Malware

Troj/DocDl-AAZL removal

Malware Removal

The Troj/DocDl-AAZL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-AAZL virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine Troj/DocDl-AAZL?


File Info:

crc32: 0BB824D0
md5: b51e3c4895a53eed7b974c5bf9917190
name: upload_file
sha1: bd1210ab8ad851ad78de72289efaaa8a7bf257da
sha256: 824db89a974de2fdd2bab3b28897ebe67bc4efc7cd2dea9245ac4317c35cb909
sha512: cac050264e1121fc7c00a80b7e3c71411f828290b9734e6d4ed2fcf168fe1fb896d532ab8c3ecefe426083fbd7a98df17e64eb54fef081567e1e80629e50f8bd
ssdeep: 6144:7k3hOdsylKlgryzc4bNhZF+E+W2kn1p6qI/ONSyjJ+kir4mpysnjbgIWmXFyCDK:upPI2NP+kkPysjbg1mXFzDd6/C9UJjs
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Dell, Last Saved By: Dell, Create Time/Date: Thu Oct 22 23:03:18 2020, Last Saved Time/Date: Thu Oct 22 23:03:18 2020, Security: 0

Version Info:

0: [No Data]

Troj/DocDl-AAZL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44159894
FireEyeTrojan.GenericKD.44159894
CAT-QuickHealXMLS.VBAPurging.38956
McAfeeDownloader-FCBY!B51E3C4895A5
CyrenDownldr.HO
SymantecW97M.Downloader
AvastSNH:Script [Dropper]
KasperskyHEUR:Trojan-Downloader.Script.Generic
BitDefenderTrojan.GenericKD.44159894
ViRobotXLS.Z.Agent.386560.F
Ad-AwareTrojan.GenericKD.44159894
ComodoMalware@#2kukskgcjeup8
DrWebExploit.Siggen2.54764
InvinceaTroj/DocDl-AAZL
McAfee-GW-EditionBehavesLike.OLE2.Downloader.fb
SophosTroj/DocDl-AAZL
AviraVBA/Dldr.Agent.wokje
AegisLabTrojan.Script.Generic.a!c
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataTrojan.GenericKD.44159894
ALYacTrojan.GenericKD.44159894
MAXmalware (ai score=99)
ZonerProbably Heur.W97ShellB
ESET-NOD32VBA/TrojanDownloader.Agent.UQV
RisingMalware.ObfusVBA@ML.87 (VBA)
TACHYONTrojan/XF.PS.Gen
FortinetVBA/Agent.BLX!tr.dldr
AVGSNH:Script [Dropper]
Qihoo-360Generic/Trojan.Downloader.251

How to remove Troj/DocDl-AAZL?

Troj/DocDl-AAZL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment