Malware

Should I remove “Troj/DocDl-AAGO”?

Malware Removal

The Troj/DocDl-AAGO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AAGO virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

How to determine Troj/DocDl-AAGO?


File Info:

crc32: BDDEAD18
md5: 32230c3a9a3ffedcf1f5ad048826ecb4
name: upload_file
sha1: a52fc18f48e0e3e8d794d58af77def2d095129b1
sha256: 398278d9d2531b76db98cff8540e109af72ab623e56e549fe3dc8af259a0385e
sha512: e00014f41d4de890150110a4b6f06ff09772736cc093f8e3c52d0a4400d5ec16d46e5f46aebccc26e123903a9afcc161dabb8b96761fc50c85513b7d730e0b7c
ssdeep: 24576:9ajEa/AsfXeGlbldRpKCn770NQ6JBerz:cbDX/xlzpnIQ
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 20 11:19:16 2020, Security: 0

Version Info:

0: [No Data]

Troj/DocDl-AAGO also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.18684
MicroWorld-eScanTrojan.GenericKD.43699241
FireEyeTrojan.GenericKD.43699241
CAT-QuickHealX97M.Downloader.38800
McAfeeW97M/Downloader.dds
AegisLabTrojan.Script.Generic.4!c
SangforMalware
TrendMicroTROJ_FRS.0NA103HK20
BitDefenderThetaGen:NN.ZedlaF.34216.ty5@aSY3W2ci
CyrenPNG/Trojan.USCY-8
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
AvastOther:Malware-gen [Trj]
ClamAVWin.Dropper.Hideproc-6663113-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.43699241
NANO-AntivirusTrojan.Win32.Redcap.hsqoli
ViRobotDOC.Z.Agent.890780
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
Ad-AwareTrojan.GenericKD.43699241
TACHYONSuspicious/W97.NS.Gen
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
InvinceaTroj/DocDl-AAGO
SophosTroj/DocDl-AAGO
IkarusTrojan.Office.Doc
AviraHEUR/Macro.Downloader.MRUZ.Gen
Antiy-AVLTrojan/Generic.Generic
MicrosoftTrojanDropper:O97M/GraceWire.ARK!MTB
ArcabitTrojan.Generic.D29ACC29
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.43699241
CynetMalicious (score: 85)
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.43699241
MAXmalware (ai score=99)
ZonerProbably Heur.W97Call
ESET-NOD32GenScript.JVI
TencentWin32.Trojan.Generic.Lgjj
SentinelOneDFI – Malicious OLE
FortinetW32/Dropper.GIF!tr
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove Troj/DocDl-AAGO?

Troj/DocDl-AAGO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment