Worm

Worm:Win32/Yacspeel removal instruction

Malware Removal

The Worm:Win32/Yacspeel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Yacspeel virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG1
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Uses suspicious command line tools or Windows utilities

How to determine Worm:Win32/Yacspeel?


File Info:

name: E5C06BD78DF948D15268.mlw
path: /opt/CAPEv2/storage/binaries/050ee6c08f2498edc7cc46b23217d0cd5d054066f58dea1f07df43cb4f330a38
crc32: 0D3682F5
md5: e5c06bd78df948d15268f41a11499667
sha1: 0954620ba64081f1800b3713b3690fffc66becad
sha256: 050ee6c08f2498edc7cc46b23217d0cd5d054066f58dea1f07df43cb4f330a38
sha512: 9c054421355e29f3328885233a9eaed59cd5ca9e29a5fd6d3e8a201401be7a22fd76c747118fc4308403eec4eba0dc89e3c612fa47b6a8d27fe2ceee377f407d
ssdeep: 1536:9qSoyYo5o2NQV9TcmviTvLKUZRm5VVY87uoXO3p:GE2JGLN34jb7uoXOZ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1CFA39D12F6D284F2C1DD853D18555F3B577FB8F01BA18A83A334CEA91D352929A2A347
sha3_384: 5dcd9845b2c231d8ee74962ff81f31131590c41964828009db5f6259d474f0e723821a1c30dc0cb32cb5dd27a30fd8c8
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2007-06-26 08:46:11

Version Info:

0: [No Data]

Worm:Win32/Yacspeel also known as:

LionicTrojan.Win32.Turla.4!c
AVGWin32:Turla-F [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanWorm.Generic.52569
CMCGeneric.Win32.e5c06bd78d!MD
SkyhighW32/Autorun.worm.q
McAfeeW32/Autorun.worm.q
MalwarebytesTurla.Trojan.Stealer.DDS
VIPREWorm.Generic.52569
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/AutoRun.6f29cf7a
K7GWHacktool ( 005284351 )
K7AntiVirusHacktool ( 005284351 )
ArcabitWorm.Generic.DCD59
VirITTrojan.Win32.Agent.BQB
SymantecTrojan.Minit
ESET-NOD32Win32/AutoRun.COB
CynetMalicious (score: 100)
AvastWin32:Turla-F [Trj]
ClamAVWin.Worm.Autorun-374
KasperskyTrojan.Win32.Agent.bve
BitDefenderWorm.Generic.52569
NANO-AntivirusTrojan.Win32.Agent.gdkb
SUPERAntiSpywareWorm.AutoRun/Variant
RisingBackdoor.[Turla]ComRAT!1.C333 (CLASSIC)
EmsisoftWorm.Generic.52569 (B)
F-SecureTrojan.TR/Agent.98304E
DrWebWin32.HLLW.Autoruner1.61072
ZillyaTrojan.Agent.Win32.2649
TrendMicroWORM_AUTORUN.J
FireEyeGeneric.mg.e5c06bd78df948d1
SophosTroj/Agent-ALGH
IkarusVirus.Win32.AutoRun.sd
JiangminTrojan/Agent.egnq
VaristW32/Backdoor.HQJM-0751
AviraTR/Agent.98304E
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
XcitiumWorm.Win32.Autorun.q0@1dw93u
MicrosoftWorm:Win32/Yacspeel
ViRobotTrojan.Win32.Agent.98304.K
ZoneAlarmTrojan.Win32.Agent.bve
GDataWin32.Rootkit.Uroburos.C
GoogleDetected
AhnLab-V3Worm/Win32.AutoRun.C77572
ALYacWorm.Generic.52569
TACHYONTrojan/W32.Agent.98304.S
VBA32BScope.Worm.Autorun
Cylanceunsafe
PandaW32/Autorun.HN.worm
TrendMicro-HouseCallWORM_AUTORUN.J
TencentMalware.Win32.Gencirc.10bc5840
YandexTrojan.GenAsa!OG/m5PpfVZA
MaxSecureTrojan.Malware.15521.susgen
FortinetW32/AutoRun.BDJ!tr
ZonerTrojan.Win32.3352
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.Agent.5b9eb58d

How to remove Worm:Win32/Yacspeel?

Worm:Win32/Yacspeel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment