Malware

What is “VBA:Downloader-GAK [Trj]”?

Malware Removal

The VBA:Downloader-GAK [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA:Downloader-GAK [Trj] virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VBA:Downloader-GAK [Trj]?


File Info:

crc32: 973CD74A
md5: 78990db79a91149fd7ddcd888fba3f39
name: upload_file
sha1: 6e8f7597e5c980e3851aa31f012616c43958287a
sha256: b840b2a914a1f64a546c1ce7ee92c49c59e7f1e43ac65d13b88d15535b4120a5
sha512: 07e7e866d1d471bad8d4e7be0eb39211f62675d3a573fffb7eb26aa863b856773fb5518731d23ce218b607fb4a8e579ade75171e2ea6e600f0d26843daa7ae02
ssdeep: 48:rSKYUAV6vRxizhw+dnMaWLodF1EbzUiSA0jTywcw4kksc6zXsb8ZXQ99d7q:WBj6Zxi9wonW4XiVWtJksdsAZXwd7
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

VBA:Downloader-GAK [Trj] also known as:

MicroWorld-eScanTrojan.GenericKD.34260841
ALYacTrojan.GenericKD.34260841
AegisLabTrojan.MSWord.Generic.4!c
ArcabitHEUR.VBA.Trojan.d
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDownloader.Agent.TWJ
AvastVBA:Downloader-GAK [Trj]
BitDefenderTrojan.GenericKD.34260841
RisingDownloader.Agent!8.B23 (TOPIS:E0:pjfYZbFoamG)
Ad-AwareTrojan.GenericKD.34260841
F-SecureMalware.VBA/Dldr.Agent.ylbjh
FortinetVBA/Agent.GAK!tr.dldr
FireEyeTrojan.GenericKD.34260841
EmsisoftTrojan.GenericKD.34260841 (B)
IkarusTrojan-Downloader.VBA.Agent
CyrenTrojan.PMBC-7
AviraVBA/Dldr.Agent.ylbjh
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Tiggre!rfn
ViRobotDOC.Z.Agent.5632.MF
CynetMalicious (score: 85)
TACHYONSuspicious/X97M.Downloader.Gen
ZonerProbably Heur.W97Obfuscated
TencentHeur.Macro.Generic.f.22bcf2ed
SentinelOneDFI – Malicious OLE
GDataTrojan.GenericKD.34260841
AVGVBA:Downloader-GAK [Trj]
Qihoo-360Generic/Trojan.Downloader.635

How to remove VBA:Downloader-GAK [Trj]?

VBA:Downloader-GAK [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment