Malware

W97m.Downloader.IYX removal guide

Malware Removal

The W97m.Downloader.IYX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97m.Downloader.IYX virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine W97m.Downloader.IYX?


File Info:

crc32: 3A47925C
md5: b97077f2fd78304297bd7cbb46986abb
name: upload_file
sha1: 039e760607fb738b26a1531ed0bcd02b4758d161
sha256: 20f9809d3a785f2e98379fc5c4bdcabc8a3bb7d3c74ac69f7361b96a347e4613
sha512: daa74e041562753daf7c4d179fff697cca0f03c7f96b43434266aaf2e5287e309fa2c3d23fcc58e27d6ca0eaafb6434983577a899eccdbd31d7e7960d3c0c956
ssdeep: 3072:EBeY5kb0TUNAuBqVPlB11nBkUlV56MARV9A:EEYOb0TUquBqt7nBrANRV9A
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Molestiae., Author: Mattso Richard, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Oct 14 23:36:00 2020, Last Saved Time/Date: Wed Oct 14 23:36:00 2020, Number of Pages: 1, Number of Words: 2078, Number of Characters: 11849, Security: 8

Version Info:

0: [No Data]

W97m.Downloader.IYX also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Malware.Emotet-9777973-1
FireEyeW97m.Downloader.IYY
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 005703b31 )
K7GWTrojan ( 005703b31 )
TrendMicroTROJ_GEN.F04IE00JF20
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.EMOTET.SMBA
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderW97m.Downloader.IYY
ViRobotDOC.Z.Agent.138142
MicroWorld-eScanW97m.Downloader.IYY
RisingMalware.ObfusVBA@ML.97 (VBA)
Ad-AwareW97m.Downloader.IYY
EmsisoftTrojan-Downloader.Macro.Generic.BW (A)
F-SecureMalware.VBA/Dldr.Agent.nfadk
DrWebExploit.Siggen2.49486
InvinceaMal/DocDl-K
McAfee-GW-EditionW97M/Downloader.dgk
SophosMal/DocDl-K
IkarusTrojan-Downloader.VBA.Emotet
AviraVBA/Dldr.Agent.nfadk
MicrosoftTrojanDownloader:O97M/Emotet.SS!MTB
ArcabitW97m.Downloader.IYY
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AVL
AhnLab-V3Downloader/DOC.Emotet.S1304
ALYacW97m.Downloader.IYX
ESET-NOD32VBA/TrojanDownloader.Agent.UFY
TencentHeur.Macro.Generic.h.f8b7252a
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.AVL!tr
Qihoo-360virus.office.qexvmc.1080

How to remove W97m.Downloader.IYX?

W97m.Downloader.IYX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment