Trojan

How to remove “Trojan.ShipUp”?

Malware Removal

The Trojan.ShipUp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ShipUp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.ShipUp?


File Info:

crc32: 5CDD9DA2
md5: 97136c386d4ac94437ba335a7030c586
name: 97136C386D4AC94437BA335A7030C586.mlw
sha1: dd093a0993c3cd3b135afb9c28cc844bb973f92a
sha256: 5bd39f71cf0eace15af8cd8320955b276724d446771bcd4dfffda28472a58b49
sha512: 93e0f73724a8081dd75113c11f65150191e00537777227feb3d8baca89d33a54a06f4f4639dc72ca8bf37cd8eaafe41d4f33c3a90827125e1605af005cbd4d9c
ssdeep: 6144:WCDM2K8dgQZw88wNrRJQNy+z+t21vjdciLbyyPncWR4IBqUsvU2YYG5g/:WCw2K8WQj8dNyyR1aiLbZPnVRRqUXO/
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.ShipUp also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.566432
FireEyeGeneric.mg.97136c386d4ac944
CAT-QuickHealTrojanDropper.Gepys.A
Qihoo-360Generic/HEUR/QVM20.1.5984.Malware.Gen
ALYacGen:Variant.Razy.566432
CylanceUnsafe
VIPRETrojan-Dropper.Win32.Gepys.b (v)
SangforMalware
K7AntiVirusTrojan ( 005035811 )
BitDefenderGen:Variant.Razy.566432
K7GWTrojan ( 005035811 )
Cybereasonmalicious.86d4ac
TrendMicroTROJ_DROPPR.SMNO
BaiduWin32.Trojan.Kryptik.if
CyrenW32/Gepys.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Gepys-18
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Kryptik!1.A7F4 (CLASSIC)
Ad-AwareGen:Variant.Razy.566432
SophosMal/Generic-S
ComodoTrojWare.Win32.Kryptik.BCCG@4yb52r
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Mods.1
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Variant.Razy.566432 (B)
JiangminTrojan/ShipUp.nj
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen7
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Nagram!rfn
ArcabitTrojan.Razy.D8A4A0
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.566432
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Dofoil.R68993
Acronissuspicious
McAfeeGenericRXAA-AA!97136C386D4A
VBA32Trojan.AET.24507
MalwarebytesTrojan.ShipUp
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.BCGC
TrendMicro-HouseCallTROJ_DROPPR.SMNO
TencentTrojan.Win32.Kryptik.bcig
YandexTrojan.GenAsa!ejluhcqFMZQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Gepys.AA!tr
BitDefenderThetaGen:NN.ZexaF.34634.tyZ@a8jmFfe
AVGWin32:Trojan-gen

How to remove Trojan.ShipUp?

Trojan.ShipUp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment