Skip to main content
Skip to main content
Published Apr 08, 2010 | Updated Sep 15, 2017

Worm:Win32/Pykspa.E

Detected by Microsoft Defender Antivirus

Aliases: Backdoor.Win32.Zepfod.a (Kaspersky) Win32/AutoRun.Agent.TG (ESET) WORM_VILSEL.SM (Trend Micro)

Summary

Worm:Win32/Pykspa.E is a worm that spreads via Skype messaging, Twitter, mapped drives and network shares. It contains a backdoor that allows it to execute arbitrary commands from a remote attacker. 
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, or the Microsoft Safety Scanner. For more information about using antivirus software, see http://www.microsoft.com/security/antivirus/av.aspx.
Additional remediation instructions for Worm:Win32/Pykspa.E
This threat may make lasting changes to a computer’s configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following article/s: 
Restoring your System Registry:
Resetting System Security Settings to default:
Stopping and starting Windows services:
Enabling System Restore:
Enabling Windows Firewall:
Enabling Windows Security Center/Action Center alerts:
Correctly disabling Autorun in Windows:
Recreating a clean HOSTS file:
Follow us