Trojan

What is “TrojanDropper:Win32/Gepys!pz”?

Malware Removal

The TrojanDropper:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Gepys!pz?


File Info:

name: 60F45520BB14DB5DA2C6.mlw
path: /opt/CAPEv2/storage/binaries/d136a2bf33b28fd58b84036e5aa462e7bcbf7f92b9cfdd5266ee986212e57320
crc32: D70F490E
md5: 60f45520bb14db5da2c6c3b911d8c504
sha1: 3b95fdde594b95842e90ff0f8da50073772292f8
sha256: d136a2bf33b28fd58b84036e5aa462e7bcbf7f92b9cfdd5266ee986212e57320
sha512: 1a5c09b50378f466bb389e6a11f4a3aa9105234ba1f77285204738bbc47d15b66d4586ab1fc1d66b2715464027b5b0beff56818e74e8516fe4a7b47d8ad19874
ssdeep: 3072:SnBJOcumc7+5DHhH0qjuIWvJ2XVYxVJ/PWiud3uWHWABIippBr:2OCcq3BjunvJ2lYjJ/PWiuvBRppBr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F34BE497BA2EC24EA6727398AD2C9311438D9133B6444472784DDDFB1F06BF462BBE1
sha3_384: 062830ef282680641a82d33797090d1699717dbe763cb46d96ba634268be3c8ec90979d678f6e78f2c6fcc11758005cb
ep_bytes: 5589e551689c0100006a00ff1528c040
timestamp: 2013-04-12 05:07:20

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

TrojanDropper:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
ClamAVWin.Trojan.Generickd-37
SkyhighBehavesLike.Win32.PWSZbot.dh
McAfeeGeneric-FAGO!60F45520BB14
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Ransom.TorrentLocker.92
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.e594b9
BaiduWin32.Trojan.Agent.eq
VirITTrojan.Win32.Generic.SKU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AYQE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusTrojan.Win32.Mods.khtthy
SUPERAntiSpywareTrojan.Agent/Gen-Gepys
AvastWin32:Karagany
TencentTrojan.Win32.Kryptik.16000289
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Mods.146
TrendMicroTROJ_KRYPTK.SML3
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.60f45520bb14db5d
SophosMal/ZAccess-CG
GDataWin32.Trojan.PSE1.766752
JiangminTrojan.Generic.ejyoc
GoogleDetected
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[Dropper]/Win32.Gepys
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Ransom.TorrentLocker.92
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Gepys!pz
VaristW32/Zbot.JC.gen!Eldorado
AhnLab-V3Trojan/Win32.Shipup.R61194
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.o01@aW82Zpgc
MAXmalware (ai score=86)
VBA32BScope.Malware-Cryptor.Hlux
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingDropper.Win32.Gepys.h (CLASSIC)
YandexTrojan.GenAsa!8bGiVzIqWwU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.ANYO!tr
AVGWin32:Karagany
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Gepys!pz?

TrojanDropper:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment