Trojan

About “VBA/TrojanDownloader.Agent.UEI” infection

Malware Removal

The VBA/TrojanDownloader.Agent.UEI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA/TrojanDownloader.Agent.UEI virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine VBA/TrojanDownloader.Agent.UEI?


File Info:

crc32: C78D4245
md5: baadea03921d91188938d5bd6074c630
name: upload_file
sha1: acdf42cb02a30c24e0ec22cc8596a59c049333ef
sha256: c3ea9db07e0d439866c3789f94c83043f0ace2bc6a6d1ca42d487b83c96ac6a1
sha512: e05e22137d83d857cf56430066f5bf926b10422d3cb346ef49d90379f4f2b6ac90777284d7fddf9d2e111b93564bb496c93e9654e813901ba27f3c11bb9345a9
ssdeep: 6144:Rk3hOdsylKlgryzc4bNhZF+E+W2knp+AqmFkM9lz2KE8hBdLVoo5z9Nn/FDC5GV:85kMHq/8oo5ztOcVLEP9iYtHliEM9fG
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: DELL, Last Saved By: DELL, Create Time/Date: Tue Aug 18 23:00:57 2020, Last Saved Time/Date: Tue Aug 18 23:00:57 2020, Security: 0

Version Info:

0: [No Data]

VBA/TrojanDownloader.Agent.UEI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34386324
FireEyeTrojan.GenericKD.34386324
McAfeeRDN/Generic Downloader.x
SangforMalware
TrendMicroTROJ_FRS.0NA103HK20
SymantecW97M.Downloader
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
AvastSNH:Script [Dropper]
ClamAVXls.Dropper.Agent-9391333-0
KasperskyHEUR:Trojan-Downloader.MSOffice.SLoad.gen
BitDefenderTrojan.GenericKD.34386324
ViRobotXLS.Z.Agent.389120.O
AegisLabTrojan.MSOffice.SLoad.a!c
TencentHeur.Macro.Generic.e.f95136cb
Ad-AwareTrojan.GenericKD.34386324
TACHYONSuspicious/X97M.Downloader.Gen
EmsisoftTrojan.GenericKD.34386324 (B)
ComodoTrojWare.Win32.Unclassified.gen@0
F-SecureMalware.VBA/Dldr.Agent.hcgrh
DrWebExploit.Siggen2.24394
InvinceaTroj/DocDl-AABN
SophosTroj/DocDl-AABN
SentinelOneDFI – Suspicious OLE
AviraVBA/Dldr.Agent.hcgrh
Antiy-AVLTrojan[Downloader]/Script.AGeneric
MicrosoftTrojanDownloader:O97M/Donoff.YJ!MTB
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.SLoad.gen
GDataTrojan.GenericKD.34386324
CynetMalicious (score: 85)
ALYacTrojan.Downloader.XLS.gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UEI
RisingDownloader.Agent/VBA!1.C970 (CLASSIC)
IkarusTrojan-Downloader.Office.Doc
FortinetVBA/Agent.GAK!tr.dldr
AVGSNH:Script [Dropper]
Qihoo-360Generic/Trojan.Dropper.271

How to remove VBA/TrojanDownloader.Agent.UEI?

VBA/TrojanDownloader.Agent.UEI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment