Malware

About “W32/Pykse-H” infection

Malware Removal

The W32/Pykse-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Pykse-H virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine W32/Pykse-H?


File Info:

name: 943732C2B4B288FE1D48.mlw
path: /opt/CAPEv2/storage/binaries/de6d3ee424667e1fb693f38b86e7c90f513251057164c5bb8eec05f7eb9795f0
crc32: 3440FFBB
md5: 943732c2b4b288fe1d48fbe2f571f9f9
sha1: c85199e293d75dfedbf05666bc22c3b1e88f1b25
sha256: de6d3ee424667e1fb693f38b86e7c90f513251057164c5bb8eec05f7eb9795f0
sha512: 9a158ba042986ac8818c323fc2758e69fee16a999d3fc83c10290efabd10caa356204dacdcd39ad8d310834bfeffb00ab1a7c7e7e24a4619a79642f8e679ccc1
ssdeep: 12288:zXgvmzFHi0mo5aH0qMzd58E7FkqGPJQPDHvd:zXgvOHi0mGaH0qSdzFrY4V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C486B03AB6C1C8F1C444813273966F13BEF56C701124EA5BDB60DE093EB66D5D62A38B
sha3_384: b197a26de62e8f751b5b49b52fbce0d7b71c544b6b4eeed346ec0cff6b2eedc976c1d3d627b75df1009fbb097b0a4a39
ep_bytes: 6a6068f8b74200e8edf7ffffbf940000
timestamp: 2006-12-09 07:27:51

Version Info:

0: [No Data]

W32/Pykse-H also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.AgentWDCR.JMO
CAT-QuickHealWorm.Pykspa.C3
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Autorun.o
VirITTrojan.Win32.AntiAV.PIN
CyrenW32/Pykspa.A.gen!Eldorado
SymantecW32.Pykspa.D
ESET-NOD32Win32/AutoRun.Agent.TG
TrendMicro-HouseCallTROJ_AGENT_006376.TOMB
CynetMalicious (score: 100)
AlibabaMalware:Win32/km_28a2.None
TACHYONRansom/W32.Blocker.8028160.E
F-SecureTrojan.TR/Agent.327680.A
DrWebTrojan.Kypes.2
VIPRETrojan.AgentWDCR.JMO
TrendMicroTROJ_AGENT_006376.TOMB
McAfee-GW-EditionBehavesLike.Win32.Pykse.wz
Trapminesuspicious.low.ml.score
SophosW32/Pykse-H
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vilsel.cgx
AviraTR/Agent.327680.A
Antiy-AVLTrojan/Win32.AntiAV
ArcabitTrojan.AgentWDCR.JMO
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmHEUR:Worm.Win32.Agent.gen
GoogleDetected
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
PandaW32/SpySkype.E
ZonerTrojan.Win32.24407
TencentWorm.Win32.Yah.za
YandexTrojan.GenAsa!qHVVdB/AORM
IkarusTrojan.Agent
FortinetW32/AutoRun.AGENT.AUA!tr
AVGWin32:Renos-KY [Trj]
Cybereasonmalicious.2b4b28
AvastWin32:Renos-KY [Trj]

How to remove W32/Pykse-H?

W32/Pykse-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment