Trojan

TrojanDropper:Win32/Gepys!pz (file analysis)

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: F08070ECDCA797B2D2E8.mlw
path: /opt/CAPEv2/storage/binaries/4975a3dc0d82b32c306cb680bfd2154f723defeeeceb95250b3e6a8095c87cc2
crc32: 940F0227
md5: f08070ecdca797b2d2e8d25d65b62594
sha1: 3ec5c0cfe9dbddb43ed6185929c7c938977e79fd
sha256: 4975a3dc0d82b32c306cb680bfd2154f723defeeeceb95250b3e6a8095c87cc2
sha512: 4b702b93be9780c1c73e11b1a06815a47606e39a7f6ebcc10d67e6c19aedbb55e59db89b316afd0a472f21822765746540ea55711a0abc9375bb6e2f29bd389e
ssdeep: 3072:oCOcumc7SrsjVRQui8bedxuO/PWiud3uWHWABIippBm:ZOCcY8bgD/PWiuvBRppBm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17234AD8977A3EC20F9162B7846D9C971142AC5133B54680B1383CECF70B867EB697BC8
sha3_384: 806a3d8c886f3b32c8bcd4f2839976e8ea2698b3b0f16fc9f97e89b7266e846a7d18e80cfa2c5d7e7581541342c5e739
ep_bytes: 558bec51ff150cc04000689c0100006a
timestamp: 2013-04-12 10:58:22

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Gepys-E [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.Redirect.140
MicroWorld-eScanTrojan.GenericKDZ.94845
FireEyeGeneric.mg.f08070ecdca797b2
CAT-QuickHealTrojan.VindorIH.S31411928
SkyhighBehavesLike.Win32.PWSZbot.dh
McAfeeGeneric-FAGO!F08070ECDCA7
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.GenericKDZ.94845
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
Cybereasonmalicious.cdca79
BitDefenderThetaGen:NN.ZexaF.36802.o41@aaHglggc
VirITI-WORM.Beagle.DM
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYQE
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Gepys-E [Trj]
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.94845
NANO-AntivirusTrojan.Win32.ShipUp.crgjdf
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentTrojan.Win32.Ransom.wa
SophosTroj/Gyepis-A
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Agent.eq
ZillyaTrojan.Kryptik.Win32.4580414
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94845 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.14UWGU6
JiangminTrojan/Generic.avutr
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Generic.D1727D
ViRobotTrojan.Win32.Agent.269040
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Gepys!pz
GoogleDetected
AhnLab-V3Trojan/Win.Shipup.R505399
Acronissuspicious
VBA32BScope.Malware-Cryptor.Zbot.2413
ALYacTrojan.GenericKDZ.94845
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!z/xKnVWIIE8
IkarusTrojan-Dropper.Win32.Gepys
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.AYUW!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment