0.0.0
FileDescription: ProxyChecker
OriginalFilename: ProxyChecker.exe

Trojan:Win32/Occamy.CFA also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Perseus.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.MSILPerseus.192261
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ffe110
CyrenW32/MSIL_Troj.NT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.MSILPerseus.192261
MicroWorld-eScanGen:Variant.MSILPerseus.192261
Ad-AwareGen:Variant.MSILPerseus.192261
SophosML/PE-A
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.b0e7c5affe110644
EmsisoftGen:Variant.MSILPerseus.192261 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Occamy.CFA
ArcabitTrojan.MSILPerseus.D2EF05
GDataGen:Variant.MSILPerseus.192261
AhnLab-V3Malware/Win32.RL_Generic.C3985463
McAfeeArtemis!B0E7C5AFFE11
MAXmalware (ai score=87)
PandaTrj/CI.A
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.7175203.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwMAOAUA

How to remove Trojan:Win32/Occamy.CFA?

Trojan:Win32/Occamy.CFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment