VHO:Trojan.Win64.Occamy removal guide

Malware Removal

The VHO:Trojan.Win64.Occamy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What VHO:Trojan.Win64.Occamy virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine VHO:Trojan.Win64.Occamy?


File Info:

crc32: 0EC2EA89
md5: 21f17d258baf8f7e781d68ea25469aa1
name: 21F17D258BAF8F7E781D68EA25469AA1.mlw
sha1: e568900f6eda540da340c03fae0c7175e7c0f4f4
sha256: 13f598c90e0e573ad0d393b7b50dc6217d83d3df74982948418b2185986465fb
sha512: 776fea23b8659c199f804a339e79a028f9e502c457e936ca228a8465f0cea61815942ea8d6e3083d7998758088b80dc740470b2e33f218bce1ce735426c2f3a0
ssdeep: 12288:oVI0W/TtlPLfJCm3WIYxJ9yK5IQ9PElOlidGAWilgm5Qq0nB6wtt4AenZ1:9fP7fWsK5z9A+WGAW+V5SB6Ct4bnb
type: PE32+ executable (DLL) (console) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserv
InternalName: bitsp
FileVersion: 7.5.7600.16385 (win7_rtm.090713-
CompanyName: Microsoft Corporati
ProductName: Microsoftxae Windowsxae Operating S
ProductVersion: 6.1.7600
FileDescription: Background Intellig
OriginalFilename: kbdy
Translation: 0x0409 0x04b0

VHO:Trojan.Win64.Occamy also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.3504
ClamAVWin.Packed.Razy-9769561-0
ALYacTrojan.GenericKDZ.76753
CylanceUnsafe
ZillyaTrojan.Injexa.Win64.17
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005601a91 )
K7AntiVirusTrojan ( 005601a91 )
CyrenW64/S-9d36de06!Eldorado
ESET-NOD32a variant of Win64/Kryptik.BWL
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win64.Occamy.gen
BitDefenderTrojan.GenericKDZ.76753
MicroWorld-eScanTrojan.GenericKDZ.76753
TencentMalware.Win32.Gencirc.10b8f418
Ad-AwareTrojan.GenericKDZ.76753
SophosML/PE-A + Troj/Dridex-AII
TrendMicroTrojanSpy.Win64.DRIDEX.SMF
McAfee-GW-EditionBehavesLike.Win64.Drixed.tz
FireEyeGeneric.mg.21f17d258baf8f7e
EmsisoftTrojan.GenericKDZ.76753 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.s
AviraHEUR/AGEN.1114452
Antiy-AVLTrojan/Generic.ASMalwS.30014E7
MicrosoftTrojan:Win64/Dridex.DK!MTB
GridinsoftTrojan.Win64.Banker.oa!s1
GDataTrojan.GenericKDZ.76753
AhnLab-V3Malware/Win64.RL_Trojanspy.R328983
Acronissuspicious
McAfeeDrixed-FIC!21F17D258BAF
MAXmalware (ai score=88)
MalwarebytesBackdoor.Qbot
TrendMicro-HouseCallTrojanSpy.Win64.DRIDEX.SMF
YandexTrojan.GenAsa!RYtjI3PRurw
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Dridex.7ECB!tr
AVGWin64:BankerX-gen [Trj]

How to remove VHO:Trojan.Win64.Occamy?

VHO:Trojan.Win64.Occamy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment