Home Malware Programs Trojans Trojan.Skintrim

Trojan.Skintrim

Posted: April 1, 2009

Trojan.Skintrim is a dangerous Trojan horse infection that could download other malicious software onto the infected computer. Trojan.Skintrim may enter into your system from it being compromised by either a browser security hole or a vulnerability allowing outside attackers to possibly gain access to personal files or data. Trojan.Skintrim should be detected with a spyware scan tool so that it may be safely removed without causing additional damages to your system or system files.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\MailSkinner\anim_0.gif
    2 %ProgramFiles%\MailSkinner\anim_help.gif
    3 %ProgramFiles%\MailSkinner\MailSkinner.exe
    4 %ProgramFiles%\MailSkinner\OLSkinner.dll
    5 %ProgramFiles%\MailSkinner\uninst.exe
    6 %System%\[RANDOM].dat
    7 %System%\[RANDOM].exe
    8 %System%\nvs2.inf
    9 %WinDir%\msskinner\msbackup.dat
    10 %WinDir%\pack.epk
    11 %WinDir%\Temp\install.exe
    12 %WinDir%\Temp\msksetup.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\epk_extrHKEY_CURRENT_USER\Software\extsHKEY_LOCAL_MACHINE\SOFTWARE\MailSkinnerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\OutlookAddin.AddinHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MailSkinner.exeHKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{180B4EE9-1795-4429-9651-F17A6515726D}HKEY_CLASSES_ROOT\Interface\{0A089E22-5736-4092-B3F8-3F0D5F345482}HKEY_CLASSES_ROOT\OutlookAddin.AddinHKEY_CLASSES_ROOT\OutlookAddin.Addin.1HKEY_CLASSES_ROOT\TypeLib\{5BAD7FAE-81F0-4439-8C1A-3E8907998047}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}MailSkinner

Related Posts

Loading...