Malware

VirTool:Win32/Occamy.AA (file analysis)

Malware Removal

The VirTool:Win32/Occamy.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Occamy.AA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/Occamy.AA?


File Info:

crc32: B9DBD332
md5: 58a39300d73290e32a7130e3f759a592
name: ach.exe
sha1: f094a4964c9c570bf8f32604db47d3af18b7f738
sha256: 9510e1fa52d972842634706946a75a957f1578b58d247a498915e0c30fea6d2d
sha512: abda6851061947c38b11ee29d1d577d5d424fc8230b87bb12c8a98396abc5a614b6c3c0f481aaca73827e3553add9a6d2a87c544aa08bc1cc0437aa8adfa8cce
ssdeep: 12288:+wuGAp/gAZ3k+9JJQrm3g9KqtVnn4Ug8orPr5CDKDad:+ntPZhrg+UgB35CDK4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Occamy.AA also known as:

MicroWorld-eScanGen:Variant.Zusy.303686
Qihoo-360Win32/Trojan.469
McAfeeFareit-FTB!58A39300D732
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Zusy.303686
K7GWTrojan ( 005668161 )
K7AntiVirusTrojan ( 005668161 )
ArcabitTrojan.Zusy.D4A246
TrendMicroTSPY_HPLOKI.SMBD
F-ProtW32/Trojan3.APDT
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ELWH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Kryptik.8c2bf0b8
NANO-AntivirusTrojan.Win32.Inject3.hkdsco
AegisLabTrojan.Win32.Kryptik.4!c
RisingDropper.Agent!8.2F (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.303686 (B)
F-SecureTrojan.TR/Injector.gnlah
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.jc
FortinetW32/Injector.ELXR!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.58a39300d73290e3
SophosMal/Fareit-AA
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.UXET-2696
WebrootW32.Trojan.Gen
AviraTR/Injector.gnlah
MAXmalware (ai score=100)
MicrosoftVirTool:Win32/Occamy.AA
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
AhnLab-V3Suspicious/Win.Delphiless.X2066
Acronissuspicious
VBA32Trojan.Wacatac
ALYacGen:Variant.Zusy.303686
Ad-AwareGen:Variant.Zusy.303686
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ZonerTrojan.Win32.74414
TrendMicro-HouseCallTSPY_HPLOKI.SMBD
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Injector!/fHzhr931MQ
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_100%
GDataGen:Variant.Zusy.303686
BitDefenderThetaGen:NN.ZelphiF.34110.OGW@a4XtLrki
AVGWin32:Trojan-gen
Cybereasonmalicious.64c9c5
AvastWin32:Trojan-gen

How to remove VirTool:Win32/Occamy.AA?

VirTool:Win32/Occamy.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment