Trojan

How to remove “Trojan:Win32/Occamy.C80”?

Malware Removal

The Trojan:Win32/Occamy.C80 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.C80 virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Trojan:Win32/Occamy.C80?


File Info:

crc32: D9097E3F
md5: 91a11726dba01ae1d78a4102743d9aff
name: 4.exe
sha1: fd12633010c0f5e2ea34bb428143024a7eaa682f
sha256: 80c7f9af9097fa0f8d5cdbbeab9128ee6d524d0c4eea4f95cf55b9cd687fce2b
sha512: ca7e2158c983f18e062b61be9b03c8bebc5923dbbd7588125e1be77d0400ededa363659bff6d68e2929f20c92d219c72817de726e68f62b2727d6b8813a74d0e
ssdeep: 12288:CM/6dm3LuEH5/5lJ0Bg2K2USXL9WnrL4kYys1j6ZD71Clq0eNwtX9F+f11/dp:8UTSBUS79IL5Yys1jm71CotSt9F+X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2020 International GeoGebra Institute
InternalName: Setup.exe
FileVersion: 6.0.588
CompanyName: International GeoGebra Institute
SquirrelAwareVersion: 1
ProductName: GeoGebra Classic
ProductVersion: 6.0.588
FileDescription: GeoGebra Classic
OriginalFilename: Setup.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Occamy.C80 also known as:

BkavW32.AIDetectVM.malwareB
MicroWorld-eScanTrojan.GenericKD.43368661
FireEyeGeneric.mg.91a11726dba01ae1
CAT-QuickHealTrojan.Multi
McAfeeGenericRXLB-UP!91A11726DBA0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0054c4a01 )
BitDefenderTrojan.GenericKD.43368661
K7GWTrojan ( 0054c4a01 )
TrendMicroTROJ_GEN.R057C0WFL20
BitDefenderThetaGen:NN.ZexaF.34128.gv0@aiRf8Moi
CyrenW32/Trojan.BQWW-1847
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ClipBanker.IR
TrendMicro-HouseCallTROJ_GEN.R057C0WFL20
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.43368661
KasperskyTrojan-Banker.Win32.ClipBanker.lvj
AlibabaTrojanBanker:Win32/ClipBanker.bafafab7
APEXMalicious
TencentMalware.Win32.Gencirc.119a0402
Ad-AwareTrojan.GenericKD.43368661
EmsisoftTrojan.GenericKD.43368661 (B)
ComodoMalware@#1n0xb2zggl7t3
F-SecureTrojan.TR/ClipBanker.wxqms
DrWebTrojan.MulDrop11.52446
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tm
SophosMal/Generic-S
IkarusTrojan.Win32.Clipbanker
JiangminTrojan.Banker.ClipBanker.aee
AviraTR/ClipBanker.wxqms
MAXmalware (ai score=82)
Antiy-AVLTrojan[Banker]/Win32.ClipBanker
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D295C0D5
ZoneAlarmTrojan-Banker.Win32.ClipBanker.lvj
MicrosoftTrojan:Win32/Occamy.C80
CynetMalicious (score: 85)
VBA32BScope.TrojanDropper.Scrop
ALYacTrojan.GenericKD.43368661
MalwarebytesTrojan.ClipBanker.VMP
PandaTrj/CI.A
RisingTrojan.ClipBanker!8.5FB (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetW32/ClipBanker.IR!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.a94

How to remove Trojan:Win32/Occamy.C80?

Trojan:Win32/Occamy.C80 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment