Trojan

Trojan.OccamyVMF.S22458059 removal instruction

Malware Removal

The Trojan.OccamyVMF.S22458059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.OccamyVMF.S22458059 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.OccamyVMF.S22458059?


File Info:

name: 64D3E041558A0C4D03B4.mlw
path: /opt/CAPEv2/storage/binaries/9565b9df4e669b956e6ea171e184445860345726e378a4df471a4a602b015cf1
crc32: 30D18B9A
md5: 64d3e041558a0c4d03b4c0795e9648ec
sha1: 5c3463958983ec8054e091424d5ddcb3ee5ab070
sha256: 9565b9df4e669b956e6ea171e184445860345726e378a4df471a4a602b015cf1
sha512: e9581b5f72b2ff54cadf2eecaca1bc59528fa842b631cf5517e111047460d282c01c15f63f423f08c2cac27e94cbee4b8958a035e0a0b2d3ec7c398b32b4d0bf
ssdeep: 6144:kydwVexUPYfDekgnGT3wFGptwzCA0ganVY0AJFlTuTyk8DnHd194LDE1xoI:h+YxNekgnGTwFGT7nVYf7wyBHCLDGOI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9B4541D39A23504D65ED5FE8464FDC8BAF131BD3015082AACF7D8A1E660EC6E846E36
sha3_384: ff40959cf926d91a684c3c3a7ec9f56d06369b863c072616cb2b138a05d3de2ff0beb78977074c65cae65ca0582e6329
ep_bytes: 60be003042008dbe00e0fdff5783cdff
timestamp: 2012-02-03 10:51:15

Version Info:

Translation: 0x0412 0x04b0
ProductName: 야마토런처
FileVersion: 1.00
ProductVersion: 1.00
InternalName: launcher
OriginalFilename: launcher.exe

Trojan.OccamyVMF.S22458059 also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.64d3e041558a0c4d
CAT-QuickHealTrojan.OccamyVMF.S22458059
McAfeeGenericR-NTE!9514EA026E82
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZevbaCO.34212.GmNfa47aU2mG
SymantecML.Attribute.HighConfidence
McAfee-GW-EditionBehavesLike.Win32.Autorun.hc
eGambitUnsafe.AI_Score_65%
AviraTR/Dropper.Gen
Antiy-AVLGrayWare/Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesTrojan.Agent
APEXMalicious
RisingDropper.Generic!8.35E (RDMK:cmRtazpYwt9c5SFF83nQ8LQ1L93Y)
YandexTrojan.GenAsa!gXFK/v4D/fA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.58983e

How to remove Trojan.OccamyVMF.S22458059?

Trojan.OccamyVMF.S22458059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment