Trojan

TrojanDownloader:Win32/Skidlo.AC removal tips

Malware Removal

The TrojanDownloader:Win32/Skidlo.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Skidlo.AC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

uldintoldhin.com
roblociho.ru
garinbetot.ru

How to determine TrojanDownloader:Win32/Skidlo.AC?


File Info:

crc32: 884E24E8
md5: c77e1e3da5123cdaf34f4109ea2098f0
name: C77E1E3DA5123CDAF34F4109EA2098F0.mlw
sha1: 8a5d28883e2f3ed295d3e4dcc6d5a9342f85e901
sha256: 14b4cbd05ded6674c042b148392c7ffbef532dcef102319000d9510c50f35236
sha512: 528aa779d23ff37f5e24d133da9e0a91de0a86e5acacdd8900bdc6d31f42fd3a0965fca0c6e2d2592fca5d316b9f5a3b13f80a1cf5c4f53aed51dc65100ec005
ssdeep: 1536:CVMUe8lG01fPqnYDIdPn2sEjmohHPDvns50WtzoZNH+dSnL:OMYoaH7DIUjjvs50YGHWY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1996- 2007
FileVersion: 7,2,8,1
CompanyName: QQQ&AlinSoft
ProductName: YqcfBwgaZU
ProductVersion: 7,2,8,1
FileDescription: qcfBwgaZU
OriginalFilename: YqcfBwgaZU.exe
Translation: 0x0407 0x04e8

TrojanDownloader:Win32/Skidlo.AC also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Dreidel.fq0@xKRgtini
FireEyeGeneric.mg.c77e1e3da5123cda
CAT-QuickHealRansomware.Tescrypt.WR5
McAfeeDownloader-FBIH!C77E1E3DA512
CylanceUnsafe
VIPRETrojan.Win32.TeslaCrypt.a (v)
AegisLabTrojan.Win32.Zlader.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Heur.Mint.Dreidel.fq0@xKRgtini
K7GWTrojan ( 0056fb141 )
K7AntiVirusTrojan ( 0056fb141 )
InvinceaMal/Generic-R + Troj/Agent-ASXC
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zlader.f
AlibabaTrojan:Win32/Zlader.f9ff50f9
NANO-AntivirusTrojan.Win32.TrjGen.eewvwn
ViRobotTrojan.Win32.Z.Zlader.88064
RisingDownloader.Skidlo!8.1B69 (TFE:5:FeBiP1VcG4G)
Ad-AwareGen:Heur.Mint.Dreidel.fq0@xKRgtini
SophosTroj/Agent-ASXC
ComodoMalware@#2ud92yi6cweju
F-SecureHeuristic.HEUR/AGEN.1107232
DrWebTrojan.PWS.Siggen1.54890
ZillyaTrojan.Zlader.Win32.114
TrendMicroWORM_HANCITOR.YYSVJ
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
EmsisoftGen:Heur.Mint.Dreidel.fq0@xKRgtini (B)
IkarusTrojan-Downloader.Win32.Small
JiangminTrojan.Zlader.g
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1107232
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Zlader
KingsoftWin32.Troj.Zlader.f.(kcloud)
MicrosoftTrojanDownloader:Win32/Skidlo.AC
ArcabitTrojan.Mint.Dreidel.EDB693
SUPERAntiSpywareRansom.Tobfy/Variant
ZoneAlarmTrojan.Win32.Zlader.f
GDataWin32.Trojan-Ransom.Cryptolocker.AB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C1510086
VBA32Heur.Malware-Cryptor.Filecoder
ALYacGen:Heur.Mint.Dreidel.fq0@xKRgtini
TACHYONTrojan/W32.Zlader.88064
PandaTrj/Genetic.gen
ESET-NOD32Win32/Zlader.L
TrendMicro-HouseCallWORM_HANCITOR.YYSVJ
TencentWin32.Trojan.Zlader.Syru
YandexTrojan.Zlader!3Za+w/wv/a4
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.DDEA!tr
BitDefenderThetaGen:NN.ZexaF.34634.fq0@aKRgtini
AVGWin32:Malware-gen
Cybereasonmalicious.da5123
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM10.2.8199.Malware.Gen

How to remove TrojanDownloader:Win32/Skidlo.AC?

TrojanDownloader:Win32/Skidlo.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment