Malware

Troj/Gyepis-A removal tips

Malware Removal

The Troj/Gyepis-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gyepis-A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Gyepis-A?


File Info:

name: 134459F3AB5896DB115D.mlw
path: /opt/CAPEv2/storage/binaries/a720d74e1df9eaddca85f6d86b71a276483ae3f57f632164a6d7611ea9107a97
crc32: 581823DF
md5: 134459f3ab5896db115dc1b40f09ccd2
sha1: d2a815b227e60c3356ec744a63a2db210c8f2f40
sha256: a720d74e1df9eaddca85f6d86b71a276483ae3f57f632164a6d7611ea9107a97
sha512: 25b2c339e37627bb168e1518873e890474c1a72b16b0f3c429a6a2b87d8c5a44bf09d8f7cda9280e7d5ed22f2351dee96f4c4b74c868b6c191ce5210e004db67
ssdeep: 6144:6UGsMQN0ZtXfXNcOW46+aph0vJgH6NfNHfLmHb:6UGugdfXn6++myO14
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128249CE6A5778C8BD91D353CF52C0277546B0CE0ADE9AF5762BED8126A43CD20D9C843
sha3_384: db41ba78a8ed2a98f5b061d78686a1025200666292f5840bb2f3c148210e08ae975a174b5d6979333b7ed1756bbd8bf8
ep_bytes: 558bec51ff1588224300689c0100006a
timestamp: 2013-04-15 17:39:45

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Troj/Gyepis-A also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94707
ClamAVWin.Malware.Lethic-6840643-0
FireEyeGeneric.mg.134459f3ab5896db
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacTrojan.GenericKDZ.94707
Cylanceunsafe
ZillyaTrojan.ShipUp.Win32.1338
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
AlibabaTrojan:Win32/Kryptik.08ca13a0
K7GWTrojan ( 004cf6b81 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Agent.eq
VirITTrojan.Win32.Agent4.AMQI
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYUW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.94707
NANO-AntivirusTrojan.Win32.ShipUp.bxnopp
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Gepys-A [Trj]
TencentMalware.Win32.Gencirc.10b2f8c0
SophosTroj/Gyepis-A
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.RedirectENT.140
VIPRETrojan.GenericKDZ.94707
TrendMicroTROJ_SPNR.35FH13
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94707 (B)
IkarusTrojan-Dropper.Win32.Gepys
GDataWin32.Trojan.PSE.1XFBPX6
JiangminTrojan/Generic.avutd
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Generic.D171F3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zbot.SIBL!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R64039
McAfeeGeneric-FAGO!134459F3AB58
VBA32BScope.Malware-Cryptor.Zbot.2413
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.35FH13
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!3OH/Ykv9YJo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
BitDefenderThetaGen:NN.ZexaF.36132.mu1@aOwdCTjc
AVGWin32:Gepys-A [Trj]
DeepInstinctMALICIOUS

How to remove Troj/Gyepis-A?

Troj/Gyepis-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment