Home Malware Programs Trojans Skintrim.gen.f

Skintrim.gen.f

Posted: December 23, 2010

Skintrim.gen.f is a malicious Trojan which creates a start-up registry so it runs automatically every time you log on. Skintrim.gen.f runs in the background and invites corrupt files or programs from the Internet. These provide a loophole for cyber criminals to gain access to the machine. Skintrim.gen.f then disables the firewall and attempts to steal sensitive financial data like credit card numbers and online banking details. Use a reliable malware remover to make sure your PC is free of Skintrim.gen.f.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ALLUSERSPROFILE%\desktop\instantaccess.lnk
    2 %PROGRAMFILES%\instant access\center\instantaccess.lnk
    3 %PROGRAMFILES%\instant access\desktopicons\instantaccess.lnk
    4 %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\Common\module.php
    5 %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\dialerexe.ini
    6 %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\instant access.exe
    7 %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\js\js_api_dialer.php
    8 %PROGRAMFILES%\Instant Access\Multi\20[private subnet]\medias\dialer.ico
    9 %TEMP%\3D748B.dmp
    10 %USERPROFILE%\Start Menu\InstantAccess.lnk
    11 %WINDIR%\dialerexe.ini
    12 %WINDIR%\SYSTEM32\nsinet.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\EGDHTML\HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DF1C8E21-4045-4D67-B528-335F1A4F0DE9}HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DF1C8E21-4045-4D67-B528-335F1A4F0DE9}\LOCALSERVER32\
Loading...