Trojan

VBA/TrojanDownloader.Agent.UOH removal instruction

Malware Removal

The VBA/TrojanDownloader.Agent.UOH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA/TrojanDownloader.Agent.UOH virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VBA/TrojanDownloader.Agent.UOH?


File Info:

crc32: 66F2D078
md5: 0790a1adfdf722900b54c7ad47863176
name: upload_file
sha1: af15a6af3f18e51e0a120744273fd7d317a5458d
sha256: 35002c596375385dd78d903f1df0ec36f04977b30907f29f3adc5a40617b08bd
sha512: ce8a0ea8c2c2229e97d0de9cd7063cad00b6b69ad019b7583dccdef664db077782f05f249e0a2ea8c7aae02ef064b79a36d3ac626b247acf312c47690cef4061
ssdeep: 6144:Hk3hOdsylKlgryzc4bNhZF+E+W2knSPJVbTc0i+VLvuD+ktw5ljqv2til0dJdpa:t9Q+mSxbtiaPdpCNccnXw
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Dell, Last Saved By: Dell, Create Time/Date: Mon Oct 5 18:24:38 2020, Last Saved Time/Date: Mon Oct 5 18:24:38 2020, Security: 0

Version Info:

0: [No Data]

VBA/TrojanDownloader.Agent.UOH also known as:

Elasticmalicious (high confidence)
DrWebExploit.Siggen2.47703
MicroWorld-eScanTrojan.GenericKD.43989992
FireEyeTrojan.GenericKD.43989992
CAT-QuickHealXMLS.VBAPurging.38956
McAfeeRDN/Generic Downloader.x
CyrenX97M/Agent.HP
SymantecW97M.Downloader
AvastVBA:Downloader-BLX [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderTrojan.GenericKD.43989992
ViRobotXLS.Z.Agent.313344.E
Ad-AwareTrojan.GenericKD.43989992
F-SecureMalware.VBA/Dldr.Agent.rstfv
McAfee-GW-EditionBehavesLike.OLE2.Downloader.fb
EmsisoftTrojan.GenericKD.43989992 (B)
SentinelOneDFI – Suspicious OLE
AviraVBA/Dldr.Agent.rstfv
MicrosoftTrojanDownloader:O97M/Obfuse.YAJ!MTB
ArcabitHEUR.VBA.CG.1
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataTrojan.GenericKD.43989992
CynetMalicious (score: 85)
ALYacTrojan.Downloader.XLS.gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UOH
RisingDownloader.Agent!8.B23 (TOPIS:E0:PHR5SBRy4DJ)
IkarusTrojan-Downloader.VBA.Agent
FortinetVBA/Agent.BLX!tr.dldr
AVGVBA:Downloader-BLX [Trj]
Qihoo-360Generic/Trojan.3b4

How to remove VBA/TrojanDownloader.Agent.UOH?

VBA/TrojanDownloader.Agent.UOH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment