Malware

DOC/Agent.FO malicious file

Malware Removal

The DOC/Agent.FO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DOC/Agent.FO virus can do?

  • Performs some HTTP requests
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

biz9holdings.com

How to determine DOC/Agent.FO?


File Info:

crc32: 18E146DD
md5: 0081b9e85b6cf0bb1b44b32a92aa3d22
name: upload_file
sha1: 03dcaade5ca2573ffe8e5361e40e09d301b35762
sha256: c8b5f021926392bf884a0c718133b7066038ce812d21d492195eae29b917dde1
sha512: 4c789e7adc585bf945e33eddb7bdb7fc99a37b2ae641bb70d0de80b99f079ea7e483202e1b835b409982496e149c17434507b3c1a691cb8cefdfb23df897ebe9
ssdeep: 384:wm717v/AgsuTbHeEkY6Dx4F8hQqhKZlU8k7ZWh1:wm7l/ptbHpR6DW4HhKZEd+
type: Microsoft Excel 2007+

Version Info:

0: [No Data]

DOC/Agent.FO also known as:

DrWebW97M.DownLoader.2938
MicroWorld-eScanTrojan.GenericKD.34328554
FireEyeTrojan.GenericKD.34328554
BitDefenderTrojan.GenericKD.34328554
K7GWTrojan ( 0054b0d71 )
K7AntiVirusTrojan ( 0054b0d71 )
CyrenCVE-2017-11882.C.gen!Camelot
SymantecExp.CVE-2017-11882!g2
ESET-NOD32DOC/Agent.FO
TrendMicro-HouseCallTROJ_CVE20171182.SM
AvastWin32:ShellCode [Expl]
GDataTrojan.GenericKD.34328554
KasperskyHEUR:Exploit.MSOffice.Generic
AlibabaTrojanDownloader:VBA/Maldoc.ali1000107
ViRobotEML.S.Agent.15221
AegisLabHacktool.MSOffice.Generic.3!c
Ad-AwareTrojan.GenericKD.34328554
TACHYONSuspicious/XOX.CVE-2017-11882
F-SecureExploit.EXP/CVE-2017-11882.Gen
TrendMicroTROJ_CVE20171182.SM
SophosTroj/DocExp-AB
IkarusExploit.CVE-2017-11882
AviraEXP/CVE-2017-11882.Gen
MicrosoftExploit:O97M/CVE-2017-11882.AT!MTB
ArcabitTrojan.Generic.D20BCFEA
AhnLab-V3OLE/Cve-2017-11882.Gen
ZoneAlarmHEUR:Exploit.MSOffice.Generic
CynetMalicious (score: 85)
McAfeeExploit-CVE2017-11882.yx
MAXmalware (ai score=100)
ZonerProbably Heur.W97NativeOnly
TencentOffice.Exploit.Generic.Dav
YandexTrojan.Ofex.Gen.BPN
SentinelOneDFI – Malicious OPENXML
FortinetMSOffice/CVE_2017_11882.B!exploit
AVGWin32:ShellCode [Expl]
Qihoo-360Generic/Trojan.Exploit.ed7

How to remove DOC/Agent.FO?

DOC/Agent.FO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment