Trojan

How to remove “Trojan:Win32/Occamy.CD1”?

Malware Removal

The Trojan:Win32/Occamy.CD1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CD1 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

z.whorecord.xyz
a.tomx.xyz
update.teenup.or.kr

How to determine Trojan:Win32/Occamy.CD1?


File Info:

crc32: DB398848
md5: 7a2ebcac101151170eeed1c3d40907f1
name: 7A2EBCAC101151170EEED1C3D40907F1.mlw
sha1: 9c38c88f18b9dc118312312f6cfe9f3b02c64ae7
sha256: d11f9cecc705d2a2561dc0001587d1cf7e4d7bc4c4812c8c6c5ca4e547fd3e94
sha512: fbc589d9b0ca43b7a5316440849f40e308bfa3d972650c76e5f07297094cf927585d86eecef1a9a583bd3d5258c8add4da46fd09d95bb726567f115481bcb0fb
ssdeep: 24576:Brc/jBkuPFS+anXf0TLzMCHnT+IUI+wxQ0SCxocL7rT5VvpKx4zmx9T6sC:B6enCHCPJWocL7rT5h0izmXT6sC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) NetFly. All rights reserved.
InternalName: TeenupExamManager.exe
FileVersion: 2014, 4, 30, 0
CompanyName: NetFly
ProductVersion: 1, 0, 0, 1
FileDescription: xc9c1xc5c5xae30xcd08xb2a5xb825xd3c9xac00 xac10xb3c5xad50xc0ac
OriginalFilename: TeenupExamManager.exe
Translation: 0x0412 0x03b5

Trojan:Win32/Occamy.CD1 also known as:

K7AntiVirusRiskware ( 0049f6ae1 )
LionicTrojan.Win32.Blocker.j!c
ALYacTrojan.GenericKD.3581875
CylanceUnsafe
ZillyaTrojan.BlockerCRTD.Win32.10838
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Blocker.e9320b77
K7GWRiskware ( 0049f6ae1 )
Cybereasonmalicious.c10115
SymantecTrojan.Gen
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Ransomware.0049f6ae-7
KasperskyTrojan-Ransom.Win32.Blocker.iapj
BitDefenderTrojan.GenericKD.3581875
NANO-AntivirusTrojan.Win32.Blocker.enpvil
MicroWorld-eScanTrojan.GenericKD.3581875
TencentWin32.Trojan.Blocker.Ahfa
Ad-AwareTrojan.GenericKD.3581875
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.3581875
EmsisoftTrojan.GenericKD.3581875 (B)
JiangminTrojan.Blocker.fhv
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.CD1
GDataTrojan.GenericKD.3581875
McAfeeArtemis!7A2EBCAC1011
MAXmalware (ai score=86)
PandaTrj/CI.A
FortinetW32/Blocker.IAPJ!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan:Win32/Occamy.CD1?

Trojan:Win32/Occamy.CD1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment