Trojan

VBA/TrojanDownloader.Agent.UJV removal guide

Malware Removal

The VBA/TrojanDownloader.Agent.UJV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA/TrojanDownloader.Agent.UJV virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VBA/TrojanDownloader.Agent.UJV?


File Info:

crc32: 16ED95FA
md5: 31fce8af8b5af9c064cc565577dc9792
name: upload_file
sha1: a1e267f3d9cff7ccab32b6d337765994d6ad6315
sha256: a901784fb0185dc6565a3aac02a3bbec8eec8846e52cbdcf8cc9cf2384f77d33
sha512: e44cd8361ec07a339d6ca466972465782c6ebc63201da002c80ce40bb336d3452667f455a957f8cf76aeb1fe1ff5e5d0bfd65d55cdea95a0268794b4286e4144
ssdeep: 1536:CC+rdi1Ir77zOH98Wj2gpngx+a9aH4oaJrtrYYnalL2VCf3oNHc:GrfrzOH98ipg+HEJrtrDnalL2Vw3mc
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Nostrum., Author: Tom Perez, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Sep 18 23:05:00 2020, Last Saved Time/Date: Fri Sep 18 23:05:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 21, Security: 0

Version Info:

0: [No Data]

VBA/TrojanDownloader.Agent.UJV also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Downloader.Generic-9763712-0
CAT-QuickHealW97M.Emotet.39151
McAfeeW97M/Downloader!31FCE8AF8B5A
K7AntiVirusTrojan ( 0056edf51 )
K7GWTrojan ( 0056edf51 )
ArcabitVB:Trojan.Downloader.JUYA
InvinceaMal/DocDl-K
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDownloader.Agent.UJV
TrendMicro-HouseCallTrojan.W97M.EMOTET.SMBA1
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan-Downloader.Script.Generic
BitDefenderVB:Trojan.Downloader.JUYA
NANO-AntivirusTrojan.Script.Downloader.hvpwfd
MicroWorld-eScanVB:Trojan.Downloader.JUYA
RisingMalware.ObfusVBA@ML.95 (VBA)
Ad-AwareVB:Trojan.Downloader.JUYA
SophosMal/DocDl-K
F-SecureMalware.W97M/Agent.7353511
TrendMicroTrojan.W97M.EMOTET.SMBA1
McAfee-GW-EditionW97M/Downloader!31FCE8AF8B5A
FireEyeVB:Trojan.Downloader.JUYA
EmsisoftTrojan-Downloader.Macro.Generic.BC (A)
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.7353511
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ufy
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataVB:Trojan.Downloader.JUYA
AhnLab-V3Downloader/MSOffice.Generic
ALYacVB:Trojan.Downloader.JUYA
ZonerProbably Heur.W97Obfuscated
TencentHeur.Macro.Generic.h.98cdbfca
FortinetVBA/Agent.DBV!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.obfuscated.1

How to remove VBA/TrojanDownloader.Agent.UJV?

VBA/TrojanDownloader.Agent.UJV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment