Trojan

TrojanDropper:Win32/Gepys!pz malicious file

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: 15F69D6A114889AEC357.mlw
path: /opt/CAPEv2/storage/binaries/b6a984fe07b93ad4d0ecfa8a7f114ea8b0f748149de1f9b4da59a394c3a6368c
crc32: 7CE3809D
md5: 15f69d6a114889aec357dfe118510be0
sha1: 160c0527ecec813d99501aee695982c05749f497
sha256: b6a984fe07b93ad4d0ecfa8a7f114ea8b0f748149de1f9b4da59a394c3a6368c
sha512: 6cdeff837c6b4d475239e96ac3a7143f7b95645bca56256fff273d0d733e664a996aefb1cc919722f3f0500733cfea13ed449481ca364e12dcd329d791f86b6c
ssdeep: 3072:jyJQi36nt1Yks8Tz86POoZVcb+BCqKHeqa+MFxb5w:GSlt1YksazzZnKBm6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112C3C081F3D1EE87E55C623180670A6305B8DD19E6A1366B1588BF7FECB1331066BE1B
sha3_384: 7202794b9d3d88afb2cdf44b66d77c969ee70b2a9e1d35d6cc83e4d74295ab810f505ee6ef1a5400aff24cc84b3eaa25
ep_bytes: 60be000045008dbe0010fbff57eb0b90
timestamp: 2013-03-05 08:54:29

Version Info:

0: [No Data]

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gepys.b!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Babar.38379
FireEyeGeneric.mg.15f69d6a114889ae
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Babar.38379
Cylanceunsafe
ZillyaDropper.Agent.Win32.576166
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004363fa1 )
AlibabaTrojanDropper:Win32/Gepys.29010f71
K7GWTrojan ( 004363fa1 )
Cybereasonmalicious.a11488
ArcabitTrojan.Babar.D95EB
BitDefenderThetaGen:NN.ZexaF.36802.hmJfa4h3nLgi
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Gepys.AA
APEXMalicious
KasperskyTrojan-Dropper.Win32.Agent.hkve
BitDefenderGen:Variant.Babar.38379
NANO-AntivirusTrojan.Win32.Agent.cqkxzp
AvastWin32:Gepys-B [Trj]
TencentTrojan.Win32.Agent.agu
EmsisoftGen:Variant.Babar.38379 (B)
BaiduWin32.Trojan-Dropper.Gepys.a
F-SecureTrojan.TR/Crypt.XPACK.Gen8
DrWebTrojan.Mods.146
VIPREGen:Variant.Babar.38379
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.bnns
VaristW32/Gepys.BS.gen!Eldorado
AviraTR/Crypt.XPACK.Gen8
Antiy-AVLTrojan[Dropper]/Win32.Gepys
Kingsoftmalware.kb.b.971
XcitiumTrojWare.Win32.Gepys.A@4z4j8j
MicrosoftTrojanDropper:Win32/Gepys!pz
ZoneAlarmTrojan-Dropper.Win32.Agent.hkve
GDataWin32.Trojan.PSE.1IW07WR
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!15F69D6A1148
MAXmalware (ai score=87)
VBA32Trojan.Redirect
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingDropper.Gepys!8.15D (TFE:5:TrGpy0WuCcL)
YandexTrojan.GenAsa!aK3gU8Sx7oA
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gepys.B!tr
AVGWin32:Gepys-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[dropper]:Win/Gepys.AA

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment