Malware

Should I remove “Troj/DocDl-ABCO”?

Malware Removal

The Troj/DocDl-ABCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DocDl-ABCO virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Troj/DocDl-ABCO?


File Info:

crc32: 6E97653D
md5: 5f6922cf3fea60aa2fe3b99becd5ad1e
name: upload_file
sha1: a936819e26d7081a825c80b58194ed903de5147a
sha256: 9f944d45d5e7d40e9f1fce8f48c7fae48a14b56666b6c149b9a2f028567d2019
sha512: e9ac5c873e789cc1ac6ca097f7800618f2a4daa0679b1571357f92b486317db75ef8c6f56b14223e7054f033127d1f52866cd5be7e320512d10551572bbe2842
ssdeep: 3072:O6o58xNPSoBcABq1UJivKie6B/w2yiWydwdOQ/rXkyKP1q1:PJiP/w2P7srX5iE1
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

Troj/DocDl-ABCO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB:Trojan.VBA.Agent.BIR
FireEyeVB:Trojan.VBA.Agent.BIR
CAT-QuickHealOLE.Emotet.39664
McAfeeW97M/Downloader.dha
SangforMalware
TrendMicroTrojan.W97M.EMOTET.TIOIBEME
CyrenW97M/Agent.LD.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.EMOTET.TIOIBEME
AvastVBS:Malware-gen
ClamAVDoc.Downloader.Generic-9785156-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BIR
ViRobotDOC.Z.Agent.247587
AegisLabTrojan.MSWord.Macro.4!c
RisingMalware.ObfusVBA@ML.84 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BIR
EmsisoftTrojan-Downloader.Macro.Generic.CH (A)
ComodoTrojWare.Win32.Agent.kcoqx@0
F-SecureMalware.W97M/Agent.4629214
DrWebW97M.DownLoader.4898
InvinceaTroj/DocDl-ABCO
McAfee-GW-EditionW97M/Downloader.dha
SophosTroj/DocDl-ABCO
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.4629214
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ufy
MicrosoftTrojanDownloader:O97M/Emotet.RKC!MTB
GridinsoftTrojan.U.Emotet.lu
ArcabitVB:Trojan.VBA.Agent.BIR
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AVL
CynetMalicious (score: 85)
AhnLab-V3Downloader/MSOffice.Generic
ALYacVB:Trojan.VBA.Agent.BIR
ESET-NOD32VBA/TrojanDownloader.Agent.UFY
TencentHeur.Macro.Generic.h.c2b46b82
FortinetMSOffice/Emotet.FF6D!tr
AVGVBS:Malware-gen
Qihoo-360virus.office.qexvmc.1095

How to remove Troj/DocDl-ABCO?

Troj/DocDl-ABCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment