Trojan

TrojanDownloader:O97M/IcedID.PW!MTB information

Malware Removal

The TrojanDownloader:O97M/IcedID.PW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/IcedID.PW!MTB virus can do?

  • The office file contains 4 macros
  • The office file contains a macro with auto execution
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine TrojanDownloader:O97M/IcedID.PW!MTB?


File Info:

crc32: 4A695239
md5: 2b8435a6132c8a84ca374a4e09f56d48
name: upload_file
sha1: aa42c69b66879f887cad87b439aae85d321ff21f
sha256: 70a307513785f96c821eaef340cd69841b6d44dcf42eb721e0dfa4778434ae95
sha512: afee0aaff9c08cd4265abc9b32c243c4017b234b73f951e514edb58e181d6eef781565dec78ea240d49658589c79203b75256147ac2eb5763814b729b624c081
ssdeep: 3072:GlxFfIGnuO1Xfa+4r1mjNTBJCWk8XCChj/AVONTtcM9I6Bvg6aKunGgzVBfNT:GlTDnjxa+4r1mZTpxCWj/AVQTtB9ZI6A
type: Microsoft Word 2007+

Version Info:

0: [No Data]

TrojanDownloader:O97M/IcedID.PW!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34797588
FireEyeTrojan.GenericKD.34797588
AegisLabTrojan.MSWord.Generic.4!c
BitDefenderTrojan.GenericKD.34797588
TrendMicroHEUR_VBA.O2
SymantecISB.Downloader!gen428
KasperskyHEUR:Trojan-Downloader.MSOffice.Agent.gen
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
Ad-AwareTrojan.GenericKD.34797588
EmsisoftTrojan.GenericKD.34797588 (B)
McAfee-GW-EditionBehavesLike.Downloader.cc
IkarusWin32.Outbreak
GDataTrojan.GenericKD.34797588
MicrosoftTrojanDownloader:O97M/IcedID.PW!MTB
ArcabitTrojan.Generic.D212F814
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.Agent.gen
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=89)
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UQR
TencentHeur.Macro.Generic.h.3ff8b502
SentinelOneDFI – Malicious OPENXML
FortinetVBA/Agent.UQR!tr.dldr
Qihoo-360virus.office.obfuscated.1

How to remove TrojanDownloader:O97M/IcedID.PW!MTB?

TrojanDownloader:O97M/IcedID.PW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment