Malware

How to remove “Troj/DocDl-AAFZ”?

Malware Removal

The Troj/DocDl-AAFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AAFZ virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with suspicious strings

How to determine Troj/DocDl-AAFZ?


File Info:

crc32: 6A5C68E0
md5: f084e15f23e8f78a4ae11d464f028c54
name: upload_file
sha1: 9acf71f411eb3ac795eaaa985badf22a71820697
sha256: af9b5f37adfc70ae0980f08e035e06e7f9eaa9a4bcfba4e49c59039e3a76d66f
sha512: 667db77c0da560b32948931a62046e473b3bc397580a52e44638746abc98fbd9be00073f4304107b312171d4e141bfbef6e1813140b63d70fb2cba3e328eb171
ssdeep: 3072:3j6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkZWl6/3+4yWwsuZ:3HgtEWPsL/aTyT9GkZWl6f/wsuZ
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Ab., Author: Camille Olivier, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Aug 17 06:01:00 2020, Last Saved Time/Date: Mon Aug 17 06:01:00 2020, Number of Pages: 2, Number of Words: 4, Number of Characters: 26, Security: 0

Version Info:

0: [No Data]

Troj/DocDl-AAFZ also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Downloader.Emotet-9369689-0
FireEyeVB:Trojan.Agent.EVBJ
CAT-QuickHealOLE.Emotet.38831
McAfeeW97M/Downloader.ddv
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMK
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.Agent.EVBJ
ViRobotDOC.Z.Agent.239810
MicroWorld-eScanVB:Trojan.Agent.EVBJ
RisingTrojan.Downloader!1.CAAF (CLASSIC)
Ad-AwareVB:Trojan.Agent.EVBJ
F-SecureMalware.W97M/Agent.6712213
DrWebExploit.Siggen2.21424
VIPRETrojan-Downloader.W97M.Agent.jc (v)
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMK
SophosTroj/DocDl-AAFZ
AviraW97M/Agent.6712213
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ubv
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
AegisLabTrojan.MSWord.Generic.4!c
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AUI
AhnLab-V3Downloader/MSOffice.Generic
ALYacTrojan.Downloader.DOC.Gen
MAXmalware (ai score=81)
VBA32TrojanDownloader.O97M.Emotet
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UBV
TencentHeur.Macro.Generic.f.48a137c9
IkarusTrojan-Downloader.VBA.Emotet
FortinetVBA/Agent.GC!tr.dldr
AVGScript:SNH-gen [Trj]
PandaW97M/Downloader.DDE
Qihoo-360virus.office.qexvmc.1075

How to remove Troj/DocDl-AAFZ?

Troj/DocDl-AAFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment