Spy

Win32/Spy.KeyLogger.OCU removal tips

Malware Removal

The Win32/Spy.KeyLogger.OCU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.OCU virus can do?

  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Win32/Spy.KeyLogger.OCU?


File Info:

name: 4E513FC370730EF094CD.mlw
path: /opt/CAPEv2/storage/binaries/a1ab36cec4ba2597ffe9d74b8501b2c5f96ca1039988def17f90f01b9f2ef633
crc32: 539E1763
md5: 4e513fc370730ef094cdaf8ecd144c4c
sha1: fdc6b2e0d57d6b3776d4d023319f3bfea794f3c2
sha256: a1ab36cec4ba2597ffe9d74b8501b2c5f96ca1039988def17f90f01b9f2ef633
sha512: 1bf3094280857691f792cf3d94e30a952ea1d6107d7fe17513d1d1bc0c5158527edd4cd9e1ec2a4b575089869041c37107eb4310b49dc47481141f66f631ead4
ssdeep: 6144:inwxsgX9nEbDeeZ1VnKX30FjFc1xcmJRpoh+nnrMKPZpljmYPpZ2wlm:lmOVEbD/n+kbc19JHohenXpkYPpowl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135A46D37B2E19437D1231B78CC2B5BA89D2ABE502D38A4463BE51F4C5F396817927393
sha3_384: f08a7114c1bfade6ddbb1d0e4050fa9143260b20edbc741ae33427c3a846582e9ef908fcde86c55c51e58a57e5645105
ep_bytes: 558bec83c4f0b828724600e88cf4f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x041f 0x04e6

Win32/Spy.KeyLogger.OCU also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qyslfg.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
McAfeeRDN/Generic PWS.y
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Keylogger.Win32.77276
SangforSpyware.Win32.KeyLogger.Vgsw
K7AntiVirusSpyware ( 000fcaa11 )
AlibabaTrojanSpy:Win32/KeyLogger.2ea88502
K7GWSpyware ( 000fcaa11 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.KeyLogger.OCU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.KeyLogger.gen
BitDefenderGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
NANO-AntivirusTrojan.Win32.KeyLogger.jupuos
AvastWin32:Trojan-gen
TencentWin32.Trojan-Spy.Keylogger.Dflw
EmsisoftGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG (B)
F-SecureTrojan.TR/Spy.KeyLogger.tkppd
VIPREGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.gh
Trapminemalicious.moderate.ml.score
FireEyeGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
SophosMal/Keylog-A
IkarusTrojan-PWS.Win32.Gestron
GDataGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
GoogleDetected
AviraTR/Spy.KeyLogger.tkppd
MAXmalware (ai score=87)
Antiy-AVLTrojan[Spy]/Win32.KeyLogger
ArcabitTrojan.SMTP-Mailer.E2CA7A
ZoneAlarmHEUR:Trojan-Spy.Win32.KeyLogger.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZelphiF.36196.DG0@a4qYSLfG
ALYacGen:Trojan.SMTP-Mailer.DG0@a4qYSLfG
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Generic@AI.90 (RDML:sN2m2JDQ1uWOyWznxFm6zA)
FortinetPossibleThreat.SB!tr.bdr
AVGWin32:Trojan-gen
Cybereasonmalicious.370730
DeepInstinctMALICIOUS

How to remove Win32/Spy.KeyLogger.OCU?

Win32/Spy.KeyLogger.OCU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment