Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 06, 2010 | Updated Sep 15, 2017

Worm:Win32/Pykspa.C

Detected by Microsoft Defender Antivirus

Aliases: Trojan.Win32.Vilsel.piv (Kaspersky) W32/Pykse.A (Norman) BackDoor.Hackdoor.P (AVG) Win32/AutoRun.Agent.TG (ESET) W32/Pykse.worm (McAfee) W32.Pykspa.D (Trend Micro)

Summary

Worm:Win32/Pykspa.C is a worm that spreads via Skype messaging, Twitter, mapped drives and network shares. It contains a backdoor that allows it to execute arbitrary commands from a remote attacker. 
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, or the Microsoft Safety Scanner. For more information about using antivirus software, see http://www.microsoft.com/security/antivirus/av.aspx.
Additional remediation instructions for Worm:Win32/Pykspa.C
This threat may make lasting changes to a computer’s configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following article/s: 
Restoring your System Registry:
Resetting System Security Settings to default:
Stopping and starting Windows services:
Enabling System Restore:
Enabling Windows Firewall:
Enabling Windows Security Center/Action Center alerts:
Correctly disabling Autorun in Windows:
Recreating a clean HOSTS file:
Follow us