Malware

About “Troj/Gepys-A” infection

Malware Removal

The Troj/Gepys-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gepys-A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Troj/Gepys-A?


File Info:

name: 72412B875F8EE505F0D6.mlw
path: /opt/CAPEv2/storage/binaries/65c04288fb54fdc314b99e9f755a1f4b5e73f8b00d4b3114be47d1859339c4a5
crc32: 4CEAAFAF
md5: 72412b875f8ee505f0d68839c134e567
sha1: 5eaf669db4c22910055d9e6f5dfa3acc79374fca
sha256: 65c04288fb54fdc314b99e9f755a1f4b5e73f8b00d4b3114be47d1859339c4a5
sha512: b5790ea17c54996d6f34a9d0eac33b58c4172850adae2558fb96c0b0ff861cb4ee1e18ab131c8ce9f454dccaf4b96cd7f284ff148cde45cc44d88a1244da8c16
ssdeep: 3072:ScLXTpcvocFIALdm3vL52HBnXTmy5xEKJ9W8NRh4E5RyuAl1SWZj7cpOI7YtH:5LX1qoEd2v928DHERh4E58lNj7cTYl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D524DF1276D5D942E8144B358843C6FC5691BDA1DF2F8217B6C2FE1FAFB67B05D22A00
sha3_384: 32b9383dbb4dc809b801d304601ae7858f3b23fe40d08a5260cc936cc3f6c3258a1b261f9750c6004fb86ec875977440
ep_bytes: 53515256c884000081ed82000000c745
timestamp: 2013-05-22 11:52:03

Version Info:

0: [No Data]

Troj/Gepys-A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.24
FireEyeGeneric.mg.72412b875f8ee505
CAT-QuickHealTrojan.GepyPMF.S32844610
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4768069
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f4c81 )
K7GWTrojan ( 0040f4c81 )
BitDefenderThetaGen:NN.ZexaF.36804.nuZ@a8B0Exm
VirITTrojan.Win32.Generic.VVS
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GUXR
APEXMalicious
ClamAVWin.Malware.Ulise-6840317-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
NANO-AntivirusTrojan.Win32.MlwGen.cqkyhq
TencentTrojan.Win32.Kryptik.kcb
SophosTroj/Gepys-A
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Mods.146
VIPREGen:Heur.Mint.Zard.24
TrendMicroTROJ_AGENT_057677.TOMB
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Mint.Zard.24 (B)
JiangminTrojan/Generic.awsky
WebrootW32.Trojan.Genkdz
VaristW32/GenTroj.BW.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BBSW@4xttk5
ArcabitTrojan.Mint.Zard.24
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.17GTXUI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R637012
Acronissuspicious
VBA32Virus.Virlock.gen
GoogleDetected
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_AGENT_057677.TOMB
RisingTrojan.Kryptik!1.B5A3 (CLASSIC)
YandexTrojan.GenAsa!S5LTJErtm2o
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.BBSW!tr
PandaTrj/Genetic.gen

How to remove Troj/Gepys-A?

Troj/Gepys-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment