Trojan

What is “Trojan:BAT/Gepys.A”?

Malware Removal

The Trojan:BAT/Gepys.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:BAT/Gepys.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • A possible heap spray exploit has been detected
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine Trojan:BAT/Gepys.A?


File Info:

name: C887FB11FC112F70FC65.mlw
path: /opt/CAPEv2/storage/binaries/00d99529990012f73b6ab3a726619756447504c9fb14f5164f3f3c73da02619d
crc32: CFD73234
md5: c887fb11fc112f70fc6550028a2c900c
sha1: a03a1c230fbbe5f5a9b05d3f3fa6fa558fdbf4c8
sha256: 00d99529990012f73b6ab3a726619756447504c9fb14f5164f3f3c73da02619d
sha512: 77013085717db84d82b336a452ace869da0322e3fbe15866e229242bb43fae669179765ec2eb50711a1df9e8c705b8acc7ceb921cb96cc952f33b32b02a26243
ssdeep: 12288:tK2mhAMJ/cPl2cHobZ5TT7crJv5ay5MGoPYqyebu+fup0PDI2d:82O/Gl677s4YdrpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAE4F1427A81D0B4EC240E34047B9F1A5B72BC386CB4A957FB95B64EFB72391342A717
sha3_384: 7c3ce8959dd598834c4589eb5caa89ad8cf6325ee808e1142b58bd0e3a4bd6e99763a8782885cd1b7e3cbf2b5c7946ca
ep_bytes: e8e3feffff33c050505050e89f300000
timestamp: 2012-06-09 13:19:49

Version Info:

0: [No Data]

Trojan:BAT/Gepys.A also known as:

LionicTrojan.Win32.ShipUp.mwEE
MicroWorld-eScanTrojan.ScriptKD.512
FireEyeTrojan.ScriptKD.512
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Variant.Razy.749567
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.1168
SangforTrojan.Win32.Agent.Vpkd
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/CeeInject.eca24bf7
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1fc112
BitDefenderThetaGen:NN.ZexaF.34806.oq0@aqP3dNgi
VirITTrojan.Win32.Siggen5.CTY
CyrenW32/Zbot.JC.gen!Eldorado
SymantecTrojan.Gen.3
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
BaiduMulti.Threats.InArchive
TrendMicro-HouseCallTROJ_KRYPTK.SML3
Paloaltogeneric.ml
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyTrojan.Win32.ShipUp.boe
BitDefenderTrojan.ScriptKD.512
NANO-AntivirusTrojan.Win32.ShipUp.bqpmbi
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastBV:Malware-gen
TencentWin32.Trojan.Shipup.Kzfl
Ad-AwareTrojan.ScriptKD.512
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
DrWebTrojan.DownLoader10.14978
VIPRETrojan.ScriptKD.512
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Zbot-EHY
APEXMalicious
GDataWin32.Trojan.Gepys.GKTY46
JiangminTrojan/ShipUp.ix
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.217
KingsoftWin32.Troj.ShipUp.b.(kcloud)
ViRobotTrojan.Win32.Z.Agent.717618
MicrosoftTrojan:BAT/Gepys.A
CynetMalicious (score: 99)
McAfeeArtemis!C887FB11FC11
VBA32Trojan.Redirect
MalwarebytesShipUp.Worm.Autorun.DDS
IkarusTrojan.Win32.Spy
RisingTrojan.Kryptik!1.AB51 (CLASSIC)
SentinelOneStatic AI – Malicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
AVGBV:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan:BAT/Gepys.A?

Trojan:BAT/Gepys.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment