Trojan

TrojanDropper:Win32/Pykspa!pz removal instruction

Malware Removal

The TrojanDropper:Win32/Pykspa!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Pykspa!pz virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Pykspa!pz?


File Info:

name: 5399091B8EF6A6F9B09C.mlw
path: /opt/CAPEv2/storage/binaries/6f24a84d2036c31db3d318b6c1fe1d153763217f3f558f78fd2fc3b5e2f4cf92
crc32: 213A05C4
md5: 5399091b8ef6a6f9b09c70954f5d2114
sha1: 9a826ce0c069b04e5595a5ffb161f3ddc386405b
sha256: 6f24a84d2036c31db3d318b6c1fe1d153763217f3f558f78fd2fc3b5e2f4cf92
sha512: cca0018d24c9dad974ef72e3146ce28359c29481fb82a7c0b7474f51430ecb997c18e32da107b5cf4b404bb17a0836fac268473fc34dc8bea8a2016ca46be4c9
ssdeep: 6144:I1Qv8rK3FQp4LGCr9a9n4FRm6RGMXKq6QFHgTr4186JQPDHDdx/Qtqa:1OkiCpat4FU6JXKqtZgcPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112E5C02AB781C8F2C441803172D5AE236DF56C700656A76BEB508F452FF59E9E32A34F
sha3_384: 1850416cba1d3888ca30f874a19340b816df95550bed65013ce0ee8b701393f07a596c8c6265722ab09b87e2f9303524
ep_bytes: 6a6068f8b74200e8edf7ffffbf940000
timestamp: 2006-12-09 07:17:27

Version Info:

0: [No Data]

TrojanDropper:Win32/Pykspa!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EFYN
FireEyeGeneric.mg.5399091b8ef6a6f9
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.wz
ALYacTrojan.Agent.EFYN
Cylanceunsafe
VIPRETrojan.Agent.EFYN
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.0c069b
BaiduWin32.Worm.Autorun.o
VirITTrojan.Win32.Generic.LA
SymantecW32.Pykspa.D
ESET-NOD32Win32/AutoRun.Agent.TG
APEXMalicious
ClamAVWin.Worm.Pykspa-9869413-0
KasperskyHEUR:Worm.Win32.Agent.gen
BitDefenderTrojan.Agent.EFYN
NANO-AntivirusTrojan.Win32.TrjGen.dxqwva
SUPERAntiSpywareWorm.SkypeBot
AvastWin32:Renos-KY [Trj]
TencentTrojan-Ransom.Win32.Blocker.kk
TACHYONRansom/W32.Blocker.3268608.L
EmsisoftTrojan.Agent.EFYN (B)
F-SecureTrojan.TR/Agent.327680.A
DrWebTrojan.Siggen.36621
ZillyaTrojan.Blocker.Win32.40256
TrendMicroWORM_PYKSPA_EK050341.UVPM
Trapminemalicious.high.ml.score
SophosW32/Pykse-F
IkarusTrojan.Win32.AntiAV
GDataWin32.Trojan.PSE.10K2FIK
JiangminTrojan/Blocker.lia
WebrootWorm:Win32/Pykspa.C
GoogleDetected
AviraTR/Agent.327680.A
VaristW32/Pykspa.A.gen!Eldorado
Antiy-AVLTrojan/Win32.AntiAV
XcitiumWorm.Win32.Autorun.Agent_TG0@1isiwy
ArcabitTrojan.Agent.EFYN
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmHEUR:Worm.Win32.Agent.gen
MicrosoftTrojanDropper:Win32/Pykspa!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
McAfeeW32/Pykse.worm.gen.a
MAXmalware (ai score=83)
VBA32TrojanRansom.Blocker
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.24407
TrendMicro-HouseCallWORM_PYKSPA_EK050341.UVPM
RisingWorm.Autorun!1.BC87 (CLASSIC)
YandexTrojan.GenAsa!R41E4MI3PTc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.AGENT.AUA!tr
BitDefenderThetaGen:NN.ZexaF.36792.hpW@aeq6uAj
AVGWin32:Renos-KY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Pykspa!pz?

TrojanDropper:Win32/Pykspa!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment