Trojan

Trojan:Win32/ShipUp.DSK!MTB malicious file

Malware Removal

The Trojan:Win32/ShipUp.DSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/ShipUp.DSK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/ShipUp.DSK!MTB?


File Info:

crc32: 57FAAE66
md5: a637da5e3756dcb7f7a1738af4f1d083
name: A637DA5E3756DCB7F7A1738AF4F1D083.mlw
sha1: 3b25279057f11d149f238408adbfba1035240cfa
sha256: 1a3b1670fa0e74423c87b8c7bdd1f1f26721703f17a52bd3f16da1253058d88b
sha512: 5bff423c5f07bc69421f1be853c3f2aff4f6fbb8b450411f739f67f418af54b8248d2ed860e85b23126f5b19e0211599bdc1431fb141854b93caf182f31b136c
ssdeep: 6144:GNUTxSfmWnqst3YzV9y8R/Xzd6r0lrVyu:GNxfRRtEQ8R/XJxl1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: dpvsetup.exe
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.03.2600.5512
FileDescription: Microsoft DirectPlay Voice Test
OriginalFilename: dpvsetup.exe
Translation: 0x0409 0x04b0

Trojan:Win32/ShipUp.DSK!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00557ff21 )
Elasticmalicious (high confidence)
DrWebTrojan.Redirect.140
ClamAVWin.Packed.Shipup-6804175-0
CAT-QuickHealTrojanDropper.Gepys.A
McAfeePacked-AM!A637DA5E3756
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.1171
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00557ff21 )
Cybereasonmalicious.e3756d
BaiduWin32.Trojan.Agent.eq
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.AXID
APEXMalicious
AvastWin32:Gepys-J [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.bon
BitDefenderGen:Variant.Razy.853043
NANO-AntivirusTrojan.Win32.ShipUp.brntbf
MicroWorld-eScanGen:Variant.Razy.853043
TencentMalware.Win32.Gencirc.10b4da66
Ad-AwareGen:Variant.Razy.853043
SophosML/PE-A + Mal/ZAccess-CG
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
BitDefenderThetaGen:NN.ZexaF.34236.pq1@au!9xAhi
VIPRETrojan.Win32.Encpk.ait (v)
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.a637da5e3756dcb7
EmsisoftGen:Variant.Razy.853043 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/ShipUp.aah
AviraHEUR/AGEN.1121426
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.128138
MicrosoftTrojan:Win32/ShipUp.DSK!MTB
ZoneAlarmTrojan.Win32.ShipUp.bon
GDataGen:Variant.Razy.853043
AhnLab-V3Trojan/Win32.Shipup.R58811
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
MAXmalware (ai score=99)
MalwarebytesTrojan.FakeMS.ED
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.Kryptik!F7LZy2dghgs
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
AVGWin32:Gepys-J [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/ShipUp.DSK!MTB?

Trojan:Win32/ShipUp.DSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment