Trojan

Trojan:Win32/Occamy.C03 removal instruction

Malware Removal

The Trojan:Win32/Occamy.C03 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C03 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Trojan:Win32/Occamy.C03?


File Info:

crc32: 49DF9304
md5: ef15cfcd483155f482a89bca4dfae990
name: googlemap.exe
sha1: 17c5c9e75169bc52d3fe21f92cae4e9e014b0fed
sha256: 03bf37535365b57967705099da2ad4521058403639a4a2e4382b9e5242982f21
sha512: 614a2487f40cda5e200525d24f0fca9749a548208105db571f359687d28ef0a71fad4394554ebef7519a436423d7e566b352c54d7104cf56573867793d85e16f
ssdeep: 49152:11fkdof6rlk4zjxHCn7cJ/cVp06jmpEW/S/jtK2CJQBWIrYwsY5mxVjrhagDE1g:nlCe4zVHIy/cVC6auuWK2xdIW+jlyg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: all rights reserved
FileVersion: 4.6.0.9
CompanyName: Bartkowalski-1960-Matchbox-Cars-Hatra-Tractor-Shovel june
LegalTrademarks: Bartkowalski-1960-Matchbox-Cars-Hatra-Tractor-Shovel company all rights
Comments: Bartkowalski-1960-Matchbox-Cars-Hatra-Tractor-Shovel june
ProductName: Bartkowalski-1960-Matchbox-Cars-Hatra-Tractor-Shovel
Translation: 0x0409 0x04e4

Trojan:Win32/Occamy.C03 also known as:

BkavHW32.Packed.
ClamAVWin.Malware.Score-6931191-0
FireEyeGen:Variant.Ursu.917740
Qihoo-360Generic/Trojan.Dropper.e13
McAfeeArtemis!EF15CFCD4831
CylanceUnsafe
AegisLabTrojan.NSIS.Agent.b!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Ursu.917740
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyHEUR:Trojan-Dropper.NSIS.Agent.gen
MicroWorld-eScanGen:Variant.Ursu.917740
Ad-AwareGen:Variant.Ursu.917740
EmsisoftGen:Variant.Ursu.917740 (B)
F-SecureTrojan.TR/Redcap.eomon
DrWebTrojan.MulDrop13.2281
McAfee-GW-EditionBehavesLike.Win32.Browser.vc
SophosMal/Generic-S
IkarusTrojan.Inject
AviraTR/Redcap.eomon
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DE00EC
ViRobotTrojan.Win32.S.Agent.2709470
ZoneAlarmHEUR:Trojan-Dropper.NSIS.Agent.gen
MicrosoftTrojan:Win32/Occamy.C03
ALYacGen:Variant.Ursu.917740
MalwarebytesTrojan.Dropper.SFX
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H07FL20
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
GDataGen:Variant.Ursu.917740
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan:Win32/Occamy.C03?

Trojan:Win32/Occamy.C03 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment