Worm

Worm:Win32/Pykspa!pz information

Malware Removal

The Worm:Win32/Pykspa!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Pykspa!pz virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Pykspa!pz?


File Info:

name: FCFEEFE1724180FAEEC6.mlw
path: /opt/CAPEv2/storage/binaries/319d912ef25b998435fccc87b6f2e78aa6dc18d2b8a31222b321d5d123894139
crc32: 5059ACDF
md5: fcfeefe1724180faeec6e6cb8e6ac94a
sha1: 7e66ed79e65f0ac09d7e5cb230228a2c51d44bde
sha256: 319d912ef25b998435fccc87b6f2e78aa6dc18d2b8a31222b321d5d123894139
sha512: a53fb49766c37f71e140ea52f3841170a759fd84460da05594b03b7d1b252e35cc498231ef1a6675df1b9ea75640c9a5848d35cfcb5cc10c3911e367dbadeaa5
ssdeep: 12288:7XgvmzFHi0mo5aH0qMzd58D7FYnPJQPDHvd:7XgvOHi0mGaH0qSdMFG4V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13876B036B780C8B1C4858031769AAE136EF56C301524FA67D7A4DE463EF91E4D72A38F
sha3_384: 518d43de2e547aa93f920af55fb9baee2ab0bfcd4e188c5d3d7511182ecd3c4c21913f94dca336d40bff460f6b80c331
ep_bytes: 6a6068f8b74200e8edf7ffffbf940000
timestamp: 2006-12-09 03:25:50

Version Info:

0: [No Data]

Worm:Win32/Pykspa!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.tnDI
DrWebTrojan.Kypes.2
MicroWorld-eScanTrojan.AgentWDCR.JMO
FireEyeGeneric.mg.fcfeefe1724180fa
CAT-QuickHealWorm.Pykspa.C3
SkyhighBehavesLike.Win32.Pykse.wz
McAfeeW32/Pykse.worm.gen.a
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.AgentWDCR.JMO
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
BitDefenderTrojan.AgentWDCR.JMO
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.9e65f0
BitDefenderThetaGen:NN.ZexaF.36792.@pW@a8Rp1ep
VirITTrojan.Win32.AntiAV.PIN
SymantecW32.Pykspa.D
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.Agent.TG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Autorun-437
KasperskyHEUR:Worm.Win32.Agent.gen
AlibabaMalware:Win32/km_28a2.None
NANO-AntivirusTrojan.Win32.AntiAV.dsnxsg
ViRobotTrojan.Win32.Blocker.Gen.B
RisingWorm.Autorun!1.BC87 (CLASSIC)
SophosW32/Pykse-H
F-SecureTrojan.TR/Agent.327680.A
BaiduWin32.Worm.Autorun.o
ZillyaTrojan.Blocker.Win32.28137
TrendMicroTROJ_AGENT_006376.TOMB
Trapminemalicious.high.ml.score
EmsisoftTrojan.AgentWDCR.JMO (B)
IkarusTrojan.Agent
JiangminTrojan/Vilsel.cgx
WebrootWorm:Win32/Pykspa.C
VaristW32/Pykspa.A.gen!Eldorado
AviraTR/Agent.327680.A
Antiy-AVLTrojan/Win32.AntiAV
MicrosoftWorm:Win32/Pykspa!pz
XcitiumWorm.Win32.Autorun.Agent_TG0@1isiwy
ArcabitTrojan.AgentWDCR.JMO
ZoneAlarmHEUR:Worm.Win32.Agent.gen
GDataWin32.Trojan.BSE.1JWSKP9
GoogleDetected
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
VBA32Worm.Yah
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/SpySkype.E
ZonerTrojan.Win32.24407
TrendMicro-HouseCallTROJ_AGENT_006376.TOMB
TencentWorm.Win32.Yah.za
YandexTrojan.GenAsa!qHVVdB/AORM
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoRun.AGENT.AUA!tr
AVGWin32:Renos-KY [Trj]
AvastWin32:Renos-KY [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Pykspa!pz?

Worm:Win32/Pykspa!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment