Trojan

What is “Trojan.Win32.ShipUp.bnv”?

Malware Removal

The Trojan.Win32.ShipUp.bnv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.ShipUp.bnv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.ShipUp.bnv?


File Info:

name: AFAB91FB6E495DF8ABCA.mlw
path: /opt/CAPEv2/storage/binaries/0881aa96a69de74043d938ef65110acabf268d2c8750a3cd44ec088a8e14590d
crc32: D2227837
md5: afab91fb6e495df8abcadf1cce749a57
sha1: acb8d1cf185ac8bce95df737a60f5cd54bbe981a
sha256: 0881aa96a69de74043d938ef65110acabf268d2c8750a3cd44ec088a8e14590d
sha512: 34e3b15d4ebf38915c0b0564b0e000b75f8f2a29b4c95915b837d9d76d016c8da03756eaf078bb4184852a2949122cbfebdc003f808d8702cd39e563ba4065f6
ssdeep: 3072:T5MiiVM2EB3D3OtlX/L9+wijkKpj37u9vmHAyUFVdhxDdiht1wNyY9y63:NTiVdI3D38p+RXjtHAbFbiD11Ry
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE24ACCEA2AD5A3DDEFF35B158A583BE503653E06E614EE31658C240CF08FA73C454A6
sha3_384: 68b5185ab6fcc55ce65fa3af812203583af9ebf10decde684d6a0cab9fd21a6b3d21d98c41212db708728e1478829856
ep_bytes: 558bec51558f05f0644300a1f0644300
timestamp: 2011-01-15 08:45:30

Version Info:

0: [No Data]

Trojan.Win32.ShipUp.bnv also known as:

BkavW32.FamVT.ShipUpTC.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Redirect.140
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot-FAQW!AFAB91FB6E49
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.ShipUp.Win32.1159
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0040f7c21 )
K7AntiVirusTrojan ( 0040f7c21 )
BitDefenderThetaGen:NN.ZexaF.36250.nGX@aOmdiMmi
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AWRZ
APEXMalicious
ClamAVWin.Trojan.Shipup-90
KasperskyTrojan.Win32.ShipUp.bnv
BitDefenderTrojan.GenericKDZ.94711
NANO-AntivirusTrojan.Win32.ShipUp.bqorug
SUPERAntiSpywareTrojan.Agent/Gen-Injector
MicroWorld-eScanTrojan.GenericKDZ.94711
AvastWin32:Gepys-J [Trj]
TencentTrojan.Win32.ShipUp.awe
EmsisoftTrojan.GenericKDZ.94711 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Agent.eq
VIPRETrojan.GenericKDZ.94711
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.afab91fb6e495df8
SophosTroj/Zbot-EHY
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.166LU01
JiangminTrojan/ShipUp.hy
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.ShipUp.BNV@4vayon
ArcabitTrojan.Generic.D171F7
ZoneAlarmTrojan.Win32.ShipUp.bnv
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R58491
Acronissuspicious
VBA32BScope.Trojan.ShipUp
ALYacTrojan.GenericKDZ.94711
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB51 (CLASSIC)
YandexTrojan.GenAsa!KrAnaudnXQw
IkarusTrojan.Crypt3
MaxSecureTrojan.ShipUp.bnv
FortinetW32/Kryptik.AYTK!tr
AVGWin32:Gepys-J [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.ShipUp.bnv?

Trojan.Win32.ShipUp.bnv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment