Malware

How to remove “Troj/DocDl-AARW”?

Malware Removal

The Troj/DocDl-AARW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AARW virus can do?

  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Troj/DocDl-AARW?


File Info:

crc32: 1F37D520
md5: d9feb9b4f57a9dbb4b96e86cffb0763e
name: upload_file
sha1: a8adb478b66189d70ed7d1f0b434d8fc299f5e5b
sha256: 9c0ee5ec6927fc3d66e98e5fb2f0094f98853e71849bb51140dfc573c16864f8
sha512: a3fdf781db9376483365c00c8128035e22d75e929af683485079a87db142bddfe817f63adf8b76cc7ff4d7338320dbd527ed3a89a49070f818bed9630815a301
ssdeep: 1536:pARD3bNqfNpu39IId5a6XP3Mg8afmqIdotKdz/Rek6Ef3Ei9WEvOE:OR1qf69xak3MgxmKKl/R89i9WAOE
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Et., Author: Rayan Menard, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Sep 24 21:34:00 2020, Last Saved Time/Date: Thu Sep 24 21:34:00 2020, Number of Pages: 1, Number of Words: 3132, Number of Characters: 17856, Security: 8

Version Info:

0: [No Data]

Troj/DocDl-AARW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB:Trojan.VBA.Agent.BHU
FireEyeVB:Trojan.VBA.Agent.BHU
McAfeeW97M/Downloader.dbv
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 0056edf51 )
K7GWTrojan ( 0056edf51 )
TrendMicroTrojan.W97M.EMOTET.TIOIBELH
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.EMOTET.TIOIBELH
AvastOther:Malware-gen [Trj]
ClamAVDoc.Downloader.Emotet-9765780-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BHU
ViRobotDOC.Z.Agent.171598
RisingMalware.ObfusVBA@ML.97 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BHU
EmsisoftTrojan-Downloader.Macro.Generic.BI (A)
ComodoMalware@#28z9c30tgfjp1
F-SecureMalware.VBA/Dldr.Agent.mfxon
DrWebExploit.Siggen2.43594
InvinceaTroj/DocDl-AARW
McAfee-GW-EditionW97M/Downloader.dbv
SophosTroj/DocDl-AARW
IkarusTrojan.VBA.Agent
AviraVBA/Dldr.Agent.mfxon
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ufy
MicrosoftTrojanDownloader:O97M/Emotet.PEE!MTB
ArcabitVB:Trojan.VBA.Agent.BHU
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataGeneric.Trojan.Agent.VNAA8V
AhnLab-V3Downloader/DOC.Emotet.S1294
ALYacTrojan.Downloader.DOC.Gen
ESET-NOD32VBA/TrojanDownloader.Agent.UFY
TencentHeur.Macro.Generic.h.276c9b5b
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.UFY!tr
AVGOther:Malware-gen [Trj]
Qihoo-360virus.office.qexvmc.1090

How to remove Troj/DocDl-AARW?

Troj/DocDl-AARW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment