Threat Database Trojans Skintrim.gen.f

Skintrim.gen.f

By JubileeX in Trojans

Skintrim.gen.f is a Trojan that can run in the background of a compromised system without a user's knowledge. The moment Skintrim.gen.f penetrates a system, it creates a start-up registry entry then it connects to a remote server in order to give a hacker access and control over a compromised PC. Skintrim.gen.f can scan a system for sensitive information such as credit card numbers, usernames and passwords which it later sends to the remote hacker who may use it for fraudulent activities.

File System Details

Skintrim.gen.f may create the following file(s):
# File Name Detections
1. %WINDIR%\SYSTEM32\nsinet.exe
2. %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\instant access.exe
3. %PROGRAMFILES%\instant access\center\instantaccess.lnk
4. %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\dialerexe.ini
5. %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\js\js_api_dialer.php
6. %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\medias\dialer.ico
7. %PROGRAMFILES%\instant access\desktopicons\instantaccess.lnk
8. %TEMP%\3D748B.dmp
9. %USERPROFILE%\Start Menu\InstantAccess.lnk
10. %WINDIR%\dialerexe.ini
11. %ALLUSERSPROFILE%\desktop\instantaccess.lnk
12. %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\Common\module.php

Registry Details

Skintrim.gen.f may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DF1C8E21-4045-4D67-B528-335F1A4F0DE9}\LOCALSERVER32\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DF1C8E21-4045-4D67-B528-335F1A4F0DE9}
HKEY_CURRENT_USER\SOFTWARE\EGDHTML\

Trending

Most Viewed

Loading...