Malware

Should I remove “Win32/Skintrim.FT”?

Malware Removal

The Win32/Skintrim.FT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Skintrim.FT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.ip-adress.com

How to determine Win32/Skintrim.FT?


File Info:

crc32: A3F4FF28
md5: d9df3a13114fe91dfbc2d27f643f2566
name: upload_file
sha1: a2e404cdbd9f413e691ada2db53b97a9ea82e959
sha256: 95de158e9b4302b8381dd9fab6da6977d6c2d1ad646720a66a9c8add4135a4d8
sha512: 98f4009a694903848108d87c4e21d356f6c81f3d853d9d9d4866ff2a808ad12de1a40420a912522f5d02bd40ba8b081c0b7620644bff05040a4a811fba03a467
ssdeep: 6144:dGUgm5pEfjVcjeETg1gpq0RHMH9TvV4hJ13J4OkcY7:dMBcjeugyY0RcKJjw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Skintrim.FT also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.52090
MicroWorld-eScanTrojan.GenericKD.34395406
FireEyeGeneric.mg.d9df3a13114fe91d
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Trojan.e91
McAfeeW32/PinkSbot-HA!D9DF3A13114F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
K7AntiVirusTrojan ( 00485ed61 )
BitDefenderTrojan.GenericKD.34395406
K7GWTrojan ( 00485ed61 )
Cybereasonmalicious.dbd9f4
TrendMicroBackdoor.Win32.QAKBOT.SMF1
BitDefenderThetaGen:NN.ZexaF.34196.QrX@aO1is5i
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.atyq
AlibabaBackdoor:Win32/KZip.beaecf8f
NANO-AntivirusTrojan.Win32.Zenpak.hsqkvq
ViRobotTrojan.Win32.Z.Qakbot.1743376
TencentWin32.Trojan.Falsesign.Wurf
Ad-AwareTrojan.GenericKD.34395406
ComodoTrojWare.Win32.UMal.yksmy@0
F-SecureTrojan.TR/AD.Qbot.bkdyu
Invinceaheuristic
SophosMal/EncPk-APV
IkarusTrojan.Win32.Skintrim
WebrootW32.Trojan.Gen
AviraTR/AD.Qbot.bkdyu
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.SD!rfn
ArcabitTrojan.Generic.D20CD50E
ZoneAlarmTrojan.Win32.Zenpak.atyq
GDataTrojan.GenericKD.34395406
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Qakbot.R349573
VBA32BScope.Malware-Cryptor.SB.01798
ALYacTrojan.Agent.QakBot
MalwarebytesBackdoor.Qbot
ESET-NOD32a variant of Win32/Skintrim.FT
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SMF1
RisingTrojan.Kryptik!1.CA76 (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.EYS!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.105705927.susgen

How to remove Win32/Skintrim.FT?

Win32/Skintrim.FT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment