Trojan

How to remove “Trojan:Win32/Gepys!pz”?

Malware Removal

The Trojan:Win32/Gepys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gepys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Gepys!pz?


File Info:

name: 80DD4A6DFFB895E9A274.mlw
path: /opt/CAPEv2/storage/binaries/e120d1b468e72827608c0598a0cc40a5509b3a9a7fbda93b688d8a613c0d49c6
crc32: D7DB41E3
md5: 80dd4a6dffb895e9a274daafc48fcf9c
sha1: f88f54941678e132298277b71386e703ff06c2b4
sha256: e120d1b468e72827608c0598a0cc40a5509b3a9a7fbda93b688d8a613c0d49c6
sha512: 7ff2c53fe6314bff8d622b4224bf906ed7e593f4ff1825b11c4f8545b5a535cc92cfa4f8e898d41350397c421a9993e435a30461a575b5caad4504e401e798ac
ssdeep: 3072:TmpUAQIRTt0iheqKPOks25BJWf5O1nOrXX++hnFwPBnBBisgLCVq7gtyy900OS2e:TmGAQ2TtYDPOks2DKO18Xu+hnF8BBiRq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B14BE03B794DC42E0255630C857D7BC06A1FC52D95582A332D8BF9FECBA3909E36B5A
sha3_384: 68a134a54e1220969426d8d6995cfc3e1fea8a5c8ceb07e9d0b1937f88f8cf57226cd07ea99b36d46b7acb6d726b9baf
ep_bytes: 535152e82c09000089c385c0750dff15
timestamp: 2010-08-08 18:32:42

Version Info:

0: [No Data]

Trojan:Win32/Gepys!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lUUy
MicroWorld-eScanGen:Variant.Zusy.440890
CAT-QuickHealTrojanDropper.Gepys.A
SkyhighBehavesLike.Win32.Dropper.ch
McAfeeDropper-FGJ!80DD4A6DFFB8
Cylanceunsafe
VIPREGen:Variant.Zusy.440890
SangforTrojan.Win32.Kryptik.Vh6j
K7AntiVirusTrojan ( 0040f4c81 )
BitDefenderGen:Variant.Zusy.440890
K7GWTrojan ( 0040f4c81 )
Cybereasonmalicious.41678e
VirITTrojan.Win32.Crypt.COYR
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BDPT
APEXMalicious
ClamAVWin.Trojan.Agent-1123386
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Gepys.758ed0d5
NANO-AntivirusTrojan.Win32.ShipUp.bxpjor
ViRobotTrojan.Win.Z.Zusy.190416
RisingTrojan.Crypto!8.364 (TFE:4:XrurqJkKijC)
SophosTroj/Agent-ACIZ
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Mods.1
ZillyaTrojan.ShipUp.Win32.1642
TrendMicroTROJ_GEN.R002C0DK523
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.80dd4a6dffb895e9
EmsisoftGen:Variant.Zusy.440890 (B)
IkarusTrojan.CryptOYR
MAXmalware (ai score=88)
JiangminTrojan/Generic.axfgs
GoogleDetected
AviraTR/Crypt.ZPACK.Gen7
VaristW32/A-2d381ee4!Eldorado
Antiy-AVLTrojan/Win32.Unknown
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Gepys!pz
XcitiumTrojWare.Win32.Gepys.AC@50ivv5
ArcabitTrojan.Zusy.D6BA3A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.2AKVBF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dofoil.R70806
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.luX@a4DKjMp
ALYacGen:Variant.Zusy.440890
DeepInstinctMALICIOUS
VBA32Trojan.ShipUp
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DK523
TencentMalware.Win32.Gencirc.10b89ad1
YandexTrojan.ShipUp!JDiyd2hcE+U
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.BDUE!tr
AVGWin32:Kryptik-MCR [Trj]
AvastWin32:Kryptik-MCR [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Gepys!pz?

Trojan:Win32/Gepys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment