Trojan

About “TrojanDropper:Win32/Gepys!pz” infection

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: 2AD2EF852FDC6034320A.mlw
path: /opt/CAPEv2/storage/binaries/fc52fbd39efecd65604837ddb710760785dda23c9c7c5d8b902fdc0dadf12342
crc32: 41BAD51F
md5: 2ad2ef852fdc6034320ac67e12c03b82
sha1: b3d68f7a6c4483d90e614071d9689d40d422829e
sha256: fc52fbd39efecd65604837ddb710760785dda23c9c7c5d8b902fdc0dadf12342
sha512: 789c0e4b0b63c64eab66033017b1d766a63bf8f8bccd59bb1752c75fc5ef62d1984e096071496b896940850698b5cb56c7ee587325aff00b1ca2206d5ba5cb98
ssdeep: 3072:K/lXvD2enVN5UkL+jRj7o+8ijdJp8NXQkkxvU84xUa4bjRT5cmHR:K/lfD2Ap3MjdLMeqJ2j8mHR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A724BD016BB63C87DC0C24BC9562F5787BDBB563B308956178A0DAA7FDE2AF14B44342
sha3_384: dba5375b816dd103f81f24860cddbe0b51198e4d876504ff3fe995f1f4a8667798d53352164fbdaa17573944cb398e95
ep_bytes: 558bec51ff1588224300689c0100006a
timestamp: 2013-04-16 04:35:55

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ShipUp.lISW
Elasticmalicious (high confidence)
DrWebTrojan.RedirectENT.140
MicroWorld-eScanTrojan.GenericKDZ.97319
FireEyeGeneric.mg.2ad2ef852fdc6034
CAT-QuickHealTrojanPWS.Zbot.Y
SkyhighBehavesLike.Win32.PWSZbot.dc
ALYacTrojan.GenericKDZ.97319
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.373284
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
AlibabaTrojan:Win32/Kryptik.e113
K7GWTrojan ( 004cf6b81 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D17C27
BitDefenderThetaGen:NN.ZexaF.36744.mu1@amp73icc
VirITTrojan.Win32.Generic.BSLY
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYUW
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Lethic-7101888-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.97319
NANO-AntivirusTrojan.Win32.RedirectENT.cqosnc
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Gepys-A [Trj]
TencentTrojan.Win32.Copak.wg
EmsisoftTrojan.GenericKDZ.97319 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan.Agent.eq
VIPRETrojan.GenericKDZ.97319
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
SophosTroj/Gyepis-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.avutd
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.ShipUp
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
MicrosoftTrojanDropper:Win32/Gepys!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.10E223C
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R64039
Acronissuspicious
McAfeeGeneric-FAGO!2AD2EF852FDC
MAXmalware (ai score=87)
VBA32BScope.Malware-Cryptor.Zbot.2413
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!3OH/Ykv9YJo
IkarusTrojan-Dropper.Win32.Gepys
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.AYUW!tr
AVGWin32:Gepys-A [Trj]
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment