Trojan

DOC/TrojanDropper.Agent.SV removal instruction

Malware Removal

The DOC/TrojanDropper.Agent.SV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DOC/TrojanDropper.Agent.SV virus can do?

  • Executable code extraction
  • Detected script timer window indicative of sleep style evasion
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine DOC/TrojanDropper.Agent.SV?


File Info:

crc32: FB64FD04
md5: c1ba2bce350a9720ffbb40ed215b3857
name: upload_file
sha1: bb0ed6438e52b742008fc8e5070edbe19d4219cf
sha256: 06aa198c6c7505c0cbd97c98fc5a7bc7760caad0db34513a7d497b41ccc1674a
sha512: 9bbe694cf04b2cde045363fc0da5674ef6f74071ae0000a98b3d71ca9fe33aa42c14486673dbe8b2a2f3955c7ae857743a3f7ce6eb93ee7f772a2a8ff86ba855
ssdeep: 3072:Zx++++++++8OOO8q8OOOOONOOOOOOUOOOOOOOOOOOOG0q8/U3VLOOOO8OOOOOOVp:Z0
type: Rich Text Format data, version 1, unknown character set

Version Info:

0: [No Data]

DOC/TrojanDropper.Agent.SV also known as:

MicroWorld-eScanTrojan.GenericKD.35059099
FireEyeTrojan.GenericKD.35059099
CAT-QuickHealExp.RTF.Obfus.Gen
McAfeeRTFObfustream.c!C1BA2BCE350A
TrendMicroTrojan.W97M.CVE201711882.YQUOOWD
CyrenRTF/CVE-2017-11882.P.gen!Camelot
SymantecTrojan.Gen.NPE
TrendMicro-HouseCallTrojan.W97M.CVE201711882.YQUOOWD
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Trojan.VBS.SAgent.gen
BitDefenderTrojan.GenericKD.35059099
NANO-AntivirusExploit.Rtf.Heuristic-rtf.dinbqn
RisingDownloader.Agent!8.B23 (TOPIS:E0:7ZyWgqQnmlK)
Ad-AwareTrojan.GenericKD.35059099
EmsisoftTrojan.GenericKD.35059099 (B)
F-SecureMalware.VBS/Agent.zwtqo
DrWebExploit.Rtf.Obfuscated.16
McAfee-GW-EditionRTFObfustream.c!C1BA2BCE350A
IkarusExploit.CVE-2017-11882
AviraVBS/Agent.zwtqo
Antiy-AVLTrojan[Exploit]/RTF.Obscure.Gen
MicrosoftExploit:O97M/CVE-2017-11882!MTB
GridinsoftTrojan.U.Downloader.oa
ArcabitTrojan.Generic.D216F59B
ZoneAlarmHEUR:Exploit.RTF.CVE-2018-0802.gen
GDataTrojan.GenericKD.35059099
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.35059099
TACHYONSuspicious/RTF.Obfus.Gen
ZonerProbably Heur.RTFObfuscationE
ESET-NOD32DOC/TrojanDropper.Agent.SV
TencentWin32.Exploit.Cve-2018-0802.Sxxy
MAXmalware (ai score=87)
FortinetVBS/Agent.C1B9!tr
AVGOther:Malware-gen [Trj]
Qihoo-360susp.rtf.objupdate.gen

How to remove DOC/TrojanDropper.Agent.SV?

DOC/TrojanDropper.Agent.SV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment