VBA/TrojanDownloader.Agent.BVO [Threat Name] go to Threat

VBA/TrojanDownloader.Agent.BVO [Threat Variant Name]

Category trojan
Size 35339 B
Aliases Trojan.VBS.Agent.aef (Kaspersky)
  TrojanDownloader:O97M/Donoff (Microsoft)
  W97M.Downloader (Symantec)
  W97M.DownLoader.1195 (Dr.Web)
Short description

VBA/TrojanDownloader.Agent.BVO is a trojan which tries to download other malware from the Internet.


The trojan does not create any copies of itself.

Other information

The trojan contains a list of (3) URLs.

It tries to download a file from the addresses.

The file is stored in the following location:

  • %temp%\­rufiad%variable%

A string with variable content is used instead of %variable% .

The files contain encrypted executables.

After decryption the data is saved in the following files:

  • %temp%/vuchbots%variable%.dll

The file is then executed.

A string with variable content is used instead of %variable% .

Trojan requires the Microsoft Word to run.

Please enable Javascript to ensure correct displaying of this content and refresh this page.