Trojan

TrojanDropper:Win32/Gepys!pz malicious file

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: EB79D970C3ACC0ED30A4.mlw
path: /opt/CAPEv2/storage/binaries/4c49cc26dd5b93f76536a67526f4104194545b3aec4190ee281a763fb0e41c94
crc32: 37AAE59A
md5: eb79d970c3acc0ed30a441abf502034b
sha1: fbaa20f2d14cb08d409ddecd64e810dcedf6b2c5
sha256: 4c49cc26dd5b93f76536a67526f4104194545b3aec4190ee281a763fb0e41c94
sha512: 67f8d920ef683b66fb912248a051c5962a3c532b933939e5b1a2d69dde7af6db6d163fa127faa4f34092e9d1d6d424a16bfc31a1d19442e6729728b48299108e
ssdeep: 3072:aw9XTpcvocFIALdm3vL5wI1G6OoBQXTmy5xEKJ9W8NRVvmwXeegZ4cphfo:J9X1qoEd2v9wI1XOoTDHERVXcTA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F704AE83B3938ADBE8384A35784286FC265D7D6EB561522735C0FF8FE8F21452F12691
sha3_384: a74751110ff4ca8e28a7fbcef04c01810196d98b42e9243ab39840bd09203710d3ac1bc616347a06f778ecda73459b6b
ep_bytes: 53515256c884000081ed82000000c745
timestamp: 2013-05-22 11:52:03

Version Info:

0: [No Data]

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Mods.146
MicroWorld-eScanGen:Variant.Zusy.538834
FireEyeGeneric.mg.eb79d970c3acc0ed
SkyhighBehavesLike.Win32.Dropper.ch
McAfeeDropper-FFQ!EB79D970C3AC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4600792
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f4c81 )
K7GWTrojan ( 0040f4c81 )
Cybereasonmalicious.0c3acc
BitDefenderThetaGen:NN.ZexaF.36802.luZ@a8B0Exm
VirITTrojan.Win32.Generic.VVS
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GUXR
APEXMalicious
TrendMicro-HouseCallPAK_Xed-21
ClamAVWin.Malware.Ulise-6840317-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.538834
AvastWin32:Kryptik-LUA [Trj]
SophosTroj/Gepys-A
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Zusy.538834
TrendMicroPAK_Xed-21
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.538834 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.awsky
VaristW32/GenTroj.BW.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Kryptik.BBSW@4xttk5
ArcabitTrojan.Zusy.D838D2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.17GTXUI
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R635927
Acronissuspicious
VBA32Trojan.AET.24507
ALYacGen:Variant.Zusy.538834
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B5A3 (CLASSIC)
YandexTrojan.GenAsa!S5LTJErtm2o
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.BBSW!tr
AVGWin32:Kryptik-LUA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment