Trojan

Trojan:Win32/Occamy.CD4 removal

Malware Removal

The Trojan:Win32/Occamy.CD4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CD4 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
grumpyfall.cc

How to determine Trojan:Win32/Occamy.CD4?


File Info:

crc32: DB599636
md5: aa13e132dfbe9fa419c203b0596ee874
name: AA13E132DFBE9FA419C203B0596EE874.mlw
sha1: 34fa8d522cbb5d3db1bd13f81b377ce9f1fc31c8
sha256: d45c2ec267407050d858913fa8b94528baef0a41ee5007710ff866a7faae3f20
sha512: 57c2d0e259eda4b5d1b5c3f23b924e47ee4064e1c90ce936c8846fb86c8ac4767a8877f37c0ce8555538d890e6807a90c6a30ce25b0b221e0e37a789ca928e36
ssdeep: 6144:5NmKOBgB+ZwFaOIe2eVF8Qy4xRemqv37rtdQZEHBZJ/4oa1:5czeFdzxMNd0GBZJ/4x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Sapphire Ventures xa9. All rights reserved.
InternalName: Facilitatin
FileVersion: 8.7.4.388
CompanyName: Sapphire Ventures
FileDescription: Waitone Penetration Translate Gradle Linen
LegalTrademarks: Sapphire Ventures xa9. All rights reserved.
Comments: Waitone Penetration Translate Gradle Linen
ProductName: Facilitatin
Languages: English
ProductVersion: 8.7.4.388
PrivateBuild: 8.7.4.388
OriginalFilename: Facilitatin
Translation: 0x0409 0x04b0

Trojan:Win32/Occamy.CD4 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.28481
MicroWorld-eScanTrojan.GenericKD.31318974
FireEyeGeneric.mg.aa13e132dfbe9fa4
CAT-QuickHealTrojanSpy.Ursnif
McAfeeArtemis!AA13E132DFBE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053fc591 )
BitDefenderTrojan.GenericKD.31318974
K7GWTrojan ( 0053fc591 )
Cybereasonmalicious.2dfbe9
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.Ursnif.abey
AlibabaTrojanSpy:Win32/Ursnif.21a68c36
NANO-AntivirusTrojan.Win32.Ursnif.fjtfgk
AegisLabTrojan.Win32.Ursnif.4!c
RisingRansom.Locky!8.1CD4 (CLOUD)
Ad-AwareTrojan.GenericKD.31318974
SophosMal/Generic-S
ComodoMalware@#2oxyfisgmw1r6
F-SecureHeuristic.HEUR/AGEN.1109235
ZillyaTrojan.Ursnif.Win32.3069
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionBehavesLike.Win32.Emotet.fh
EmsisoftTrojan.GenericKD.31318974 (B)
GDataTrojan.GenericKD.31318974
AviraHEUR/AGEN.1109235
Antiy-AVLTrojan[Spy]/Win32.Ursnif
ArcabitTrojan.Generic.D1DDE3BE
ZoneAlarmTrojan-Spy.Win32.Ursnif.abey
MicrosoftTrojan:Win32/Occamy.CD4
CynetMalicious (score: 100)
VBA32TrojanSpy.Ursnif
ALYacTrojan.GenericKD.31318974
MAXmalware (ai score=83)
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.CPCG
TrendMicro-HouseCallRansom_HPLOCKY.SME1
TencentWin32.Trojan-spy.Ursnif.Llqp
YandexTrojanSpy.Ursnif!mjV435cBbnM
IkarusTrojan-Ransom.GandCrab
FortinetW32/GenKryptik.CPCG!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Spy.027

How to remove Trojan:Win32/Occamy.CD4?

Trojan:Win32/Occamy.CD4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment