Malware

W97m.Downloader.IZC (file analysis)

Malware Removal

The W97m.Downloader.IZC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97m.Downloader.IZC virus can do?

  • The office file has a unconventional code page: ANSI Cyrillic; Cyrillic (Windows)
  • The office file contains a macro
  • The office file contains a macro with auto execution
  • The office file contains anomalous features

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine W97m.Downloader.IZC?


File Info:

crc32: 346F89C4
md5: e205fcbf439be2ed7271e520f6bbff33
name: upload_file
sha1: 580a88ea299ebcca748aa4b92745aa269261f0f8
sha256: 99b7bcded151782c43a7b44287cd80a8315fb98061e85dc43ee436e14d5aa12c
sha512: 0857121bcd063ddb5328f60b8d0b19044d09a91dbf14ae9d763f8168a1d4e07fa040c1e41c28dcc7ce3957937f5950eb7d610107628784a483a3870428d08334
ssdeep: 1536:fycKoSsxz1PDZLDZjlbR868O8KlVH3edm7uDphYHceXVhca+fMHLtyeGxcl8/dg:fycKoSsxzNDZLDZjlbR868O8KlVH3ed
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Tue Oct 20 10:50:58 2020, Security: 0

Version Info:

0: [No Data]

W97m.Downloader.IZC also known as:

MicroWorld-eScanW97m.Downloader.IZC
CAT-QuickHealTrojan.XLS.Downloader.39295
CyrenXF/Sneaky.BQ.gen!Camelot
KasperskyHEUR:Trojan.Script.Generic
BitDefenderW97m.Downloader.IZC
DrWebExploit.Siggen2.52855
McAfee-GW-EditionRDN/Qakbot
IkarusTrojan-Downloader.Office.Crypt
MicrosoftTrojanDownloader:O97M/EncDoc.QBT!MTB
ZoneAlarmHEUR:Trojan.Script.Generic
GDataMacro.Trojan-Downloader.Agent.AVJ
McAfeeRDN/Qakbot
TACHYONTrojan/XF.Downloader.Gen
ZonerProbably Heur.W97ShellB
ESET-NOD32DOC/TrojanDownloader.Agent.CFF
FortinetMSExcel/Agent.AVJ!tr.dldr
Qihoo-360Generic/Trojan.Script.ed4

How to remove W97m.Downloader.IZC?

W97m.Downloader.IZC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment