Malware

Troj/DocDl-ABAW removal tips

Malware Removal

The Troj/DocDl-ABAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-ABAW virus can do?

  • The office file contains 4 macros
  • The office file contains a macro with auto execution
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with suspicious strings

How to determine Troj/DocDl-ABAW?


File Info:

crc32: 1109EEC1
md5: d426e47418b79acd0a54b48086aa6527
name: upload_file
sha1: 945b2c8c3c186f5c282e2c0d0e768a0e9eecbb34
sha256: 8faeb2b3a5ee7d05dfd15b9ac3a3798ef95667dc201033141891ff58a037f1b1
sha512: 6928cc5bd281d92c5222c5d0023481da9800a4f12328302e71f4b3afe8bb309b6c8951107d54af79751077d38a1f69485e1b8a682df307df53c39aeccb32d277
ssdeep: 3072:Y4s6wRJVr/x93RyG56wr+3IYWEFUEKsfGNw4CZO0mjBCiN3G:Y4srJVld6wr+3IYWqhv4CZDmjsEG
type: Microsoft Word 2007+

Version Info:

0: [No Data]

Troj/DocDl-ABAW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34975463
McAfeeW97M/Downloader.ddb
AlibabaTrojanDownloader:VBA/Obfuscation.A
TrendMicroHEUR_VBA.O2
CyrenPP97M/Downldr.OK!Eldorado
SymantecTrojan.Gen.NPE
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderTrojan.GenericKD.34975463
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
TencentHeur.Macro.Generic.f.8823a8cb
Ad-AwareTrojan.GenericKD.34975463
SophosTroj/DocDl-ABAW
F-SecureHeuristic.HEUR/Macro.Downloader.MRDY.Gen
InvinceaTroj/DocDl-ABAW
McAfee-GW-EditionBehavesLike.Downloader.cc
FireEyeTrojan.GenericKD.34975463
EmsisoftTrojan.GenericKD.34975463 (B)
SentinelOneDFI – Malicious OPENXML
GDataTrojan.GenericKD.34975463
AviraHEUR/Macro.Downloader.MRDY.Gen
MicrosoftTrojanDownloader:O97M/IcedID.YJ!MTB
ArcabitHEUR.VBA.CG.1
AegisLabTrojan.MSWord.Generic.4!c
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
CynetMalicious (score: 85)
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UTN
RisingMalware.ObfusVBA@ML.92 (VBA)
IkarusTrojan-Downloader.VBA.Agent
FortinetVBA/Agent.UTN!tr
AVGOther:Malware-gen [Trj]
Qihoo-360virus.office.obfuscated.1

How to remove Troj/DocDl-ABAW?

Troj/DocDl-ABAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment