Malware

Troj/Gepys-C removal instruction

Malware Removal

The Troj/Gepys-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gepys-C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Troj/Gepys-C?


File Info:

name: DAA880984D93E1D300D2.mlw
path: /opt/CAPEv2/storage/binaries/937888301a62b4addbc7b0b1fa1c994a78f48a3a30715a25ee20ae21a572dee6
crc32: F68B9EE2
md5: daa880984d93e1d300d2e43ee3a371f4
sha1: f6c6b2caa4d6a04636050591fb47c51e55145b6a
sha256: 937888301a62b4addbc7b0b1fa1c994a78f48a3a30715a25ee20ae21a572dee6
sha512: 51b3e35c68ec2a066566990bc5302f3650993a43f722847ce402aa3a815367da2433f30a5f3aeee95d1d0bd3a71a6825173f113869f63089902909ce934a60d2
ssdeep: 6144:8lzoEi+QW3usXbZ8OLamr3RLzGGNi7/jF0M0VatJGPon:8tOeuEbZ83m3IG4TjmM082Qn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11754BECF900C959AD03A5E7044D0EEFCC5BD8677CBAC12DE2BA9DC06E78A342567560D
sha3_384: c06b0f60c6a990cec7eef36182ab379bebf8fb5879472c3a4771811b16552e81e8f5e3fe85c2b0402e349187e291f342
ep_bytes: 558bec83ec508d45b050ff1534d04200
timestamp: 2013-05-03 07:04:19

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Troj/Gepys-C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ShipUp.lISW
Elasticmalicious (high confidence)
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.GenericKDZ.95326
FireEyeGeneric.mg.daa880984d93e1d3
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.dc
McAfeeDropper-FFI!DAA880984D93
Cylanceunsafe
VIPRETrojan.GenericKDZ.95326
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.GenericKDZ.95326
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.ru3@a48Ws3ic
VirITTrojan.Win32.Generic.ABIE
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BAAR
APEXMalicious
ClamAVWin.Malware.Generic-9884182-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Mods.fxvewh
RisingDropper.Gepys!1.AEB3 (CLASSIC)
EmsisoftTrojan.GenericKDZ.95326 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Agent.eq
ZillyaTrojan.ShipUp.Win32.1699
TrendMicroTROJ_AGENT_055399.TOMB
Trapminemalicious.high.ml.score
SophosTroj/Gepys-C
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bpved
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.ShipUp
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Agent.rho@4x457v
ArcabitTrojan.Generic.D1745E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE1.V68JXL
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R64039
Acronissuspicious
VBA32Trojan.ShipUp
ALYacTrojan.GenericKDZ.95326
DeepInstinctMALICIOUS
MalwarebytesGepys.Trojan.Dropper.DDS
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_AGENT_055399.TOMB
TencentTrojan.Win32.Agent.vbd
YandexTrojan.GenAsa!lLUyx8f5sz0
IkarusTrojan-Dropper.Win32.Gepys
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.FG!tr
AVGWin32:Dropper-MRI [Drp]
Cybereasonmalicious.84d93e
AvastWin32:Dropper-MRI [Drp]
alibabacloudTrojan[dropper]:Multi/Gepys

How to remove Troj/Gepys-C?

Troj/Gepys-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment