Trojan

What is “Trojan:Win32/Occamy.CD3”?

Malware Removal

The Trojan:Win32/Occamy.CD3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CD3 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
dldir1.qq.com
a.tomx.xyz
go.browser.qq.com
wup.browser.qq.com

How to determine Trojan:Win32/Occamy.CD3?


File Info:

crc32: DC8828D4
md5: e451909bbb177feb987462db3d79c024
name: autoqq.exe
sha1: 82535598d59042ead7615b12cdb70e0c72d788f2
sha256: d3bb27d24c3be8318951126b11ea91bffef1a2f236e31424b44c22c3a9b5088d
sha512: e207fd8c26c4ac2f24cc1bf7b1695581083206dc5ff59e690609f943d9185d6dc6223219c493973ab53ef4020f258570cf322442911f4fa1840c7c7ec5a4231c
ssdeep: 192:cXqWhMppEvfKBTFfEHri26vPbiHDNF5uhNtiiqrDI1h+WsD304oXF:4qVECBT6tePmjP5uhNtgrEh2D304KF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: autoqq
FileVersion: 1.00
CompanyName: aaaa
ProductName: x5de5x7a0b1
ProductVersion: 1.00
OriginalFilename: autoqq.exe

Trojan:Win32/Occamy.CD3 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Heur.Mint.Zard.11
FireEyeGeneric.mg.e451909bbb177feb
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
K7AntiVirusTrojan ( 0050da3e1 )
BitDefenderGen:Heur.Mint.Zard.11
K7GWTrojan ( 0050da3e1 )
Cybereasonmalicious.bbb177
BitDefenderThetaAI:Packer.590E135F1F
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R002H0CGM20
GDataGen:Heur.Mint.Zard.11
KasperskyTrojan.Win32.VBKrypt.aakeh
AlibabaDownloader:Application/NewHeur.afe2aa0c
AegisLabTrojan.Win32.Mint.4!c
TencentWin32.Trojan.Dropper.Airh
Ad-AwareGen:Heur.Mint.Zard.11
SophosMal/Emogen-F
ComodoTrojWare.Win32.TrojanDownloader.VB.PMEA@4rev5s
F-SecureTrojan.TR/Dropper.VB.Gen7
EmsisoftGen:Heur.Mint.Zard.11 (B)
IkarusTrojan.NewHeur_VB_Downloader
CyrenW32/Trojan.UPIQ-0442
AviraTR/Dropper.VB.Gen7
ArcabitTrojan.Mint.Zard.11
SUPERAntiSpywareTrojan.Agent/Gen-Vbaj
ZoneAlarmTrojan.Win32.VBKrypt.aakeh
MicrosoftTrojan:Win32/Occamy.CD3
CynetMalicious (score: 85)
ALYacGen:Heur.Mint.Zard.11
MAXmalware (ai score=85)
APEXMalicious
ESET-NOD32a variant of NewHeur_VB_Downloader.2
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
eGambitUnsafe.AI_Score_59%
FortinetW32/VBKrypt.AAKEH!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.Dropper.890

How to remove Trojan:Win32/Occamy.CD3?

Trojan:Win32/Occamy.CD3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment