Malware

Troj/DocDl-AAGZ information

Malware Removal

The Troj/DocDl-AAGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AAGZ virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/DocDl-AAGZ?


File Info:

crc32: AD4321B1
md5: 037b656fb96767e43580bd2766014439
name: upload_file
sha1: 95898fbf36de3ef1dd2232d7f7220de4ab0edddf
sha256: 91c7a707f1f6f1558689a4912069cdbf5262b0f375469d27332cc95c17c1b71f
sha512: 5af33cdf1eefe4e74a62109ba01f5c9537f23f7340b48b213a0fe8f17b0cbe771094eb9a6ae347cef9ee56b75579b3e6373e1767e2a2b1e6f6a136834910cc9a
ssdeep: 3072:S4PrXcuQuvpzm4bkiaMQgAlSuOgiWMYK4+wohjd:TDRv1m4bnQgISuOxWMa+wohjd
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Qui., Author: Eva Pons, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Aug 21 04:00:00 2020, Last Saved Time/Date: Fri Aug 21 04:00:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 20, Security: 0

Version Info:

0: [No Data]

Troj/DocDl-AAGZ also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Malware.Generic-9443669-0
FireEyeVB:Trojan.VBA.Agent.BGM
CAT-QuickHealOLE.Emotet.38803
ALYacTrojan.Downloader.DOC.Gen
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
TrendMicroTrojan.W97M.POWLOAD.THHBDBO
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.THHBDBO
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BGM
NANO-AntivirusTrojan.Script.Downloader.htfcpy
MicroWorld-eScanVB:Trojan.VBA.Agent.BGM
RisingMalware.ObfusVBA@ML.99 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BGM
F-SecureMalware.W97M/Agent.0034911
DrWebExploit.Siggen2.25718
InvinceaTroj/DocDl-AAGZ
SophosTroj/DocDl-AAGZ
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.0034911
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.jvu
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitVB:Trojan.VBA.Agent.BGM
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AUG
AhnLab-V3Downloader/MSOffice.Generic
McAfeeW97M/Downloader.ddv
ZonerProbably Heur.W97Obfuscated
ESET-NOD32GenScript.JVU
TencentHeur.Macro.Generic.h.d52948ef
FortinetVBA/Agent.GC!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1080

How to remove Troj/DocDl-AAGZ?

Troj/DocDl-AAGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment