Malware

Should I remove “Troj/DocDl-AAWA”?

Malware Removal

The Troj/DocDl-AAWA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AAWA virus can do?

  • The office file contains 4 macros
  • The office file contains a macro with auto execution
  • The office file contains a macro with suspicious strings

How to determine Troj/DocDl-AAWA?


File Info:

crc32: 652C90D3
md5: cd8cbbe5bfb269a059d83fd028b0f647
name: upload_file
sha1: f1048b1d2e78379e2cdf6f9ce6e9d42954858519
sha256: d90cac341ea9f377a9a20b2cc2f098956a2b09c1a423a82de9af0fa91f6d777c
sha512: 178d778c190bf031de7df4a114ab4f24f4c50226aa4d4cfc4703f02049dec5820a7bffd6f262768c2b1fcb21d9ac61a95a391428c34805eaff16e2cc2cb0fa21
ssdeep: 3072:cm6DaWYbHEgTic2R9D+kQlKDpT6BLagNZNJ:ZVWYbHX2YlK4RaCNJ
type: Microsoft Word 2007+

Version Info:

0: [No Data]

Troj/DocDl-AAWA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34764088
ALYacTrojan.Downloader.DOC.Gen
BitDefenderTrojan.GenericKD.34764088
InvinceaTroj/DocDl-AAWA
CyrenPP97M/Downldr.OK!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.THJADBO
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
AlibabaTrojanDownloader:VBA/Obfuscation.A
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
RisingMalware.ObfusVBA@ML.84 (VBA)
Ad-AwareTrojan.GenericKD.34764088
EmsisoftTrojan.GenericKD.34764088 (B)
McAfee-GW-EditionBehavesLike.Downloader.nc
FireEyeTrojan.GenericKD.34764088
SophosTroj/DocDl-AAWA
GDataTrojan.GenericKD.34764088
MicrosoftTrojanDownloader:O97M/IcedID.YI!MTB
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
ZonerProbably Heur.W97Obfuscated
TencentHeur.Macro.Generic.e.1eb91395
SentinelOneDFI – Malicious OPENXML
FortinetVBA/Agent.UQJ!tr
Qihoo-360virus.office.obfuscated.1

How to remove Troj/DocDl-AAWA?

Troj/DocDl-AAWA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment