Trojan

About “VBA/TrojanDownloader.Agent.UOW” infection

Malware Removal

The VBA/TrojanDownloader.Agent.UOW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA/TrojanDownloader.Agent.UOW virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VBA/TrojanDownloader.Agent.UOW?


File Info:

crc32: F5EAAAED
md5: 90b96f55ad5ad57ae1dd60ca025df039
name: upload_file
sha1: cf29e94c27dfa7a339b588564ec1bb336c21017d
sha256: 47146f8d8b46a395adabd4c961732aa28c28b08776d1a0e91a71b66da0eb767b
sha512: 4f3537fecf86b8fbd35831f4983fdcbdd1855519004e8f5683a08bd0c8bb12a79eeba0f46f91b12c47b5184ab78089f31d7dd261297a544ec4c5acd4f551c5c7
ssdeep: 12288:U2+NJ9iY+2yy/RJVSjlWRKTZ01lQhO8M0KiT:U2+NJ9iYgqjABgeZiQ7pKiT
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Dell, Last Saved By: Dell, Create Time/Date: Tue Oct 6 10:16:54 2020, Last Saved Time/Date: Tue Oct 6 10:16:54 2020, Security: 0

Version Info:

0: [No Data]

VBA/TrojanDownloader.Agent.UOW also known as:

Elasticmalicious (high confidence)
CAT-QuickHealXMLS.VBAPurging.38956
SymantecTrojan.Gen.2
AvastVBA:Downloader-BLX [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
F-SecureMalware.W97M/Hancitor.hrhtj
DrWebExploit.Siggen2.47662
McAfee-GW-EditionBehavesLike.OLE2.Downloader.gb
SentinelOneDFI – Suspicious OLE
GDataGeneric.Trojan.Agent.730GDR
AviraW97M/Hancitor.hrhtj
ArcabitHEUR.VBA.CG.1
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Obfuse.YAJ!MTB
CynetMalicious (score: 85)
McAfeeRDN/Generic Downloader.x
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UOW
RisingDownloader.Agent!8.B23 (TOPIS:E0:PHR5SBRy4DJ)
IkarusWin32.SuspectCrc
FortinetVBA/Agent.BLX!tr.dldr
AVGVBA:Downloader-BLX [Trj]
Qihoo-360Generic/Trojan.3b4

How to remove VBA/TrojanDownloader.Agent.UOW?

VBA/TrojanDownloader.Agent.UOW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment