Trojan

TrojanDropper:Win32/Gepys!pz (file analysis)

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: 0E741800430D07500220.mlw
path: /opt/CAPEv2/storage/binaries/9d3084dbb0b10091fdd9ead6131c811ec4ad148ab4bb7bbbf7cbdaeaebecc4a3
crc32: 6F22355B
md5: 0e741800430d075002205e708402c27b
sha1: 3deee60af16e2a510a8ba96c09ccf9fbb9e21c56
sha256: 9d3084dbb0b10091fdd9ead6131c811ec4ad148ab4bb7bbbf7cbdaeaebecc4a3
sha512: 5aac70a770523fa451a34489b3eedc7fd0f6bfa1f902b5a8cfccb813c545fc2cb71cdcd987df19a48154cdf780a450c331f7d92286c7c44d58f3fc5242594424
ssdeep: 6144:dd+ozneIZIwYJnuEgH88zdTyKzkCyYOkwpOKu:dIoivwYJuRAKzAYHwp6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE348C02A750FC32D9ED02F0BF864B35275E50AD6B1D5982958FFAB5A11228178FCDF2
sha3_384: 5850413d995f257801648e94b2042b05eab8c10576bbc9207683812757e5a1f5d098c82457b8f9f64d32b8a63298a759
ep_bytes: 558bec51689c0100006a00ff1554c040
timestamp: 2013-04-10 09:12:02

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Gepys-E [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.0e741800430d0750
SkyhighBehavesLike.Win32.PWSZbot.dh
McAfeeGeneric-FAGO!0E741800430D
MalwarebytesTrojan.Dropper
VIPRETrojan.Ransom.Cerber.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Agent.eq
VirITI-WORM.Beagle.DM
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYMY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Redirect.cqnkbb
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000289
SophosTroj/Gyepis-A
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Redirect.140
ZillyaTrojan.Agent.Win32.361710
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.avpsx
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1A06N6
GoogleDetected
AhnLab-V3Trojan/Win.Kryptk.R638652
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.oK1@a4stRhhc
ALYacTrojan.Ransom.Cerber.1
VBA32BScope.Malware-Cryptor.Zbot.2413
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.WebSpoof.Gen.AL
IkarusTrojan.Win32.ShipUp
FortinetW32/Kryptik.AYUW!tr
Cybereasonmalicious.0430d0
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment