Malware

What is “Troj/IcedID-K”?

Malware Removal

The Troj/IcedID-K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/IcedID-K virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

help.twitter.com
www.intel.com
support.apple.com
support.oracle.com
voairtaxetion.xyz

How to determine Troj/IcedID-K?


File Info:

crc32: 7EB1EF69
md5: 2fd8674aa0d866d91d3daebafb8cb597
name: upload_file
sha1: 21222c38a19af737932a02778a1f3aee90c16e70
sha256: ad0fbe340bf6448e7f8d4179a2eb5774e0f4a1757262b659214903cdf2f6dfb8
sha512: 64770906d3435f47a997941559b2ff74bc9a3c32a7da31dde6174b83e4fdd1da1f4ffd42fee266a20fa9fa6ddf719828aad9d540862c311c6833ab89c917f2eb
ssdeep: 3072:PgBi6gDqiaAewY7mp9mAW/OJwBXpAvvfDwnxbXt2EL4785h5DdKSb947RIkt:lbVm7mp9qYw1yv+xJ/s785Fi7akt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2011 Close Believe 22 Corporation. All rights reserved.
InternalName: Product.dll
FileVersion: 0.4.3.470
Figure: Chair
CompanyName: Close Believe 22
ProductName: Close Believe 22 Rose class
ProductVersion: 0.4.3.470
OriginalFilename: Product.dll
Translation: 0x0409 0x04b0

Troj/IcedID-K also known as:

MicroWorld-eScanTrojan.GenericKD.35077231
FireEyeTrojan.GenericKD.35077231
McAfeeRDN/Generic.hbg
MalwarebytesTrojan.IcedID
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
BitDefenderTrojan.GenericKD.35077231
K7GWTrojan ( 0056ae771 )
K7AntiVirusTrojan ( 0056ae771 )
TrendMicroTrojan.Win32.ICEDID.THKOFBO
CyrenW32/Agent.BZN.gen!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
AlibabaTrojan:Win32/IcedId.1ac47816
Ad-AwareTrojan.GenericKD.35077231
SophosTroj/IcedID-K
F-SecureTrojan.TR/AD.PhotoDlder.vndya
DrWebTrojan.IcedID.30
InvinceaMal/Generic-R + Troj/IcedID-K
McAfee-GW-EditionRDN/Generic.hbg
EmsisoftTrojan.GenericKD.35077231 (B)
AviraTR/AD.PhotoDlder.vndya
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/IcedId.DM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2173C6F
GDataTrojan.GenericKD.35077231
CynetMalicious (score: 100)
ALYacTrojan.IcedID.gen
MAXmalware (ai score=80)
VBA32Trojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEZX
TrendMicro-HouseCallTrojan.Win32.ICEDID.THKOFBO
RisingTrojan.Kryptik!8.8 (TFE:5:8g4bniFx34H)
FortinetW32/Kryptik.HEZX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.ad1

How to remove Troj/IcedID-K?

Troj/IcedID-K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment