Malware

Should I remove “VirTool:Win32/Occamy.C”?

Malware Removal

The VirTool:Win32/Occamy.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Occamy.C virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

www.sostronk.com
ocsp.pki.goog
dl.sostronk.com

How to determine VirTool:Win32/Occamy.C?


File Info:

crc32: DB08F90D
md5: 7a5310f42f25fccd0507ac974a630254
name: 7A5310F42F25FCCD0507AC974A630254.mlw
sha1: 574555b695129634a54aa0ec93b0bf082376e237
sha256: 43f5da1590cbff8990c2d55d3f472321e2f56ee022f8c3d1897f1e0598577136
sha512: a5d26398f5a54abbafc7e60d60137d67f1e7b8e9a3c472342dd669733213e236857008c27f894ee5f48e5890e5161b42e473f61870bbde3e400f420001fb4dca
ssdeep: 3072:jAsj8MBX8s0oXJos6RGeLh1IlkHBMFrAPDckULurWcEiDoThqd1PB:jAsBZms6YahMF8PIkULurKZNqdb
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

VirTool:Win32/Occamy.C also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 99)
McAfeeArtemis!7A5310F42F25
CylanceUnsafe
ZillyaTrojan.RansomKD.Win32.77
SangforTrojan.Win32.Bitrep.8
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.42f25f
SymantecRansom.Cerber
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.RansomKD.5986697
MicroWorld-eScanTrojan.RansomKD.5986697
Ad-AwareTrojan.RansomKD.5986697
SophosMal/Generic-S
ComodoMalware@#af83jvqecigg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
FireEyeGeneric.mg.7a5310f42f25fccd
EmsisoftTrojan.RansomKD.5986697 (B)
WebrootW32.Trojan.RansomKD
AviraTR/StartPage.ibtfv
MicrosoftVirTool:Win32/Occamy.C
ArcabitTrojan.RansomKD.D5B5989
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.RansomKD.5986697
AhnLab-V3Trojan/Win32.Occamy.C2610505
VBA32suspected of Trojan.Downloader.gen
MAXmalware (ai score=100)
PandaTrj/CI.A
FortinetPossibleThreat
AVGWin32:Malware-gen

How to remove VirTool:Win32/Occamy.C?

VirTool:Win32/Occamy.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment