Malware

Troj/IcedID-K information

Malware Removal

The Troj/IcedID-K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/IcedID-K virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
help.twitter.com
www.intel.com
support.apple.com
support.oracle.com
voairtaxetion.xyz

How to determine Troj/IcedID-K?


File Info:

crc32: 7BB8C3BA
md5: 8b349de882d6375f99dc3a55b1f868bb
name: upload_file
sha1: 5bcf9b1063d02776255646bcb30f51b727cca682
sha256: c6472bae69e266ae072de28f0ce49161edc6bf041fbfcc59dd7ee4a18a51a283
sha512: 8fd80418573be6bd5a976fa883daaf6a406a5bef89f41fba28e88ef5d66a81b0d34228559170c34b5a4b098e52a085b39b8dd7a6d3b84e27a8d8942d2c969d58
ssdeep: 3072:PgBZ6gDqiaAewY7mp9mAW/OJwBXpAvvfDwnxbXt2EL4785h5DdKSb947RIkt:ybVm7mp9qYw1yv+xJ/s785Fi7akt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2011 Close Believe 22 Corporation. All rights reserved.
InternalName: Product.dll
FileVersion: 0.4.3.470
Figure: Chair
CompanyName: Close Believe 22
ProductName: Close Believe 22 Rose class
ProductVersion: 0.4.3.470
OriginalFilename: Product.dll
Translation: 0x0409 0x04b0

Troj/IcedID-K also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.35077347
FireEyeTrojan.GenericKD.35077347
McAfeeRDN/Generic.hbg
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.35077347
K7GWTrojan ( 0056ae771 )
K7AntiVirusTrojan ( 0056ae771 )
TrendMicroTrojan.Win32.ICEDID.THKOFBO
CyrenW32/Agent.BZN.gen!Eldorado
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
AlibabaTrojan:Win32/IcedId.405d057a
ViRobotTrojan.Win32.Z.Icedid.168448.A
AegisLabTrojan.Win32.Generic.4!c
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.35077347
SophosTroj/IcedID-K
DrWebTrojan.IcedID.30
InvinceaMal/Generic-R + Troj/IcedID-K
McAfee-GW-EditionRDN/Generic.hbg
EmsisoftTrojan.GenericKD.35077347 (B)
IkarusTrojan.Win32.Crypt
AviraTR/AD.PhotoDlder.vndya
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/IcedId.DM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2173CE3
GDataTrojan.GenericKD.35077347
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Kryptik.HEZX
VBA32Trojan.IcedID
ALYacTrojan.IcedID.gen
MalwarebytesTrojan.IcedID
RisingTrojan.Kryptik!8.8 (TFE:5:8g4bniFx34H)
MaxSecureTrojan.Malware.109320367.susgen
FortinetW32/Kryptik.HEZX!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
Qihoo-360Generic/Trojan.ad1

How to remove Troj/IcedID-K?

Troj/IcedID-K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment