Trojan

Should I remove “TrojanDropper:Win32/Gepys!pz”?

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: 43035FCDBA9D3A9093BC.mlw
path: /opt/CAPEv2/storage/binaries/cd5d60f83cddaf36287bb6e2bb26ef368496c89d5bcb4cae96dbb651932b6347
crc32: 80399DEF
md5: 43035fcdba9d3a9093bc004bf913dfe8
sha1: 2d67e59d1ee8c9bb7b0528f2bfb5f86ba97906a5
sha256: cd5d60f83cddaf36287bb6e2bb26ef368496c89d5bcb4cae96dbb651932b6347
sha512: 53491c80ed985e968e99af595253a4660d472de14c96ab5edcf50041ad7dc92e4eeb9fa004aa2211a3c4abbf5d0cecbfdc70769d02af3a2dc7102bf831095ff9
ssdeep: 3072:1TptPnffub0qeGLcVrm6ixZcaDAsvgC2ZxCD2vCzC/ilcE5yCT+:1Tvn50cVkHfJicC/Gc6rC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171E3AE12B3DA9CD3E8111A32488BC6F946AAFD54B865525731C2EF8FAE362514F31633
sha3_384: b105e3e1bc710885441813e7acd853e15793c19662e60872ddc80986b63857e2f671416424a04a4776ee2f9f8482c82b
ep_bytes: 5589e55381eca4000000c78578ffffff
timestamp: 2013-05-31 16:28:27

Version Info:

0: [No Data]

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.FKP.17
ClamAVWin.Packed.Shipup-6804425-0
FireEyeGeneric.mg.43035fcdba9d3a90
SkyhighBehavesLike.Win32.Ctsinf.ch
McAfeeGeneric.atg-FAIF!43035FCDBA9D
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Heur.FKP.17
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d1ee8c
BaiduWin32.Trojan.Kryptik.ahj
VirITTrojan.Win32.Crypt.CIHS
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BCLI
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.17
NANO-AntivirusTrojan.Win32.Mods.cqimsc
AvastWin32:Kryptik-LXC [Trj]
TencentTrojan.Win32.Kryptik.bcig
EmsisoftGen:Heur.FKP.17 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Mods.1
ZillyaTrojan.ShipUp.Win32.1618
TrendMicroTROJ_DOFOIL.SMAD
Trapminemalicious.high.ml.score
SophosTroj/Gepys-Fam
IkarusTrojan-Dropper.Win32.Gepys
GDataGen:Heur.FKP.17
JiangminTrojan/ShipUp.rp
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDropper.Gepys.BCLI@79aj7f
ArcabitTrojan.FKP.17
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Gepys!pz
VaristW32/Kryptik.LRL.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R635951
Acronissuspicious
VBA32BScope.Trojan.Mods
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DOFOIL.SMAD
RisingTrojan.Kryptik!1.A7F4 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BCLI!tr
BitDefenderThetaAI:Packer.1B7028801F
AVGWin32:Kryptik-LXC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment