Trojan

Trojan:Win32/Skintrim.L (file analysis)

Malware Removal

The Trojan:Win32/Skintrim.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Skintrim.L virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Skintrim.L?


File Info:

crc32: 20E01B2B
md5: 5de22cad96a8853b768b714d38ed6d2c
name: 5DE22CAD96A8853B768B714D38ED6D2C.mlw
sha1: a2845ee71a5d01665e05fbf3dfb6f4e7cf2ed638
sha256: cf9c7ec9f41d2ebb1c0b43cce593bdb66a05f20a6a2086d375fab3d844e31bd4
sha512: 3eacc82a5988f8223b5809f0e7b495900d8092015c247c9adcbc3e57548ff69de651742243fe415f297c9cfcb46d509b9718d4af288ae84f1d299105781752da
ssdeep: 6144:Hzr+/gD5vjh8O9AkNIlYGgniNCqAoZi0Ww3WQV3+:HzS/SLhDzNIlY1iNCqAKbn3n
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: empaqueta
FileVersion: 9, 3, 7, 2
CompanyName: prxe9cordiale
LegalTrademarks: corsage
ProductName: scrambler
ProductVersion: 9, 3, 7, 2
FileDescription: comuniquxe9
Translation: 0x0409 0x04b0

Trojan:Win32/Skintrim.L also known as:

K7AntiVirusTrojan ( 700000041 )
LionicTrojan.Win32.Hrup.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Skintrim.791c5dc5
K7GWTrojan ( 700000041 )
Cybereasonmalicious.d96a88
CyrenW32/Wintrim.L.gen!Eldorado
SymantecTrojan.Skintrim!gen3
ESET-NOD32a variant of Win32/Skintrim.CR
APEXMalicious
AvastWin32:Skintrim-2
KasperskyTrojan.Win32.Hrup.ey
BitDefenderGen:Heur.NaviPromo.3
NANO-AntivirusTrojan.Win32.Hrup.fherhy
MicroWorld-eScanGen:Heur.NaviPromo.3
TencentWin32.Trojan.Hrup.Taza
Ad-AwareGen:Heur.NaviPromo.3
SophosMal/Hrup-A
ComodoTrojWare.Win32.Trojan.hrup.~GEN@1pv2gt
BitDefenderThetaGen:NN.ZexaF.34142.pq0@a4mRApai
VIPRETrojan.Win32.Skintrim.ha (v)
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
FireEyeGeneric.mg.5de22cad96a8853b
EmsisoftGen:Heur.NaviPromo.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Hrup.ceq
AviraADWARE/Adware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27EF3BD
MicrosoftTrojan:Win32/Skintrim.L
GDataGen:Heur.NaviPromo.3
Acronissuspicious
McAfeeSkintrim.gen.c
MAXmalware (ai score=100)
VBA32Trojan.Hrup
PandaTrj/Hrup.gen
RisingTrojan.Generic@ML.100 (RDMK:PtgITcekCndlgls9VygqSg)
IkarusTrojan.Win32.Skintrim
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Skintrim.CR!tr
AVGWin32:Skintrim-2
Paloaltogeneric.ml

How to remove Trojan:Win32/Skintrim.L?

Trojan:Win32/Skintrim.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment