Trojan

Trojan:Win32/IcedId.DA!MTB removal tips

Malware Removal

The Trojan:Win32/IcedId.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IcedId.DA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests

Related domains:

www.intel.com
support.apple.com
nothingtodo.co

How to determine Trojan:Win32/IcedId.DA!MTB?


File Info:

crc32: 2C74CAFF
md5: af2422d5e39ffdc3a46e3756ffc6f388
name: upload_file
sha1: c05ed258567022463bfa5ce33245953fa323c72e
sha256: fea6c70f47f30de75105042cc9356b59def243bc60e5effefbe8b5b69dc61b1b
sha512: 41f3790ca420274bc4013529c0297c86aa714c0eca2efa69c109efc508f854abededb643af103ce75771aead6ab7695c20433472eaf0ef9557dbfa03df806d92
ssdeep: 3072:GQYETBgAE8/hID93UoTLKuingNHosBx+p+m6jbN:kEAOoTLKuinqIsBxk6p
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Syllable Mass their xa9 2013
InternalName: Before minute Cloud big
FileVersion: 3.7.0.898
CompanyName: Help RunList
ProductName: Side.dll
ProductVersion: 3.7.0.898
FileDescription: Syllable Mass their
Translation: 0x0409 0x04b0

Trojan:Win32/IcedId.DA!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43643647
FireEyeGeneric.mg.af2422d5e39ffdc3
Qihoo-360Win32/Trojan.dce
McAfeeGenericRXAA-AA!AF2422D5E39F
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.43643647
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.IcedID.twpw
AlibabaTrojanBanker:Win32/IcedID.72f0f87b
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareTrojan.GenericKD.43643647
Comodofls.noname@0
F-SecureTrojan.TR/Kryptik.mfyou
TrendMicroTROJ_GEN.R002C0DHC20
FortinetW32/GenKryptik.EQDC!tr
SophosTroj/Agent-BFJC
IkarusTrojan-Banker.IcedID
CyrenW32/Trojan.SKCV-9080
AviraTR/Kryptik.mfyou
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D299F2FF
ZoneAlarmTrojan-Banker.Win32.IcedID.twpw
MicrosoftTrojan:Win32/IcedId.DA!MTB
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZedlaF.34152.ju8@aS4DRjci
ALYacTrojan.IcedID.gen
VBA32BScope.TrojanSpy.Zbot
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQDC
TrendMicro-HouseCallTROJ_GEN.R002C0DHC20
GDataTrojan.GenericKD.43643647
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/IcedId.DA!MTB?

Trojan:Win32/IcedId.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment