Categories: Malware

W97m.Downloader.IYX removal guide

The W97m.Downloader.IYX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97m.Downloader.IYX virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine W97m.Downloader.IYX?


File Info:

crc32: 3A47925Cmd5: b97077f2fd78304297bd7cbb46986abbname: upload_filesha1: 039e760607fb738b26a1531ed0bcd02b4758d161sha256: 20f9809d3a785f2e98379fc5c4bdcabc8a3bb7d3c74ac69f7361b96a347e4613sha512: daa74e041562753daf7c4d179fff697cca0f03c7f96b43434266aaf2e5287e309fa2c3d23fcc58e27d6ca0eaafb6434983577a899eccdbd31d7e7960d3c0c956ssdeep: 3072:EBeY5kb0TUNAuBqVPlB11nBkUlV56MARV9A:EEYOb0TUquBqt7nBrANRV9Atype: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Molestiae., Author: Mattso Richard, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Oct 14 23:36:00 2020, Last Saved Time/Date: Wed Oct 14 23:36:00 2020, Number of Pages: 1, Number of Words: 2078, Number of Characters: 11849, Security: 8

Version Info:

0: [No Data]

W97m.Downloader.IYX also known as:

Elastic malicious (high confidence)
ClamAV Doc.Malware.Emotet-9777973-1
FireEye W97m.Downloader.IYY
AegisLab Trojan.MSWord.Generic.4!c
K7AntiVirus Trojan ( 005703b31 )
K7GW Trojan ( 005703b31 )
TrendMicro TROJ_GEN.F04IE00JF20
Cyren W97M/Downldr.IE.gen!Eldorado
Symantec W97M.Downloader
TrendMicro-HouseCall Trojan.W97M.EMOTET.SMBA
Cynet Malicious (score: 85)
Kaspersky HEUR:Trojan.MSOffice.SAgent.gen
BitDefender W97m.Downloader.IYY
ViRobot DOC.Z.Agent.138142
MicroWorld-eScan W97m.Downloader.IYY
Rising Malware.ObfusVBA@ML.97 (VBA)
Ad-Aware W97m.Downloader.IYY
Emsisoft Trojan-Downloader.Macro.Generic.BW (A)
F-Secure Malware.VBA/Dldr.Agent.nfadk
DrWeb Exploit.Siggen2.49486
Invincea Mal/DocDl-K
McAfee-GW-Edition W97M/Downloader.dgk
Sophos Mal/DocDl-K
Ikarus Trojan-Downloader.VBA.Emotet
Avira VBA/Dldr.Agent.nfadk
Microsoft TrojanDownloader:O97M/Emotet.SS!MTB
Arcabit W97m.Downloader.IYY
ZoneAlarm HEUR:Trojan.MSOffice.SAgent.gen
GData Macro.Trojan-Downloader.Agent.AVL
AhnLab-V3 Downloader/DOC.Emotet.S1304
ALYac W97m.Downloader.IYX
ESET-NOD32 VBA/TrojanDownloader.Agent.UFY
Tencent Heur.Macro.Generic.h.f8b7252a
SentinelOne DFI – Malicious OLE
Fortinet VBA/Agent.AVL!tr
Qihoo-360 virus.office.qexvmc.1080

How to remove W97m.Downloader.IYX?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Worm.VobfusMF.S22387541 (file analysis)

The Worm.VobfusMF.S22387541 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Trojan.GenericRI.S31670896 malicious file

The Trojan.GenericRI.S31670896 is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

Generic.Malware.SF!dld!.D800E25F information

The Generic.Malware.SF!dld!.D800E25F is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Generic.35441245 (file analysis)

The Trojan.Generic.35441245 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dialer.3F709677 removal instruction

The Generic.Dialer.3F709677 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

How to remove “Win32/Klez.H”?

The Win32/Klez.H is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago