Trojan

Trojan:Win32/Gepys!MTB (file analysis)

Malware Removal

The Trojan:Win32/Gepys!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gepys!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan:Win32/Gepys!MTB?


File Info:

name: DE7FC8DA34A6BF0E28FF.mlw
path: /opt/CAPEv2/storage/binaries/a94d73515ada631c170b005a112094ace09b63a51c3acf914c874a6a86779124
crc32: B51AF4BD
md5: de7fc8da34a6bf0e28ffda1a27f65623
sha1: 8d960e0b50133d52ba1d594d298b5109db059080
sha256: a94d73515ada631c170b005a112094ace09b63a51c3acf914c874a6a86779124
sha512: 197c507dfef9c1d37c077b5fc13d7022bcb7841ceec3f4733a6d52490bf4e93329214e962af1a3f2a322219f4a960b8f5ca9dce6c98f1240b883943d8cec96f3
ssdeep: 1536:GsbgvXGlEMW588P8s0HzaJFRAo4UT/JAmcK3nCcx2PHCuAK1om7bie+pfRlM1:lUWf4lkzilRadK3CZHJAKWyh+pfRlM1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AED3AD0277D1C856F02A0A3189A3DBFD07A6FD60EA75836775D47F5FBCB66808D22A10
sha3_384: 4000058e7fa064b06ad380291b799f6d585636018b0e05d563eb65be855036dc77304e1303f02e03dcac91a609f49279
ep_bytes: 5589e55381eca4000000c78578ffffff
timestamp: 2013-05-30 10:15:16

Version Info:

0: [No Data]

Trojan:Win32/Gepys!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.FKP.17
FireEyeGeneric.mg.de7fc8da34a6bf0e
CAT-QuickHealTrojanDropper.Gepys.A
McAfeeTrojan-FCFU!DE7FC8DA34A6
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.411345
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005035811 )
AlibabaTrojan:Win32/Gepys.9028de13
K7GWTrojan ( 005035811 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Kryptik.xt
CyrenW32/S-02880761!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BCIG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.17
NANO-AntivirusTrojan.Win32.Mods.crmufd
AvastWin32:Kryptik-LXC [Trj]
TencentTrojan.Win32.Kryptik.bcig
EmsisoftGen:Heur.FKP.17 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Mods.1
VIPREGen:Heur.FKP.17
TrendMicroTROJ_DOFOIL.SMAD
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
SophosTroj/Gepys-Fam
IkarusTrojan-Dropper.Win32.Gepys
GDataWin32.Trojan.PSE.14L3VOS
JiangminTrojan/Generic.awxay
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.BCIG@4yb52m
ArcabitTrojan.FKP.17
ViRobotTrojan.Win.Z.Kryptik.136632.J
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Gepys!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R70572
BitDefenderThetaGen:NN.ZexaF.36196.iyX@aqBc71di
ALYacGen:Heur.FKP.17
MAXmalware (ai score=86)
VBA32BScope.Trojan.AET.11607
MalwarebytesCrypt.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_DOFOIL.SMAD
RisingTrojan.Kryptik!1.A7BD (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.BCLI!tr
AVGWin32:Kryptik-LXC [Trj]
Cybereasonmalicious.a34a6b
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Gepys!MTB?

Trojan:Win32/Gepys!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment