Trojan

Trojan.Agent.GEZS removal instruction

Malware Removal

The Trojan.Agent.GEZS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GEZS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan.Agent.GEZS?


File Info:

name: 13A6C50D18FB9F0AE870.mlw
path: /opt/CAPEv2/storage/binaries/6dc5788049de41f09f32ffe2c84c715353efe32536fccb9c44254de8e8eae575
crc32: 24BFC8E9
md5: 13a6c50d18fb9f0ae8708485f24a5b99
sha1: b487ee62e797ba7bc62ff7d47b0a4b5b45cf2b30
sha256: 6dc5788049de41f09f32ffe2c84c715353efe32536fccb9c44254de8e8eae575
sha512: 212919c32c4d97d35f8ddd37c5c159646c85751b7b7bcb50a70a6c0b38f44dd71b79ad73923d3a780fe74de0fee7f29dc034d266226a983b3e23fda0dc97a481
ssdeep: 1536:k/T2X/jN2vxZz0DTHUpou9WbkRMn1PxfMz:kbG7N2kDTHUpou9WbXpxS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C33AE106760C827E9F24B7268B9AB7B9FF9991255A08F4703106E4C3E737C29B1F761
sha3_384: 92d9b499edc09643120f335308d53c6a904cf3330b5439b7f09cb48491b0c726664eed135c82005091eae83edc9061be
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

CompanyName: luminixe
FileDescription: petagenics
FileVersion: 6.4.3.5
LegalCopyright: (C) luminixe
ProductName: dailybrainy
ProductVersion: 6.4.3.5
Translation: 0x0409 0x04b0

Trojan.Agent.GEZS also known as:

BkavW32.Common.1F29C288
LionicTrojan.Win32.GoPIX.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.GEZS
SkyhighBAT/Downloader.bm
McAfeeArtemis!13A6C50D18FB
MalwarebytesMalware.AI.1506826093
K7AntiVirusTrojan ( 005ad2791 )
K7GWTrojan ( 005ad2791 )
Cybereasonmalicious.d18fb9
SymantecTrojan Horse
ESET-NOD32PowerShell/TrojanDownloader.Agent.HNA
TrendMicro-HouseCallTROJ_GEN.R002C0DF323
KasperskyHEUR:Trojan.BAT.GoPIX.gen
BitDefenderTrojan.Agent.GEZS
AvastBV:Obfuscated-P [Cryp]
TencentWin32.Trojan-Downloader.Downloader.Ekjl
EmsisoftTrojan.Agent.GEZS (B)
F-SecureTrojan.TR/Agent.auls
VIPRETrojan.Agent.GEZS
TrendMicroTROJ_GEN.R002C0DF323
FireEyeTrojan.Agent.GEZS
SophosMal/Generic-R
MAXmalware (ai score=84)
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Agent.auls
VaristW32/ABRisk.WTMF-9380
MicrosoftTrojan:Win32/Rastreio.A!MTB
ArcabitTrojan.Agent.GEZS
ViRobotTrojan.Win.Z.Agent.54264
ZoneAlarmHEUR:Trojan.BAT.GoPIX.gen
GDataBAT.Trojan.Agent.U43REY
AhnLab-V3Trojan/Win.Agent.C5435330
ALYacTrojan.Agent.GEZS
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan-Downloader.PowerShell.Agent
FortinetW32/Dloader.BM!tr
AVGBV:Obfuscated-P [Cryp]
DeepInstinctMALICIOUS

How to remove Trojan.Agent.GEZS?

Trojan.Agent.GEZS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment