Trojan

Trojan:Win32/Occamy.C53 removal

Malware Removal

The Trojan:Win32/Occamy.C53 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C53 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan:Win32/Occamy.C53?


File Info:

crc32: 9AE75B2C
md5: d11056f9292c6635d47f4cd78fe9678a
name: D11056F9292C6635D47F4CD78FE9678A.mlw
sha1: c13ef3123f6be137c9f8fb4279d9883fec37191e
sha256: 5354031d6e2621533b09d2189b857be02793265093b4371d1b473be78bc35422
sha512: f9f1a30fa5bebf390dd85f4da35a610e98e671b69b86a4c2e7bc71a5a35635aa4d45cbbc379027fefbea03184767271513e837c27653c0549dc559fe57861e9c
ssdeep: 3072:w6Ek5P4Y+oBsdMuAKYszXhaomeFmfQLT34bbQX9V:tBKYs7tluUb4bb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 3.7.9

Trojan:Win32/Occamy.C53 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacGen:Variant.Ransom.GandCrab.1951
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.cba813a5
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.9292c6
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJNH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.GandCrab.1951
NANO-AntivirusTrojan.Win32.Kryptik.fgzrnr
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1951
Ad-AwareGen:Variant.Ransom.GandCrab.1951
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.PSW.Coins.FS@7s47lc
BitDefenderThetaGen:NN.ZexaF.34670.ku0@aWOLgTpQ
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.d11056f9292c6635
EmsisoftGen:Variant.Ransom.GandCrab.1951 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.aog
AviraHEUR/AGEN.1102756
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Fuerboos
MicrosoftTrojan:Win32/Occamy.C53
ArcabitTrojan.Ransom.GandCrab.D79F
AegisLabTrojan.Win32.Coins.i!c
GDataGen:Variant.Ransom.GandCrab.1951
AhnLab-V3Win-Trojan/Gandcrab04.Exp
Acronissuspicious
McAfeePacked-FJN!D11056F9292C
MAXmalware (ai score=100)
VBA32BScope.Trojan.Vigorf
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.Agent!/D7lhzKlzQo
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCEpsA

How to remove Trojan:Win32/Occamy.C53?

Trojan:Win32/Occamy.C53 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment