Worm

Worm.Pykspa (file analysis)

Malware Removal

The Worm.Pykspa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Pykspa virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Worm.Pykspa?


File Info:

name: CA8B6339017000F3FEDC.mlw
path: /opt/CAPEv2/storage/binaries/56c715174c7db6e8a77dfad751415d49ae076f6cda4c40e3c8d4082fff8b0373
crc32: 4D741D19
md5: ca8b6339017000f3fedcf042c1626fa4
sha1: 5d77419e822a0ee7326960671d0487c23d89188a
sha256: 56c715174c7db6e8a77dfad751415d49ae076f6cda4c40e3c8d4082fff8b0373
sha512: 3e78e3b77569dec6b16480afa7e43fb4ccab6f7b69cbb5dada6661b95d85bf66f94cff84bbf9c29767e5f0f7a6b66dd4460330cdf72659d7c669d847e2688b99
ssdeep: 6144:LR8XcGxUEcNmnQ8/RtnmGcY39OANv4hituxp38u0:v8cmnXJhmFY39OANv4h8u/8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3E4BF3677C0C0F1C0A280326199AF369DF6687313219567EF649A092EB96F5D73B34B
sha3_384: 7b22b708b8374b5cd218e7e1d0d4eb2c6fa4a6829af8d31fd7890b70badf0481c21fa00ee0d881bbfd5e61e1088e19ec
ep_bytes: 6a606898974200e896f7ffffbf940000
timestamp: 2006-12-09 03:47:10

Version Info:

0: [No Data]

Worm.Pykspa also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Kypes.18
MicroWorld-eScanGen:Variant.Pykspa.1
CAT-QuickHealWorm.Pykspa.C3
McAfeeW32/Pykse.worm.gen.a
CylanceUnsafe
ZillyaTrojan.Vilsel.Win32.18512
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.901700
BitDefenderThetaGen:NN.ZexaF.34294.RmW@a85mTHi
CyrenW32/Pykspa.A.gen!Eldorado
SymantecW32.Pykspa.D
ESET-NOD32a variant of Win32/AutoRun.Agent.TG
TrendMicro-HouseCallWORM_VILSEL.SMC
ClamAVWin.Worm.Pykspa-9869413-0
KasperskyTrojan.Win32.Chydo.aaae
BitDefenderGen:Variant.Pykspa.1
NANO-AntivirusTrojan.Win32.Vilsel.egtti
AvastWin32:Renos-KY [Trj]
RisingWorm.Pykspa!1.A60D (CLASSIC)
Ad-AwareGen:Variant.Pykspa.1
SophosML/PE-A + W32/Pykse-F
ComodoTrojWare.Win32.Vilsel.Y@1v571n
BaiduWin32.Worm.Autorun.o
VIPREWorm.Win32.Skyper.b (v)
TrendMicroWORM_VILSEL.SMC
McAfee-GW-EditionBehavesLike.Win32.Pykse.jt
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.ca8b6339017000f3
EmsisoftGen:Variant.Pykspa.1 (B)
IkarusWorm.Win32.Pykspa
JiangminTrojan/Vilsel.riv
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.760B5
MicrosoftWorm:Win32/Pykspa.C
GDataWin32.Trojan.PSE.VU74Y7
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vilsel.C19337
Acronissuspicious
VBA32Trojan.Chydo
ALYacGen:Variant.Pykspa.1
TACHYONTrojan/W32.Chydo.704512.B
MalwarebytesWorm.Pykspa
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!oyWE4y6VTTI
MAXmalware (ai score=83)
eGambitUnsafe.AI_Score_100%
FortinetW32/Pykse.F!tr
AVGWin32:Renos-KY [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Worm.Pykspa?

Worm.Pykspa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment