Malware

Win32.WhiteIce.Dam removal guide

Malware Removal

The Win32.WhiteIce.Dam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.WhiteIce.Dam virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32.WhiteIce.Dam?


File Info:

crc32: EF2E74BE
md5: ac82d7b638e97c1131b07e2246e3880a
name: AC82D7B638E97C1131B07E2246E3880A.mlw
sha1: 4c0090e8c0b9033b289929ebbfec0e524666d5ff
sha256: dbd7f68bd2953338ba041bf58642eb6ee0feee6c7a4b93c798b47c6a7782003e
sha512: 0e83571ff2ceb1edb780a74b1070ae1d3617991453662924415ecc07e845f068c6468ee76b6fddff805f6f1a127c502c08d93a28135a9f094065caca926e1544
ssdeep: 3072:Amilo6Qp+1vMjRkT5ZFE5p62cCNvR44c2qCJuJggA9l:vHr44PDJuqgA9l
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1990-2000 InstallShield Software Corporation, Phone: (847) 240-9111
InternalName: Setup Launcher
FileVersion: 6, 10, 100, 1281
CompanyName: InstallShield Software Corporation
ProductName: InstallShield (R)
ProductVersion: 6, 10
FileDescription: InstallShield (R) Setup Launcher
OriginalFilename: Setup.exe
Translation: 0x0409 0x04b0

Win32.WhiteIce.Dam also known as:

Elasticmalicious (high confidence)
DrWebWin32.HLLW.Bice.8
MicroWorld-eScanWin32.WhiteIce.Dam
FireEyeGeneric.mg.ac82d7b638e97c11
ALYacWin32.WhiteIce.Dam
CylanceUnsafe
VIPREVirus.Win32.Tufik.ab (v)
SangforMalware
K7AntiVirusTrojan ( 004bf69e1 )
BitDefenderWin32.WhiteIce.Dam
K7GWTrojan ( 004bf69e1 )
Cybereasonmalicious.638e97
BitDefenderThetaAI:FileInfector.F4766A9612
CyrenW32/Injector.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Susp.PackedProcInject_im
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Rxugpefbb-7101107-0
KasperskyWorm.Win32.WhiteIce.el
AlibabaWorm:Win32/WhiteIce.6bac75f0
NANO-AntivirusTrojan.Win32.WhiteIce.cyctb
TencentWorm.Win32.Blackice.a
Ad-AwareWin32.WhiteIce.Dam
SophosMal/Generic-S
ComodoMalware@#17reey7bdp9nd
F-SecureWorm.WORM/DarkSnow.37953.2
BaiduWin32.Worm.WhiteIce.a
TrendMicroTSPY_WHITEICE_BK22015F.TOMC
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftWin32.WhiteIce.Dam (B)
AviraWORM/DarkSnow.37953.2
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Agent.a
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.ABD2
ArcabitWin32.WhiteIce.Dam
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.WhiteIce.Dam
CynetMalicious (score: 85)
AhnLab-V3Worm/Win32.WhiteIce.R35142
McAfeeArtemis!AC82D7B638E9
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32Win32/Whiteice.B
TrendMicro-HouseCallTSPY_WHITEICE_BK22015F.TOMC
RisingTrojan.PSW.Win32.QQPass.edk (CLASSIC)
YandexTrojan.GenAsa!qXHBe5f1nPw
IkarusVirus.Win32.Whiteice
MaxSecureTrojan.Buzus.enfq
FortinetW32/Tufik.D
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Virus.Win32.BlackIce.C

How to remove Win32.WhiteIce.Dam?

Win32.WhiteIce.Dam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment