Trojan

About “Win32/TrojanDownloader.Small.OCD” infection

Malware Removal

The Win32/TrojanDownloader.Small.OCD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Small.OCD virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Win32/TrojanDownloader.Small.OCD?


File Info:

name: EFADF20C27E655714112.mlw
path: /opt/CAPEv2/storage/binaries/c3ac2ee1c24f219909d8baddb90df09161170dad13477c3775586ec2b72cdd2c
crc32: C8ED5EE8
md5: efadf20c27e655714112c4835f0dd541
sha1: e48720f24375d9bb6046b04a305c5ed94e39471a
sha256: c3ac2ee1c24f219909d8baddb90df09161170dad13477c3775586ec2b72cdd2c
sha512: 5204a69e560e37d071afce49b38118eec80fae3797436feb1a69e37ee0ff5b7b3f4c0d6872cfd956775a231e7d463740e7fc98f9e39d6b57444f6a21d78dbbdb
ssdeep: 3072:kdPXqBloKbgbntDbgbntW5n2ThWsNexPnCrnkDKt5n2ThWsNexPnCrnd:khqBloKbSxbSankP+6bkD4nkP+6bd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFC3127763036A33F94179B3E76A599C04BEA3908EDBE5F0CA95B6FB8475C01014AB0D
sha3_384: 0cc43792d3c3f98c0eb5841bcaf86078528fd78c1d1cac738e61abffbc0c65e8f675c71417aaf0c28a7505373da5f08e
ep_bytes: 60be000041008dbe0010ffff5783cdff
timestamp: 2008-03-03 22:24:20

Version Info:

0: [No Data]

Win32/TrojanDownloader.Small.OCD also known as:

tehtrisGeneric.Malware
DrWebTrojan.PWS.Pace
MicroWorld-eScanTrojan.Downloader.Small.AAKR
FireEyeGeneric.mg.efadf20c27e65571
CAT-QuickHealTrojan.Toga.9282
ALYacTrojan.Downloader.Small.AAKR
CylanceUnsafe
ZillyaDownloader.Small.Win32.23837
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 000415851 )
K7GWEmailWorm ( 000415851 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.7F0A8C521B
CyrenW32/Downloader.OVCG-3444
SymantecW32.SillyFDC
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Small.OCD
TrendMicro-HouseCallWORM_SOCKS.EC
ClamAVWin.Worm.Socks-8976450-0
KasperskyTrojan-Ransom.Win32.Blocker.jckk
BitDefenderTrojan.Downloader.Small.AAKR
NANO-AntivirusTrojan.Win32.Small.mqehs
AvastWin32:Small-JVY [Trj]
Ad-AwareTrojan.Downloader.Small.AAKR
EmsisoftTrojan.Downloader.Small.AAKR (B)
ComodoTrojWare.Win32.TrojanDownloader.Small.OCD@dg9i
BaiduWin32.Trojan-Downloader.Agent.au
VIPRETrojan.Downloader.Small.AAKR
TrendMicroWORM_SOCKS.EC
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Koceg-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.Downloader.Small.AAKR
JiangminWorm/AutoRun.gxl
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.4A
ArcabitTrojan.Downloader.Small.AAKR
ViRobotTrojan.Win32.Downloader.25975
ZoneAlarmTrojan-Ransom.Win32.Blocker.jckk
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R40749
McAfeeGenericRXAA-AA!EFADF20C27E6
VBA32BScope.Trojan.Click
MalwarebytesGeneric.Trojan.Obfuscator.DDS
APEXMalicious
RisingTrojan.Agent!1.6618 (CLASSIC)
IkarusTrojan-Downloader.Win32.Small
FortinetW32/Socks.NAL!tr
AVGWin32:Small-JVY [Trj]
Cybereasonmalicious.c27e65
PandaTrj/Genetic.gen

How to remove Win32/TrojanDownloader.Small.OCD?

Win32/TrojanDownloader.Small.OCD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment