Trojan

Trojan:Win32/IcedId.VSL!MTB removal

Malware Removal

The Trojan:Win32/IcedId.VSL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IcedId.VSL!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/IcedId.VSL!MTB?


File Info:

crc32: 1C46648B
md5: 34661e2e859dcb12de17556752ace1fd
name: 34661E2E859DCB12DE17556752ACE1FD.mlw
sha1: 02138773832f9680a242d6e403f10c3a5fb9588e
sha256: c554ec9e46079b975bf33b32e0634ac45253e157c127135063ad4243b1381453
sha512: 02ab0cec1ff9787a614190ec42f699988aa8ef4a4cb4c7383de171e4e51dd318ca809af522e0d3798b9c906f48aaa478f1bb9fe6bfe14a3c43f6e7f7df36cd72
ssdeep: 6144:TV5oNXnsKT/bg5+b+urdCCjVCmM+LHtNFfeLF0:p5o9sm/bk+b+urdxdMIDFWL
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Foodtake Corporation. All rights reserved
InternalName: Tree Connect
FileVersion: 6.1.0.293
CompanyName: Foodtake Corporation
ProductName: Foodtakexae Earlythatxae
ProductVersion: 6.1.0.293
FileDescription: Foodtake Earlythat
OriginalFilename: dance.dll
Translation: 0x0409 0x04b0

Trojan:Win32/IcedId.VSL!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.54991
MicroWorld-eScanGen:Variant.Midie.77657
Qihoo-360Trojan.Generic
McAfeeGenericRXMZ-HE!34661E2E859D
SangforMalware
K7AntiVirusTrojan ( 005749361 )
BitDefenderGen:Variant.Midie.77657
K7GWTrojan ( 005749361 )
CyrenW32/Trojan.QPZY-7457
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agentb.gen
AlibabaTrojan:Win32/IcedId.8e22905e
Ad-AwareGen:Variant.Midie.77657
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.ytxej
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Midie.77657
EmsisoftGen:Variant.Midie.77657 (B)
AviraTR/Kryptik.ytxej
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/IcedId.VSL!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Midie.D12F59
AegisLabTrojan.Win32.Agentb.4!c
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
GDataGen:Variant.Midie.77657
CynetMalicious (score: 100)
ALYacTrojan.IcedID.gen
MAXmalware (ai score=83)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EYGG
RisingTrojan.GenKryptik!8.AA55 (TFE:5:aYibQkvXykJ)
FortinetW32/GenKryptik.EYGG!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]

How to remove Trojan:Win32/IcedId.VSL!MTB?

Trojan:Win32/IcedId.VSL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment