Trojan

Trojan.IcedID.Gen removal tips

Malware Removal

The Trojan.IcedID.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.IcedID.Gen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.intel.com
help.twitter.com
support.oracle.com
support.apple.com
loadbudapest.casa

How to determine Trojan.IcedID.Gen?


File Info:

crc32: E8CFD9DF
md5: 76679ed03c0f77fa6ccd1f3d35a6f979
name: upload_file
sha1: 6bf344d524598e18b0a32c6c6a8b03c8fd9b7dc8
sha256: e7d1ee172b95df20dc90f3100a5b06fb150408b76e92f159fd1e8e69c3c61035
sha512: 7fec84645f5284a3370a3fd6ce85bc17de92c576bff51c394dede5881f0402c9cc60a8559a92cf8c8cc15cd97d72161614eabddbb2ee866581392ae101d34f33
ssdeep: 3072:6KBvXLIOI4Bg6YJdC1ZxZgpARBk+ltNuVH:6wvCJA8sB3tg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.IcedID.Gen also known as:

MicroWorld-eScanTrojan.GenericKDZ.69140
FireEyeGeneric.mg.76679ed03c0f77fa
McAfeeGenericRXLO-ME!76679ED03C0F
BitDefenderTrojan.GenericKDZ.69140
K7GWTrojan ( 0056ba501 )
K7AntiVirusTrojan ( 0056ba501 )
TrendMicroTROJ_GEN.R002C0DGV20
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.69140
KasperskyTrojan-Banker.Win32.IcedID.twoh
AlibabaTrojanBanker:Win32/IcedID.7cd1a9a3
TencentWin32.Trojan-banker.Icedid.Ahet
Ad-AwareTrojan.GenericKDZ.69140
SophosMal/Generic-S
Comodofls.noname@0
F-SecureTrojan.TR/AD.PhotoDlder.zakcs
DrWebTrojan.IcedID.30
VIPRETrojan.Win32.Generic!BT
MaxSecureWin.MxResIcn.Heur.Gen
EmsisoftTrojan.GenericKDZ.69140 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.PKQC-8338
JiangminTrojan.Banker.IcedID.nz
WebrootW32.Trojan.Gen
AviraTR/AD.PhotoDlder.zakcs
MAXmalware (ai score=82)
Antiy-AVLTrojan[Banker]/Win32.IcedID
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D10E14
ZoneAlarmTrojan-Banker.Win32.IcedID.twoh
MicrosoftTrojan:Win32/IcedId.DB!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.R346572
ALYacTrojan.IcedID.Gen
TACHYONBanker/W32.IcedID.176128
MalwarebytesTrojan.MalPack.RND
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFGV
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
RisingTrojan.Kryptik!1.C9A9 (CLASSIC)
BitDefenderThetaGen:NN.ZedlaF.34144.ku4@a4vY1rc
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.5b8

How to remove Trojan.IcedID.Gen?

Trojan.IcedID.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment